<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Hawe</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Hawe"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Hawe"/>
		<updated>2026-05-19T17:50:55Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Application_Security_Put_Into_Practice&amp;diff=46740</id>
		<title>Category:OWASP Web Application Security Put Into Practice</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Application_Security_Put_Into_Practice&amp;diff=46740"/>
				<updated>2008-11-23T12:08:02Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{OWASP Book|1412042}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== About ==&lt;br /&gt;
&lt;br /&gt;
This project is about web application security put into practice, because I understand that clear examples in the specific programming language and best practices with explanation educate the best.&lt;br /&gt;
&lt;br /&gt;
The Ruby on Rails Security project [http://www.rorsecurity.info/] started this year and is the only security initiative for Ruby on Rails. Ruby is the fastest growing level A programming language, according to the Tiobe programming community index [http://www.tiobe.com/tpci.htm], partly because of its advertised simplicity. This is dangerous, as programmers could be enticed to do cargo cult programming [http://en.wikipedia.org/wiki/Cargo_cult_programming] without knowing the security impacts. I found several security holes in popular modules, and even the Rails framework itself generates potentially insecure code. Nevertheless, Rails provides good means against many of the OWASP Top Ten security flaws, but I believe these means have to be popularized much more.&lt;br /&gt;
&lt;br /&gt;
== Objectives ==&lt;br /&gt;
* Create a security guide to the most popular web server software, Apache&lt;br /&gt;
* Create a security guide to the popular database software, MySQL&lt;br /&gt;
* Ruby on Rails security guide and code examples for each of the OWASP Top Ten&lt;br /&gt;
&lt;br /&gt;
== Spring Of Code 007 ==&lt;br /&gt;
This project was selected for the spring of code 007 [http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Applications#Heiko_-_Web_Application_Security_put_into_practice].&lt;br /&gt;
&lt;br /&gt;
'''Progress'''&lt;br /&gt;
* Apache Guide (done)&lt;br /&gt;
* MySQL Guide (done)&lt;br /&gt;
* Ruby On Rails Guide (done)&lt;br /&gt;
&lt;br /&gt;
== Resources ==&lt;br /&gt;
* The final output [http://www.owasp.org/index.php/Image:Owasp-rails-security.pdf]&lt;br /&gt;
* The Ruby on Rails Security project [http://www.rorsecurity.info/]&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Application_Security_Put_Into_Practice&amp;diff=46739</id>
		<title>Category:OWASP Web Application Security Put Into Practice</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Application_Security_Put_Into_Practice&amp;diff=46739"/>
				<updated>2008-11-23T12:07:41Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{OWASP Book|1412042}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== About ==&lt;br /&gt;
&lt;br /&gt;
This project is about web application security put into practice, because I understand that clear examples in the specific programming language and best practices with explanation educate the best.&lt;br /&gt;
&lt;br /&gt;
The Ruby on Rails Security project [http://www.rorsecurity.info/] started this year and is the only security initiative for Ruby on Rails. Ruby is the fastest growing level A programming language, according to the Tiobe programming community index [http://www.tiobe.com/tpci.htm], partly because of its advertised simplicity. This is dangerous, as programmers could be enticed to do cargo cult programming [http://en.wikipedia.org/wiki/Cargo_cult_programming] without knowing the security impacts. I found several security holes in popular modules, and even the Rails framework itself generates potentially insecure code. Nevertheless, Rails provides good means against many of the OWASP Top Ten security flaws, but I believe these means have to be popularized much more.&lt;br /&gt;
&lt;br /&gt;
== Objectives ==&lt;br /&gt;
* Create a security guide to the most popular web server software, Apache&lt;br /&gt;
* Create a security guide to the popular database software, MySQL&lt;br /&gt;
* Ruby on Rails security guide and code examples for each of the OWASP Top Ten&lt;br /&gt;
&lt;br /&gt;
== Spring Of Code 007 ==&lt;br /&gt;
This project was selected for the spring of code 007 [http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Applications#Heiko_-_Web_Application_Security_put_into_practice].&lt;br /&gt;
&lt;br /&gt;
'''Progress'''&lt;br /&gt;
* Apache Guide (done)&lt;br /&gt;
* MySQL Guide (done)&lt;br /&gt;
* Ruby On Rails Guide (on the way)&lt;br /&gt;
&lt;br /&gt;
== Resources ==&lt;br /&gt;
* The final output [http://www.owasp.org/index.php/Image:Owasp-rails-security.pdf]&lt;br /&gt;
* The Ruby on Rails Security project [http://www.rorsecurity.info/]&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2&amp;diff=44632</id>
		<title>Project Information:template Ruby on Rails Security Guide V2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2&amp;diff=44632"/>
				<updated>2008-10-26T21:22:17Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Ruby on Rails Security Guide V2''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The last security guide for [[:Category:OWASP Web Application Security Put Into Practice|Rails]] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The [http://www.rorsecurity.info/ Ruby on Rails Security Project] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a [http://www.lulu.com/content/1412042 book]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:heikowebers(at)gmx.net '''Heiko Webers''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-ruby-on-rails-v2 '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-Ruby-on-Rails-V2(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:mendrel-a-gmail.com '''Anthony Shireman''']&amp;lt;br&amp;gt;[[:OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Anthony Shireman Background|Bio]]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:jons0022-at-unf.edu '''Steve Jones''']&amp;lt;br&amp;gt;[[:OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Steve Jones Background|Bio]]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* [http://www.owasp.org/index.php/Image:Owasp_rails_security2.pdf '''Download The Ruby on Rails Security Guide version 2''']&lt;br /&gt;
* (If appropriate, links to be added)&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Web Application Security Put Into Practice|OWASP Web Application Security Put Into Practice]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes, completed by 80%'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes, updating formatting for final'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;Yes, 100%.&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;Release&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes''' &amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Beta'''&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=44584</id>
		<title>Project Information:template Ruby on Rails Security Guide V2 - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=44584"/>
				<updated>2008-10-24T16:04:04Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Ruby on Rails Security Guide V2|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|OWASP The Ruby on Rails Security Guide V2 Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Everything is done, including the all-new fast-reading support (by highlights), yeah.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|100%&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Comments? Send me an e-mail!&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The presentation is still missing, will be ready for the EU Summit.&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2&amp;diff=44583</id>
		<title>Project Information:template Ruby on Rails Security Guide V2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2&amp;diff=44583"/>
				<updated>2008-10-24T15:54:56Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Ruby on Rails Security Guide V2''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The last security guide for [[:Category:OWASP Web Application Security Put Into Practice|Rails]] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The [http://www.rorsecurity.info/ Ruby on Rails Security Project] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a [http://www.lulu.com/content/1412042 book]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:heikowebers(at)gmx.net '''Heiko Webers''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-ruby-on-rails-v2 '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-Ruby-on-Rails-V2(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:mendrel-a-gmail.com '''Anthony Shireman''']&amp;lt;br&amp;gt;[[:OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Anthony Shireman Background|Bio]]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:jons0022-at-unf.edu '''Steve Jones''']&amp;lt;br&amp;gt;[[:OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Steve Jones Background|Bio]]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* [http://www.owasp.org/index.php/Image:Owasp_rails_security2.pdf '''Download The Ruby on Rails Security Guide version 2''']&lt;br /&gt;
* (If appropriate, links to be added)&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Web Application Security Put Into Practice|OWASP Web Application Security Put Into Practice]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes, completed by 80%'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes, updating formatting for final'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Owasp-rails-security.pdf&amp;diff=44582</id>
		<title>File:Owasp-rails-security.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Owasp-rails-security.pdf&amp;diff=44582"/>
				<updated>2008-10-24T15:52:08Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: uploaded a new version of &amp;quot;Image:Owasp-rails-security.pdf&amp;quot;: The all new version 2 by Heiko Webers.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Web Application Security Put Into Practice - Ruby On Rails Security&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Owasp_rails_security2.pdf&amp;diff=44581</id>
		<title>File:Owasp rails security2.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Owasp_rails_security2.pdf&amp;diff=44581"/>
				<updated>2008-10-24T15:50:54Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: The new version 2 of the Ruby on Rails Security Guide covers the OWASP Top Ten, Rails version 2 and has a better and more compact writing style.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The new version 2 of the Ruby on Rails Security Guide covers the OWASP Top Ten, Rails version 2 and has a better and more compact writing style.&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008&amp;diff=36713</id>
		<title>OWASP EU Summit 2008</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008&amp;diff=36713"/>
				<updated>2008-08-20T14:50:49Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;(WORK IN PROGRESS /UNDER DISCUSSION)&lt;br /&gt;
== UPDATES ==&lt;br /&gt;
*[[OWASP EU Summit 2008 - updates|'''OWASP EU Summit 2008 - updates''']]&lt;br /&gt;
&lt;br /&gt;
== What: OWASP Summit, a conference about OWASP and for OWASP's community ==&lt;br /&gt;
=== When: 4 to 7 Nov 2008 (4 &amp;amp; 5: Meetings and Training, 6 &amp;amp; 7: Conference) === &lt;br /&gt;
=== Where: Portugal ===&lt;br /&gt;
Faro or Lisbon&lt;br /&gt;
=== Organization===&lt;br /&gt;
Dinis Cruz, Paulo Coimbra and the OWASP Summit Team - Eduardo Neves, Leonardo Cavallari Militelli, Mark Roxberry, Michael Coates, Arturo 'Buanzo' Busleiman.&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
Theme: Present OWASP's projects, community and activities  .....     '....Connecting the dots.... &amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''Day 1 &amp;amp; 2'''&lt;br /&gt;
*Training sessions (similar to what happens at the moment at the other OWASP conferences)&lt;br /&gt;
*OWASP Working Group sessions (1/2 day each) on:&lt;br /&gt;
** OWASP Governance, &amp;quot;What is OWASP's position on ....&amp;quot; &amp;amp; Action Plan for 2009&lt;br /&gt;
** ESAPI&lt;br /&gt;
** Browser Security&lt;br /&gt;
** OWASP Top 10 2009&lt;br /&gt;
&lt;br /&gt;
'''Day 3 &amp;amp; 4 Agenda:'''&lt;br /&gt;
* Presentations from AoC, SpoC and SoC Participants&lt;br /&gt;
* Presentations from 'Release' Quality OWASP projects (not included in the list above) or Key OWASP projects (like ESAPI)&lt;br /&gt;
* Presentations about OWASP : How it works, Financial reports, OotM (OWASP on the Move), new project management guidelines, local chapter finances, OWASP governance &lt;br /&gt;
* Presentation from Chapter leaders on the activities developed on their project&lt;br /&gt;
* Discussion on next steps for OWASP and focus of next OWASP financial investment plans&lt;br /&gt;
&lt;br /&gt;
Other ideas:&lt;br /&gt;
&lt;br /&gt;
* vote on 6th OWASP board member (Candidates to Apply)&lt;br /&gt;
&lt;br /&gt;
== other details==&lt;br /&gt;
&lt;br /&gt;
'''Projected Attendees:450 '''&lt;br /&gt;
* 200 with some (or all) expenses covered by OWASP&lt;br /&gt;
** 33 SoC participants&lt;br /&gt;
** 70 SoC reviewers&lt;br /&gt;
** 10 SoC Collaborators&lt;br /&gt;
** 15 AoC &amp;amp; SpoC participants&lt;br /&gt;
** 15 Chapter Leaders&lt;br /&gt;
** 8 OWASP Board &amp;amp; Employees&lt;br /&gt;
** 49 OWASP non-individual members (2x per 9k Corporate? 1x for the others?)&lt;br /&gt;
&lt;br /&gt;
=== Financial details ===&lt;br /&gt;
'''Expenses'''&lt;br /&gt;
* Accommodation &amp;amp; meals: 80,000 USD  = 400 USD per person (200x) for 3 nights accommodation  and 5 meals (3 dinners and 2 lunches)&lt;br /&gt;
* Flights &amp;amp;  Trains : 70,000 USD&lt;br /&gt;
&lt;br /&gt;
'''Revenue sources'''&lt;br /&gt;
* Tickets (for the 250 non 'OWASP invited' attendees)&lt;br /&gt;
* Training Sessions&lt;br /&gt;
* Conference sponsors&lt;br /&gt;
&lt;br /&gt;
== Provisory list of 'expenses paid' participants    ==&lt;br /&gt;
&lt;br /&gt;
 {| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECTED CONFERENCE PAID ATTENDEES AND/OR SPEAKERS - NEEDS OWASP BOARD CONFIRMATION''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''NAME'''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''POSITION/REASON OF ATTENDANCE'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''COUNTRY'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''DEPARTURE (AIRPORT/CITY)'''&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP BOARD MEMBERS &amp;amp; EMPLOYEES''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Williams&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, Chair, Wiki, Management&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dave Wichers &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, Conferences, Financials&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dinis Cruz &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, Firehose of Ideas and Money spender&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Tom Brennan &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, OWASP Governance&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sebastien Deleersnyder &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, OWASP Chapters and Projects&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Belgium&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Paulo Coimbra&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Employee, Project Manager&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kate Hartmann&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Employee, Operations Director&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Alison McNamee&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Employee, Accounting &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Larry Casey&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Employee, Director of Information Technology &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SUMMER OF CODE 2008 PROJECT LEADERS &amp;amp; REVIEWERS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Alexander Fry&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Source Code Review OWASP Projects&amp;lt;br&amp;gt;OWASP Teachable Static Analysis Workbench&amp;lt;br&amp;gt;OWASP WeBekci Project  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Andrew Petukhov &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Access Control Rules Tester Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Russia&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Moscow&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arturo Alberto Busleiman &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Enigform and mod_Openpgp &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Argentina&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Carlo Pelliccioni &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Backend Security Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Italy &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Eduardo Vianna de Camargo Neves  &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Positive Security  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brazil &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Eoin Keary&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Code Review Guide &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ireland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Esteban Ribicic&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Backend Security Project&amp;lt;br&amp;gt;OWASP Classic ASP Security Project&amp;lt;br&amp;gt;OWASP AntiSamy .NET&amp;lt;br&amp;gt;OWASP Interceptor Project - 2008 Update&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Croatia&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Fabio Cerullo&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Internationalization Guidelines Project&amp;lt;br&amp;gt;OWASP Spanish Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ireland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Frederick Donovan&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Application Security Desk Reference (ASDR) &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|United States&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Heiko Webers&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Ruby on Rails Security Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Germany&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Frankfurt&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Juan Carlos Calderon&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Internationalization Guidelines&amp;lt;br&amp;gt;OWASP Spanish Project&amp;lt;br&amp;gt;OWASP Classic ASP Security Project &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Mexico &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kevin Fuller&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Testing Guide v3&amp;lt;br&amp;gt;OWASP SQL Injector Benchmarking Project (SQLiBENCH)&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sacramento Ca &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Leonardo Cavallari Militelli&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Application Security Desk Reference (ASDR)&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brazil &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Mark Roxberry&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Leader, OWASP .NET Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Matt Tesauro&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP Live CD 2008&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Austin&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Matthias Rohr&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Skavenger Project &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Germany &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Michael Coates&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP AppSensor &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Paolo Perego&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP Orizon Project  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Italy&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Parvathy Iyer &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Corporate Application Security Guide &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Pierre Parrend&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP OpenSign Server Project&amp;lt;br&amp;gt;OWASP Application Security Verification Standard &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|France&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Stephen Craig Evans&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Securing WebGoat using ModSecurity &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Singapore&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Singapore&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SUMMER OF CODE 2008/LOGISTICS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sarah Cruz&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, Graphic Design &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SRING OF CODE 2007 PROJECT LEADERS &amp;amp; REVIEWERS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Przemyslaw Skowron &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, Refresh Attacks List  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Poland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP AUTUMN OF CODE 2006 PROJECT LEADERS &amp;amp; REVIEWERS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rogan Dawes &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, WebScarab-NG &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|South Africa&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Simon Roses Femerling&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Pantera&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Spain&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''ACTIVE PROJECT LEADERS (NOT CURRENTLY PARTICIPATING ON SOC 08)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Alex Smolen&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Project leader, .NET ESAPI &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
  |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''ACTIVE CHAPTER LEADERS (NOT CURRENTLY PARTICIPATING ON SOC 08)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Antti Laulajainen&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader, Helsinki     &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Finland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Steve Antoniewicz&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter Board Member, NY/NJ Metro  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kuai Hinojosa&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader, Twin-Cities &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Jim Manico&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader/founder, Hawaii&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Hawaii, USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Anahola, Island of Kauai&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rex Booth&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader, Washington DC  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''SIGNIFICANT PAST OWASP CONTRIBUTOR (THAT IS NOT ALREADY COVERED BY ONE OF THE ABOVE CATEGORIES)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP NON-INDIVIDUAL MEMBERS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations - November 4-7 ==&lt;br /&gt;
&lt;br /&gt;
Under development. Please contact michael.coates{at}aspectsecurity.com with any questions or feedback.&lt;br /&gt;
&lt;br /&gt;
The agenda follows the successful OWASP conference two tracks format, with opening keynotes and presentations in the main auditorium, split tracks in the middle of the day, and closing pannel discussions back in the main auditorium both days. &lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Day 3 - November 6, 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | || style=&amp;quot;width:40%; background:#BC857A&amp;quot; | Track 1:  &amp;lt;Room 1&amp;gt;&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; | Track 2: Council Room&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:00-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Coffee &amp;lt;Diamond Sponsor&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:05 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Welcome to OWASP Summit Europe 2008&lt;br /&gt;
''speaker, company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:05-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Keynote: text [https://www.owasp.org/ link]&lt;br /&gt;
''speaker, company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:45-10:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | OWASP State of the Union&lt;br /&gt;
''Dinis Cruz''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:20-10:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-10:55 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:00-11:15 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:20-11:35 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:40-11:55 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:00-12:15 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:20-12:35 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:35-14:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:00-14:15 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:20-14:35 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:40-14:55 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:00-15:15 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:20-15:35 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:35-15:55 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo - CTF&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:00-16:15 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:20-15:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | Event Title ]] Organized by &lt;br /&gt;
 |-&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 19:00-21:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP Social Gathering: Dinner and Drinks at ...&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Day 4 - November 7, 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | || style=&amp;quot;width:40%; background:#BC857A&amp;quot; | Track 1:  &amp;lt;Room 1&amp;gt;&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; | Track 2: Council Room&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:00-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Coffee &amp;lt;Diamond Sponsor&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:05 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Welcome to OWASP Summit Europe 2008&lt;br /&gt;
''speaker, company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:05-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Keynote: text [https://www.owasp.org/ link]&lt;br /&gt;
''speaker, company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:45-10:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | OWASP State of the Union&lt;br /&gt;
''Dinis Cruz''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:20-10:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:30-14:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:50-16:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | title]] ([http://www.owasp.org/location.ppt ppt])&lt;br /&gt;
''[[user link | Speaker]], Company''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 18:00-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | [[SummitEU08_link | Event Title ]] Organized by &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 19:00-21:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP Social Gathering: Dinner and Drinks at ...}&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
Venue: &amp;lt;address&amp;gt; [http://owasp.org Google Maps Link] &lt;br /&gt;
&lt;br /&gt;
Registration is available via the OWASP Conference Cvent site at: [http://owasp.org Cvent link]&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=34118</id>
		<title>OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=34118"/>
				<updated>2008-07-15T08:48:11Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page contains Projects, Authors, Status Target and Reviewers of the sponsored programme [[OWASP Summer of Code 2008]].&amp;lt;br&amp;gt;&lt;br /&gt;
'''* Please note: The reference ‘Confirmed’ means reviewers' approval by both projects’ authors and OWASP Board.'''&lt;br /&gt;
&lt;br /&gt;
== DOCUMENTATION PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Verification Standard Project|OWASP Application Security Verification Standard]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mike Boberski &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.williams(at)owasp.org Jeff Williams]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend(at)insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AppSensor Project|OWASP AppSensor - Detect and Respond to Attacks from Within the Application]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:michael.coates(at)aspectsecurity.com Michael Coates]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eric.sheridan(at)aspectsecurity.com Eric Sheridan]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rjaninda(at)silverknightsecurity.com Randy Janinda]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers_Randy_Janinda_Curriculum Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Backend Security Project|OWASP Backend Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Carlo Pelliccioni&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:spyroinc(at)gmail.com Josh Sweeney]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Classic ASP Security Project|OWASP Classic ASP Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:andres(at)neurofuzz.com Andres Andreu]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Review Project|OWASP Code review guide, V1.1]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eoin Keary&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rahim.jina@ie.ey.com Rahim Jina]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Rahim Jina Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:psatishkumar(at)gmail.com P.Satish Kumar]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Satishkumar  Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Corporate Application Security Rating Guide|OWASP Corporate Application Security Rating Guide]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Parvathy Iyer&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:nkirschner@eisnerllp.com Neal Kirschner]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Neal Kirschner Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Omar.Sherin(at)infosec2.com Omar Sherin]&amp;lt;br&amp;gt;[http://www.infosec2.com/aboutme/about_me.html Curriculum]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Education Project|OWASP Education Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Martin Knobloch&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:sebastien.gioria@owasp.fr Sebastien Gioria]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/gioria Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn(at)bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Sebastien Deleersnyder&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Internationalization|OWASP Internationalization Guidelines Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Fabio.e.cerullo Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rodrigo(at)rmarcos.com Rodrigo Marcos]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Rodrigo.marcos Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP .NET Project#OWASP .NET Project Leader|OWASP .NET Project Leader]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mark Roxberry &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary(at)gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dennis.hurst(at)LifeCycleSecurity.com Dennis Hurst]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/0/636/2a3 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Positive Security Project|OWASP Positive Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eduardo Vianna de Camargo Neves &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:welias(at)conviso.com.br Wagner Elias]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers_Wagner_Elias#.27.27.27Wagner_Elias.2C_CBCP.2C_SANS_GIAC.2C_CobiTc.2C_ITILc.27.27.27 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers_Kenneth_R._Wyk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Ruby on Rails Security Guide V2|OWASP Ruby on Rails Security Guide v2]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Heiko Webers&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mendrel-a-gmail.com Anthony Shireman]&amp;lt;br&amp;gt;[[:OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Anthony Shireman Background|Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jons0022-at-unf.edu Steve Jones]&amp;lt;br&amp;gt; [https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers_Steve_Jones_Background Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Securing WebGoat using ModSecurity Project|OWASP Securing WebGoat using ModSecurity]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Stephen Evans &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ivan.ristic(at)breach.com Ivan Ristic] ([https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers_Ivan_Ristic Curriculum]) &amp;amp; Breach Research Labs&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:christian.folini(at)netnea.com Christian Folini]&amp;lt;br&amp;gt;[http://www.netnea.com/cms/?q=christian_folini Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot;|'''[[:Category:OWASP Source Code Review OWASP Projects Project|OWASP Source Code Review OWASP Projects]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | James Walden&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:marco.m.morana(at)gmail.com Marco M. Morana]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Marco M Morana Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Spanish|OWASP Spanish Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Fabio.e.cerullo Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rodrigo(at)rmarcos.com Rodrigo Marcos]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Rodrigo.marcos Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Testing Project|OWASP Testing Guide v3]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matteo Meucci &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn@bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:KFuller@dmv.ca.gov Kevin Fuller]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Fuller Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Sebastien Deleersnyder&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;400&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;120&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''3rd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''4th&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP ASDR Project|OWASP Application Security Desk Reference (ASDR)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Leonardo Cavallari Militelli &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:williamtsmith(at)gmail.com William Smith]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#William Smith | Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Kenneth R. van Wyk| Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kcfredman(at)gmail.com Frederick Donovan]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Frederick Donovan | Bio]]&amp;lt;br&amp;gt;  (Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Darren.Challey(at)ge.com Darren W. Challey]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Darren W. Challey | Bio]]&amp;lt;br&amp;gt;  (Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TOOLS PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:GTK plus GUI for w3af Project|GTK+ GUI for w3af project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Facundo Batista&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:andres.riancho(at)gmail.com Andres Riancho]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/ariancho Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah(at)securenet(dot)de Achim Hoffmann]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Achim Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Access Control Rules Tester Project|OWASP Access Control Rules Tester]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Andrew Petukhov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:caughron(at)gmail.com Mat Caughron]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/A84/998 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mg_chen(at)yahoo.com Min Chen]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/mgchen Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AntiSamy Project .NET| OWASP AntiSamy .NET]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arshan Dabirsiaghi&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;[[OWASP NYC AppSec 2008 Conference-SPEAKER-Yiannis Pavlosoglou|Short Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project|OWASP Application Security Tool Benchmarking Environment and Site Generator refresh]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dmitry Kozlov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:medelibero(at)gmail.com Mike de Libero]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Crawler|OWASP Code Crawler ]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Alessio Marziali &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Interceptor Project|OWASP Interceptor Project - 2008 Update]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Justin Derry&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ngreen16(at)yahoo.com Nathan Green]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Ngreen16 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP JSP Testing Tool Project|OWASP UI Component Verification Project (a.k.a. OWASP JSP Testing Tool)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jason Li&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:markkerzner(at)gmail.com Mark Kerzner]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/markkerzner Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabricio.fujikawa(at)infoglobo.com.br Fabrício Fujikawa]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Live CD 2008 Project|OWASP Live CD 2008 Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matt Tesauro&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:admin@wirefall.com Dustin Dykes]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/607/6b1 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jkpoots(at)rogers.com Kent Poots] &amp;lt;br&amp;gt; [http://www.linkedin.com/pub/5/25B/114 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Sebastien Deleersnyder&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenSign Server Project|OWASP Online code signing and integrity verification service for open source community (OpenSign Server)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Phil Potisk and Richard Conway&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend@insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arturo 'Buanzo' Busleiman&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Orizon Project|OWASP Orizon Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Paolo Perego&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:seba@deleersnyder.eu Sebastien Deleersnyder]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz@owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Python Static Analysis Project|OWASP Python Static Analysis]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Georgy Klimov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn@bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:diepvien00thayh@gmail.com P.Q.Huy]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Huy Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Skavenger Project|OWASP Skavenger]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mro(at)securenet.de Matthias Rohr]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rogan(at)dawes.za.net Rogan Dawes]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah(at)securenet(dot)de Achim Hoffmann]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Achim Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Sqlibench Project|OWASP SQL Injector Benchmarking Project (SQLiBENCH)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:urgunb@hotmail.com Bedirhan Urgun]&amp;lt;br&amp;gt;[mailto:mesut@h-labs.org Mesut Timur]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ferruh@mavituna.com Ferruh Mavituna]&amp;lt;br/&amp;gt; [[Project Information:Sqlibench:Ferruh|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kfuller@dmv.ca.gov Kevin Fuller] &amp;lt;br/&amp;gt;[[Project Information:Sqlibench:Kevin|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Teachable Static Analysis Workbench Project|OWASP Teachable Static Analysis Workbench]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ddk(at)cs.msu.su Dmitry Kozlov]&amp;lt;br&amp;gt;Igor Konnov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mwcoates(at)gmail.com Michael Coates]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP WeBekci Project|OWASP WeBekci Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:bunyamin@owasp.org Bunyamin Demir]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:stefano.dipaola(at)wisec.it Stefano Di Paola]&amp;lt;br/&amp;gt;[[User:Wisec|Profile]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== DESIGN/CORPORATE PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Book Cover &amp;amp; Sleeve Design|OWASP Book Cover &amp;amp; Sleeve Design]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;[[OWASP NYC AppSec 2008 Conference-SPEAKER-Yiannis Pavlosoglou|Short Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Individual and Corporate Member Packs plus Conference Attendee Packs Brief|OWASP Individual &amp;amp; Corporate Member Packs, Conference Attendee Packs Brief]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;[[OWASP NYC AppSec 2008 Conference-SPEAKER-Yiannis Pavlosoglou|Short Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=33704</id>
		<title>OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=33704"/>
				<updated>2008-07-08T21:23:37Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page contains Projects, Authors, Status Target and Reviewers of the sponsored programme [[OWASP Summer of Code 2008]].&amp;lt;br&amp;gt;&lt;br /&gt;
'''* Please note: The reviewers with the reference ‘Confirmed’ were only confirmed by projects’ authors and are still waiting for OWASP Board confirmation.'''&lt;br /&gt;
&lt;br /&gt;
== DOCUMENTATION PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Verification Standard Project|OWASP Application Security Verification Standard]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mike Boberski &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.williams(at)owasp.org Jeff Williams]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend(at)insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AppSensor Project|OWASP AppSensor - Detect and Respond to Attacks from Within the Application]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:michael.coates(at)aspectsecurity.com Michael Coates]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eric.sheridan(at)aspectsecurity.com Eric Sheridan]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rjaninda(at)silverknightsecurity.com Randy Janinda]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers_Randy_Janinda_Curriculum Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Backend Security Project|OWASP Backend Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Carlo Pelliccioni&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:spyroinc(at)gmail.com Josh Sweeney]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Classic ASP Security Project|OWASP Classic ASP Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:andres(at)neurofuzz.com Andres Andreu]&amp;lt;br&amp;gt;(TBC)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Review Project|OWASP Code review guide, V1.1]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eoin Keary&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rahim.jina@ie.ey.com Rahim Jina]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Rahim Jina Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:psatishkumar(at)gmail.com P.Satish Kumar]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Satishkumar  Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Corporate Application Security Rating Guide|OWASP Corporate Application Security Rating Guide]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Parvathy Iyer&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:nkirschner@eisnerllp.com Neal Kirschner]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Neal Kirschner Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Omar.Sherin(at)infosec2.com Omar Sherin]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Education Project|OWASP Education Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Martin Knobloch&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:sebastien.gioria@owasp.fr Sebastien Gioria]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/gioria Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn(at)bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Internationalization|OWASP Internationalization Guidelines Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Fabio.e.cerullo Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rodrigo(at)rmarcos.com Rodrigo Marcos]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Rodrigo.marcos Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP .NET Project#OWASP .NET Project Leader|OWASP .NET Project Leader]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mark Roxberry &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary(at)gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dennis.hurst(at)LifeCycleSecurity.com Dennis Hurst]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/0/636/2a3 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Positive Security Project|OWASP Positive Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eduardo Vianna de Camargo Neves &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:welias(at)conviso.com.br Wagner Elias]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers_Wagner_Elias#.27.27.27Wagner_Elias.2C_CBCP.2C_SANS_GIAC.2C_CobiTc.2C_ITILc.27.27.27 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers_Kenneth_R._Wyk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Ruby on Rails Security Guide V2|OWASP Ruby on Rails Security Guide v2]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Heiko Webers&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mendrel-a-gmail.com Anthony Shireman]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jons0022-at-unf.edu Steve Jones]&amp;lt;br&amp;gt; [https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers_Steve_Jones_Background Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Securing WebGoat using ModSecurity Project|OWASP Securing WebGoat using ModSecurity]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Stephen Evans &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ivan.ristic(at)breach.com Ivan Ristic] &amp;amp; Breach Group&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:christian.folini(at)netnea.com Christian Folini]&amp;lt;br&amp;gt;[http://www.netnea.com/cms/?q=christian_folini Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot;|'''[[:Category:OWASP Source Code Review OWASP Projects Project|OWASP Source Code Review OWASP Projects]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | James Walden&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:marco.m.morana(at)gmail.com Marco M. Morana]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Marco M Morana Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Spanish|OWASP Spanish Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Fabio.e.cerullo Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rodrigo(at)rmarcos.com Rodrigo Marcos]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Rodrigo.marcos Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Testing Project|OWASP Testing Guide v3]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matteo Meucci &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn@bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:KFuller@dmv.ca.gov Kevin Fuller]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Fuller Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;400&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;120&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''3rd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''4th&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP ASDR Project|OWASP Application Security Desk Reference (ASDR)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Leonardo Cavallari Militelli &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:williamtsmith(at)gmail.com William Smith]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#William Smith | Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Kenneth R. van Wyk| Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kcfredman(at)gmail.com Frederick Donovan]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Frederick Donovan | Bio]]&amp;lt;br&amp;gt;  (Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Darren.Challey(at)ge.com Darren W. Challey]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Darren W. Challey | Bio]]&amp;lt;br&amp;gt;  (Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TOOLS PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:GTK plus GUI for w3af Project|GTK+ GUI for w3af project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Facundo Batista&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:andres.riancho(at)gmail.com Andres Riancho]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/ariancho Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah(at)securenet(dot)de Achim Hoffmann]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Achim Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Access Control Rules Tester Project|OWASP Access Control Rules Tester]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Andrew Petukhov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:caughron(at)gmail.com Mat Caughron]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/A84/998 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mg_chen(at)yahoo.com Min Chen]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/mgchen Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AntiSamy Project .NET| OWASP AntiSamy .NET]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arshan Dabirsiaghi&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;[[OWASP NYC AppSec 2008 Conference-SPEAKER-Yiannis Pavlosoglou|Short Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project|OWASP Application Security Tool Benchmarking Environment and Site Generator refresh]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dmitry Kozlov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:medelibero(at)gmail.com Mike de Libero]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Crawler|OWASP Code Crawler ]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Alessio Marziali &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Interceptor Project|OWASP Interceptor Project - 2008 Update]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Justin Derry&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ngreen16(at)yahoo.com Nathan Green]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Ngreen16 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP JSP Testing Tool Project|OWASP UI Component Verification Project (a.k.a. OWASP JSP Testing Tool)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jason Li&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:markkerzner(at)gmail.com Mark Kerzner]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/markkerzner Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabricio.fujikawa(at)infoglobo.com.br Fabrício Fujikawa]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Live CD 2008 Project|OWASP Live CD 2008 Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matt Tesauro&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:admin@wirefall.com Dustin Dykes]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/607/6b1 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jkpoots(at)rogers.com Kent Poots] &amp;lt;br&amp;gt; [http://www.linkedin.com/pub/5/25B/114 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenSign Server Project|OWASP Online code signing and integrity verification service for open source community (OpenSign Server)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Phil Potisk and Richard Conway&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend@insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arturo 'Buanzo' Busleiman&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Orizon Project|OWASP Orizon Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Paolo Perego&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:seba@deleersnyder.eu Sebastien Deleersnyder]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz@owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Python Static Analysis Project|OWASP Python Static Analysis]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Georgy Klimov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn@bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:diepvien00thayh@gmail.com P.Q.Huy]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Huy Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Skavenger Project|OWASP Skavenger]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mro(at)securenet.de Matthias Rohr]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rogan(at)dawes.za.net Rogan Dawes]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah(at)securenet(dot)de Achim Hoffmann]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Achim Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Sqlibench Project|OWASP SQL Injector Benchmarking Project (SQLiBENCH)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:urgunb@hotmail.com Bedirhan Urgun]&amp;lt;br&amp;gt;[mailto:mesut@h-labs.org Mesut Timur]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ferruh@mavituna.com Ferruh Mavituna]&amp;lt;br/&amp;gt; [[Project Information:Sqlibench:Ferruh|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kfuller@dmv.ca.gov Kevin Fuller] &amp;lt;br/&amp;gt;[[Project Information:Sqlibench:Kevin|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Teachable Static Analysis Workbench Project|OWASP Teachable Static Analysis Workbench]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ddk(at)cs.msu.su Dmitry Kozlov]&amp;lt;br&amp;gt;Igor Konnov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alex Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mwcoates(at)gmail.com Michael Coates]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP WeBekci Project|OWASP WeBekci Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:bunyamin@owasp.org Bunyamin Demir]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:stefano.dipaola(at)wisec.it Stefano Di Paola]&amp;lt;br/&amp;gt;[[User:Wisec|Profile]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== DESIGN/CORPORATE PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Book Cover &amp;amp; Sleeve Design|OWASP Book Cover &amp;amp; Sleeve Design]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;[[OWASP NYC AppSec 2008 Conference-SPEAKER-Yiannis Pavlosoglou|Short Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Individual and Corporate Member Packs plus Conference Attendee Packs Brief|OWASP Individual &amp;amp; Corporate Member Packs, Conference Attendee Packs Brief]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;[[OWASP NYC AppSec 2008 Conference-SPEAKER-Yiannis Pavlosoglou|Short Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2&amp;diff=33474</id>
		<title>Project Information:template Ruby on Rails Security Guide V2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2&amp;diff=33474"/>
				<updated>2008-07-05T18:32:39Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Ruby on Rails Security Guide V2''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The last security guide for [[:Category:OWASP Web Application Security Put Into Practice|Rails]] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The [http://www.rorsecurity.info/ Ruby on Rails Security Project] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a [http://www.lulu.com/content/1412042 book]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:heikowebers(at)gmx.net '''Heiko Webers''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-ruby-on-rails-v2 '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-Ruby-on-Rails-V2(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:jons0022-at-unf.edu '''Steve Jones''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:jeff.cabaniss(at)gmail.com '''Jeff Cabaniss''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* (If appropriate, links to be added)&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Web Application Security Put Into Practice|OWASP Web Application Security Put Into Practice]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;Yes, completed by 80%&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33473</id>
		<title>Project Information:template Ruby on Rails Security Guide V2 - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33473"/>
				<updated>2008-07-05T18:28:50Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Ruby on Rails Security Guide V2|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|OWASP Ruby on Rails Security Guide v2 Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The project deliveries have nearly been completed. The following topics have not been covered, yet: Introduction, denial-of-service attacks and phishing. Also, the presentation, which is required for Release Quality, is not ready, yet.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
&lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The deliveries have been accomplished by 80%.&lt;br /&gt;
 |- &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| I'd like to have a professional and good looking design for my guide. I planned to hire someone for this, but then I found the &amp;quot;Book Cover &amp;amp; Sleeve Design&amp;quot; project in this year's Soc. Will that be for everyone, so we have a good corp. design? Otherwise this is my suggestion, to have a general, professional design (I've got a designer, I could ask him).&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33472</id>
		<title>Project Information:template Ruby on Rails Security Guide V2 - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33472"/>
				<updated>2008-07-05T18:20:05Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Ruby on Rails Security Guide V2|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|OWASP Ruby on Rails Security Guide v2 Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| sdfsdsd&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
&lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33471</id>
		<title>Project Information:template Ruby on Rails Security Guide V2 - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33471"/>
				<updated>2008-07-05T18:19:33Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Ruby on Rails Security Guide V2|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|OWASP Ruby on Rails Security Guide v2 Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
&lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33470</id>
		<title>Project Information:template Ruby on Rails Security Guide V2 - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33470"/>
				<updated>2008-07-05T18:17:50Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Ruby on Rails Security Guide V2|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|OWASP Ruby on Rails Security Guide v2 Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 | -&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
&lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33469</id>
		<title>Project Information:template Ruby on Rails Security Guide V2 - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33469"/>
				<updated>2008-07-05T18:17:33Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Ruby on Rails Security Guide V2|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|OWASP Ruby on Rails Security Guide v2 Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 | hello &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
&lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2&amp;diff=33389</id>
		<title>Project Information:template Ruby on Rails Security Guide V2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Ruby_on_Rails_Security_Guide_V2&amp;diff=33389"/>
				<updated>2008-07-03T18:58:13Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Ruby on Rails Security Guide V2''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The last security guide for [[:Category:OWASP Web Application Security Put Into Practice|Rails]] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The [http://www.rorsecurity.info/ Ruby on Rails Security Project] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a [http://www.lulu.com/content/1412042 book]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:heikowebers(at)gmx.net '''Heiko Webers''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-ruby-on-rails-v2 '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-Ruby-on-Rails-V2(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:jons0022-at-unf.edu '''Steve Jones''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:jeff.cabaniss(at)gmail.com '''Jeff Cabaniss''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* (If appropriate, links to be added)&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Web Application Security Put Into Practice|OWASP Web Application Security Put Into Practice]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications#The Ruby on Rails Security Guide v2|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Ruby on Rails Security Guide V2 - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=33204</id>
		<title>OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=33204"/>
				<updated>2008-07-02T18:15:06Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page contains Projects, Authors, Status Target and Reviewers of the sponsored programme [[OWASP Summer of Code 2008]].&amp;lt;br&amp;gt;&lt;br /&gt;
'''* Please note: The reviewers with the reference ‘Confirmed’ were only confirmed by projects’ authors and are still waiting for OWASP Board confirmation.'''&lt;br /&gt;
&lt;br /&gt;
== DOCUMENTATION PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Verification Standard Project|OWASP Application Security Verification Standard]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mike Boberski &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.williams(at)owasp.org Jeff Williams]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend(at)insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AppSensor Project|OWASP AppSensor - Detect and Respond to Attacks from Within the Application]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:michael.coates(at)aspectsecurity.com Michael Coates]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eric.sheridan(at)aspectsecurity.com Eric Sheridan]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:thrynn404(at)gmail.com Randy Janinda]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Backend Security Project|OWASP Backend Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Carlo Pelliccioni&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Classic ASP Security Project|OWASP Classic ASP Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Review Project|OWASP Code review guide, V1.1]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eoin Keary&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:psatishkumar(at)gmail.com P.Satish Kumar]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Satishkumar  Curriculum]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Corporate Application Security Rating Guide|OWASP Corporate Application Security Rating Guide]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Parvathy Iyer&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Neal Kirschner&amp;lt;br&amp;gt;Email address?&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Omar.Sherin(at)infosec2.com Omar Sherin]&amp;lt;br&amp;gt;TBC &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Education Project|OWASP Education Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Martin Knobloch&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:sebastien.gioria@owasp.fr Sebastien Gioria]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/gioria Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn(at)bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Internationalization|OWASP Internationalization Guidelines Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Fabio.e.cerullo Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rodrigo(at)rmarcos.com Rodrigo Marcos]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP .NET Project#OWASP .NET Project Leader|OWASP .NET Project Leader]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mark Roxberry &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary(at)gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dennis.hurst(at)hp.com Dennis Hurst]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Positive Security Project|OWASP Positive Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eduardo Vianna de Camargo Neves &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:welias(at)conviso.com.br Wagner Elias]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Ruby on Rails Security Guide V2|OWASP Ruby on Rails Security Guide v2]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Heiko Webers &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jons0022-at-unf.edu Steve Jones]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.cabaniss(at)gmail.com Jeff Cabaniss]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Securing WebGoat using ModSecurity Project|OWASP Securing WebGoat using ModSecurity]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Stephen Evans &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ivan.ristic(at)breach.com Ivan Ristic] &amp;amp; Breach Group&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:christian.folini(at)netnea.com Christian Folini]&amp;lt;br&amp;gt;[http://www.netnea.com/cms/?q=christian_folini Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot;|'''[[:Category:OWASP Source Code Review OWASP Projects Project|OWASP Source Code Review OWASP Projects]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | James Walden&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:marco.m.morana(at)gmail.com Marco M. Morana]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Marco M Morana Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Spanish|OWASP Spanish Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Fabio.e.cerullo Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rodrigo(at)rmarcos.com Rodrigo Marcos]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Testing Project|OWASP Testing Guide v3]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matteo Meucci &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn@bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:KFuller@dmv.ca.gov Kevin Fuller]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Fuller Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;400&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;120&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''3rd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''4th&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP ASDR Project|OWASP Application Security Desk Reference (ASDR)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Leonardo Cavallari Militelli &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:williamtsmith(at)gmail.com William Smith]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#William Smith | Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Kenneth R. van Wyk| Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kcfredman(at)gmail.com Frederick Donovan]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Frederick Donovan | Bio]]&amp;lt;br&amp;gt;  (Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Darren.Challey(at)ge.com Darren W. Challey]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Darren W. Challey | Bio]]&amp;lt;br&amp;gt;  (Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TOOLS PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:GTK plus GUI for w3af Project|GTK+ GUI for w3af project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Facundo Batista&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:andres.riancho(at)gmail.com Andres Riancho]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/ariancho Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah(at)securenet(dot)de Achim Hoffmann]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Achim Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Access Control Rules Tester Project|OWASP Access Control Rules Tester]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Andrew Petukhov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:caughron(at)gmail.com Mat Caughron]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/A84/998 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mg_chen(at)yahoo.com Min Chen]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/mgchen Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AntiSamy Project .NET| OWASP AntiSamy .NET]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arshan Dabirsiaghi&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dallasspohn(at)sbcglobal.net Dallas Spohn]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project|OWASP Application Security Tool Benchmarking Environment and Site Generator refresh]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dmitry Kozlov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:medelibero(at)gmail.com Mike de Libero]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Crawler|OWASP Code Crawler ]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Alessio Marziali &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Interceptor Project|OWASP Interceptor Project - 2008 Update]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Justin Derry&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Nathan.Green(at)ge.com Nathan.Green]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(TBC)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP JSP Testing Tool Project|OWASP UI Component Verification Project (a.k.a. OWASP JSP Testing Tool)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jason Li&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:markkerzner(at)gmail.com Mark Kerzner]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/markkerzner Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabricio.fujikawa(at)infoglobo.com.br Fabrício Fujikawa]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Live CD 2008 Project|OWASP Live CD 2008 Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matt Tesauro&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:admin@wirefall.com Dustin Dykes]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/607/6b1 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jkpoots(at)rogers.com Kent Poots] &amp;lt;br&amp;gt; [http://www.linkedin.com/pub/5/25B/114 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenSign Server Project|OWASP Online code signing and integrity verification service for open source community (OpenSign Server)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Phil Potisk and Richard Conway&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend@insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:a_campani@yahoo.fr Antonio Campanile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arturo 'Buanzo' Busleiman&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Orizon Project|OWASP Orizon Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Paolo Perego&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:seba@deleersnyder.eu Sebastien Deleersnyder]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz@owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Python Static Analysis Project|OWASP Python Static Analysis]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Georgy Klimov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn@bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:diepvien00thayh@gmail.com P.Q.Huy]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Skavenger Project|OWASP Skavenger]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mro(at)securenet.de Matthias Rohr]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Rogan Dawes&amp;lt;br&amp;gt;Email address?&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah(at)securenet(dot)de Achim Hoffmann]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Achim Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Sqlibench Project|OWASP SQL Injector Benchmarking Project (SQLiBENCH)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:urgunb@hotmail.com Bedirhan Urgun]&amp;lt;br&amp;gt;[mailto:mesut@h-labs.org Mesut Timur]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ferruh@mavituna.com Ferruh Mavituna]&amp;lt;br/&amp;gt; [[Project Information:Sqlibench:Ferruh|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kfuller@dmv.ca.gov Kevin Fuller] &amp;lt;br/&amp;gt;[[Project Information:Sqlibench:Kevin|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Teachable Static Analysis Workbench Project|OWASP Teachable Static Analysis Workbench]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ddk(at)cs.msu.su Dmitry Kozlov]&amp;lt;br&amp;gt;Igor Konnov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alex Fry]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP WeBekci Project|OWASP WeBekci Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:bunyamin@owasp.org Bunyamin Demir]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:stefano.dipaola(at)wisec.it Stefano Di Paola]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== DESIGN/CORPORATE PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Book Cover &amp;amp; Sleeve Design|OWASP Book Cover &amp;amp; Sleeve Design]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;[[OWASP NYC AppSec 2008 Conference-SPEAKER-Yiannis Pavlosoglou|Short Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Individual and Corporate Member Packs plus Conference Attendee Packs Brief|OWASP Individual &amp;amp; Corporate Member Packs, Conference Attendee Packs Brief]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;[[OWASP NYC AppSec 2008 Conference-SPEAKER-Yiannis Pavlosoglou|Short Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008&amp;diff=33058</id>
		<title>OWASP EU Summit 2008</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008&amp;diff=33058"/>
				<updated>2008-07-02T09:53:01Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;(WORK IN PROGRESS /UNDER DISCUSSION)&lt;br /&gt;
&lt;br /&gt;
== What: OWASP Summit, a conference about OWASP and for OWASP's community ==&lt;br /&gt;
=== When: 4 to 7 Nov 2008 (4 &amp;amp; 5: Meetings and Training, 6 &amp;amp; 7: Conference) === &lt;br /&gt;
=== Where: Portugal ===&lt;br /&gt;
Faro or Lisbon&lt;br /&gt;
=== Organization===&lt;br /&gt;
Paulo Coimbra and Dinis Cruz&lt;br /&gt;
== Agenda ==&lt;br /&gt;
Theme: Present OWASP's projects, community and activities  .....     '....Connecting the dots.... &amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''Day 1 &amp;amp; 2'''&lt;br /&gt;
*Training sessions (similar to what happens at the moment at the other OWASP conferences)&lt;br /&gt;
*OWASP Working Group sessions (1/2 day each) on:&lt;br /&gt;
** OWASP Governance, &amp;quot;What is OWASP's position on ....&amp;quot; &amp;amp; Action Plan for 2009&lt;br /&gt;
** ESAPI&lt;br /&gt;
** Browser Security&lt;br /&gt;
** OWASP Top 10 2009&lt;br /&gt;
&lt;br /&gt;
'''Day 3 &amp;amp; 4 Agenda:'''&lt;br /&gt;
* Presentations from AoC, SpoC and SoC Participants&lt;br /&gt;
* Presentations from 'Release' Quality OWASP projects (not included in the list above) or Key OWASP projects (like ESAPI)&lt;br /&gt;
* Presentations about OWASP : How it works, Financial reports, OotM (OWASP on the Move), new project management guidelines, local chapter finances, OWASP governance &lt;br /&gt;
* Presentation from Chapter leaders on the activities developed on their project&lt;br /&gt;
* Discussion on next steps for OWASP and focus of next OWASP financial investment plans&lt;br /&gt;
&lt;br /&gt;
Other ideas:&lt;br /&gt;
&lt;br /&gt;
* vote on 6th OWASP board member (Candidates to Apply)&lt;br /&gt;
&lt;br /&gt;
== other details==&lt;br /&gt;
&lt;br /&gt;
'''Projected Attendees:450 '''&lt;br /&gt;
* 200 with some (or all) expenses covered by OWASP&lt;br /&gt;
** 33 SoC participants&lt;br /&gt;
** 70 SoC reviewers&lt;br /&gt;
** 10 SoC Collaborators&lt;br /&gt;
** 15 AoC &amp;amp; SpoC participants&lt;br /&gt;
** 15 Chapter Leaders&lt;br /&gt;
** 8 OWASP Board &amp;amp; Employees&lt;br /&gt;
** 49 OWASP non-individual members (2x per 9k Corporate? 1x for the others?)&lt;br /&gt;
&lt;br /&gt;
=== Financial details ===&lt;br /&gt;
'''Expenses'''&lt;br /&gt;
* Accommodation &amp;amp; meals: 80,000 USD  = 400 USD per person (200x) for 3 nights accommodation  and 5 meals (3 dinners and 2 lunches)&lt;br /&gt;
* Flights &amp;amp;  Trains : 70,000 USD&lt;br /&gt;
&lt;br /&gt;
'''Revenue sources'''&lt;br /&gt;
* Tickets (for the 250 non 'OWASP invited' attendees)&lt;br /&gt;
* Training Sessions&lt;br /&gt;
* Conference sponsors&lt;br /&gt;
&lt;br /&gt;
== Participants ==&lt;br /&gt;
=== OWASP Board members &amp;amp; employees ===&lt;br /&gt;
* Jeff Williams &lt;br /&gt;
* Dave Wichers &lt;br /&gt;
* Dinis Cruz &lt;br /&gt;
* Tom Brennan &lt;br /&gt;
* Sebastien Deleersnyder &lt;br /&gt;
* Paulo Coimbra&lt;br /&gt;
* Kate Hartmann (to be confirmed)&lt;br /&gt;
* Alison McNamee (to be confirmed)&lt;br /&gt;
* Larry Casey (to be confirmed)&lt;br /&gt;
&lt;br /&gt;
=== Summer of Code 08 Participants &amp;amp; Reviewers ===&lt;br /&gt;
* (please add your name in the following format)&lt;br /&gt;
* OWASP Classic ASP Security Project Reviewer Esteban Ribicic Argentina -living in Croatia/Wien-&lt;br /&gt;
* OWASP Internationalization Guidelines Reviewer Project Esteban Ribicic&lt;br /&gt;
* OWASP Spanish Project Reviewer Esteban Ribicic&lt;br /&gt;
* OWASP Ruby on Rails Security Project Leader Heiko Webers from Germany&lt;br /&gt;
&lt;br /&gt;
=== Winter of Code 07 Participants (Completed Projects) ===&lt;br /&gt;
* (please add your name)&lt;br /&gt;
* {Project} {Name} {Origin Country}&lt;br /&gt;
&lt;br /&gt;
=== Autumn of Code 06 Participants ===&lt;br /&gt;
* (please add your name)&lt;br /&gt;
* {Project} {Name} {Origin Country}&lt;br /&gt;
&lt;br /&gt;
* OWASP Pantera, Simon Roses Femerling, Spain&lt;br /&gt;
&lt;br /&gt;
=== Active Chapter Leaders ===&lt;br /&gt;
* (please add your name in the following format)&lt;br /&gt;
* {Chapter} {Role} {Name} {Origin Country}&lt;br /&gt;
&lt;br /&gt;
=== Active Project Leaders (not currently participating on SoC 08)===&lt;br /&gt;
* (please add your name in the following format)&lt;br /&gt;
* {Project} {Role} {Name} {Origin Country}&lt;br /&gt;
&lt;br /&gt;
=== Significant Past OWASP contributor (that is not already covered by one of the above categories) ===&lt;br /&gt;
* (please add your name in the following format)&lt;br /&gt;
* {Project/Chapter} {Role} {Name} {Origin Country}&lt;br /&gt;
&lt;br /&gt;
=== Logistic and Support team ===&lt;br /&gt;
* Summit Graphic Design + Summit organization + on-site logistics support, Sarah Cruz, UK (London)&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26735</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26735"/>
				<updated>2008-03-17T09:58:59Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: Heiko Webers' application&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life Cycle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;br /&gt;
&lt;br /&gt;
== OWASP Classic ASP Security Project  ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
I am interested in making P018 - OWASP Classic ASP Security Project happen, Classic ASP 2.0 and 3.0 applications are still largely used as this technology is more than 10 years old and was largely used. there are thousands of sites on the wild that need guidance on the security arena. This is where OWASP can come up and provide help for “making the Web a better place” and continue spreading the word on security. I have always be a passionate of the technology (regardless of its inconveniences such as being old and DLL-hell prone) and I am really exited on the idea of sharing my knowledge of this area to the world and what best that though OWASP.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
Create a secure framework for Classic ASP application by complementing existing OWASP projects with documentation for this particular technology and the creation of security libraries. More specifically:&lt;br /&gt;
* Creation of a Common Object Repository for ASP applications based on OWASP ESAPI Project including objects and/or references to libraries for security applications all this aligned with OWASP Top10 and OWASP Guide .&lt;br /&gt;
* Create Documentation aligned to OWASP Code Review Project Checklist providing additional technology-specific checks.&lt;br /&gt;
* Addition of expression for Code Review Tool to support Classic ASP applications.&lt;br /&gt;
* Implementation of Version 1 of Stinger for ASP either by using an installable COM library or ISAPI.&lt;br /&gt;
* This same module will compliment the OWASP Validation Documentation Project.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver. &lt;br /&gt;
&lt;br /&gt;
Also I’ve had close contact with OWASP since 2005&lt;br /&gt;
[https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html] by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish.&lt;br /&gt;
&lt;br /&gt;
== Internationalization Guidelines and OWASP-Spanish Project ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
The main goal of OWASP is to spread the word about security (“Our mission is to make application security &amp;quot;visible,&amp;quot; so that people and organizations can make informed decisions about application security risks.”) and OWASP has done great work so far :). And now it’s time for a next big step.&lt;br /&gt;
&lt;br /&gt;
The number of native and secondary speakers in the world for Chinese, Spanish, French, Russian, Arabic and Indi languages are estimated in similar number to English speaking or even more (Some References at [http://en.wikipedia.org/wiki/Ethnologue_list_of_most_spoken_languages Ethnologue], [http://encarta.msn.com/media_701500404/Languages_Spoken_by_More_Than_10_Million_People.html Encarta], [http://en.wikipedia.org/wiki/List_of_languages_by_number_of_native_speakers Wikipedia]). I think is a good time for OWASP to reach those that do not speak English to have full access to all the OWASP materials, not just a couple of documents.&lt;br /&gt;
&lt;br /&gt;
OWASP, while open to translations, do not have clear guidelines on how to translate OWASP contents and (AFAIK) there is no multi-language support in OWASP.org site. This is understandable as there is no formal project for internationalization so far. &lt;br /&gt;
&lt;br /&gt;
'''Oportunity and Effort'''&amp;lt;br&amp;gt;&lt;br /&gt;
This is great opportunity to make Spanish the first language on which the OWASP site and documentation is fully translated and at the same time share the experience with other people interested in the same objective, Bring OWASP to the world.  And this is something I’ve being pushing for some time ago and that could be possible “at once” via SoC 2008.&lt;br /&gt;
&lt;br /&gt;
I understand this is significant effort so to have it done I will count with the help of 6 people (friend of mine, all of them Security auditors with excellent English level) plus a few well known contributors from OWASP-Spanish effort, so the founding will be divided among the people involved in the same proportion of the work they do for the completion of this effort. This, to encourage delivery.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
* Team up with Larry Casey to implement Multilanguage support in OWASP.org Mediawiki.&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to start a new language translation for OWASP Document and Site Pages&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to implement internationalization and localization ([http://www.w3.org/International/ i18n]) on OWASP Software &lt;br /&gt;
* Full translation to Spanish of all the release-level document projects. Those are:&lt;br /&gt;
** Top 10 2007&lt;br /&gt;
** Guide 2 (Already translated)&lt;br /&gt;
** Testing Guide (Already Translated)&lt;br /&gt;
** Legal&lt;br /&gt;
** FAQ&lt;br /&gt;
* Full Translation of major sections of OWASP Site&lt;br /&gt;
** Project Main Pages (Release, Beta and Alpha levels for both documents and tools projects)&lt;br /&gt;
** Principles&lt;br /&gt;
** References Section&lt;br /&gt;
** Conferences&lt;br /&gt;
** News (Those currently displayed in OWASP site)&lt;br /&gt;
** About OWASP&lt;br /&gt;
* Evaluation of Spanish translation approach for WebGoat and WebScarab and delivery of this document to Bruce and Rogan for possible implementation in near future.&lt;br /&gt;
* Leverage for deploy of es.owasp.org, the domain already exists but is not redirecting correctly.&lt;br /&gt;
* Create a Communication strategy to help and keep track on new pages or changes in significant pages so all the translations are in sync.&lt;br /&gt;
&lt;br /&gt;
'''Out of Scope'''&amp;lt;br&amp;gt;&lt;br /&gt;
Translation of the following sections are NOT in Scope&lt;br /&gt;
* Local Chapters Pages&lt;br /&gt;
* Presentations&lt;br /&gt;
* Conferences&lt;br /&gt;
* Videos&lt;br /&gt;
* Blogs&lt;br /&gt;
* All the projects deliverables in Alpha and Beta Stages&lt;br /&gt;
* All the documentation “on development” like Guide Version 3.0&lt;br /&gt;
* Translation of Pages, documentation or tools to other language other than Spanish according to the stated in above section.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I’ve being part of contributions to OWASP documents on the translation arena since 2005 [https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html], a few of them by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish. It is time to make the full job done :).&lt;br /&gt;
&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver.&lt;br /&gt;
&lt;br /&gt;
== The Ruby on Rails Security Guide v2 ==&lt;br /&gt;
Heiko Webers&lt;br /&gt;
&lt;br /&gt;
The last security guide for Rails [http://www.owasp.org/index.php/Category:OWASP_Web_Application_Security_Put_Into_Practice] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The Ruby on Rails Security Project [http://www.rorsecurity.info/] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a book [http://www.lulu.com/content/1412042]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.&lt;br /&gt;
&lt;br /&gt;
In the new Rails Security Guide I'd like to&lt;br /&gt;
* update the entire book to match Rails 2.0&lt;br /&gt;
* cover new topics, including, but not limited to:&lt;br /&gt;
** Intranet and administration interface security,&lt;br /&gt;
** phishing,&lt;br /&gt;
** real-world attack situations,&lt;br /&gt;
** short excursus on server monitoring,&lt;br /&gt;
** the new CookieStore session management,&lt;br /&gt;
** vulnerabilities in popular plug-ins,&lt;br /&gt;
** denial-of-service attacks&lt;br /&gt;
* cover all OWASP Top Ten security vulnerabilities&lt;br /&gt;
* a more compact writing style, more examples and &amp;quot;questions-and-answers&amp;quot;&lt;br /&gt;
* introduce the OWASP and Rails security to a greater audience&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Owasp-rails-security.pdf&amp;diff=23572</id>
		<title>File:Owasp-rails-security.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Owasp-rails-security.pdf&amp;diff=23572"/>
				<updated>2007-11-20T21:27:44Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: uploaded a new version of &amp;quot;Image:Owasp-rails-security.pdf&amp;quot;: Ruby on Rails Security How-To&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Web Application Security Put Into Practice - Ruby On Rails Security&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_practice&amp;diff=22789</id>
		<title>SpoC 007 - Web Application Security put into practice</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_practice&amp;diff=22789"/>
				<updated>2007-10-31T15:34:15Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AoC Candidate''': Heiko&lt;br /&gt;
&lt;br /&gt;
'''Project coordinator''': Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
'''Project Progress''': 100% Complete, [[SpoC 007 - Web Application Security put into Practice - Progress Page|Progress Page]]&lt;br /&gt;
&lt;br /&gt;
== Heiko - Web Application Security put into practice ==&lt;br /&gt;
&lt;br /&gt;
This project is about web application security put into practice, because I understand that clear examples in the specific programming language and best practices with explanation educate the best.&lt;br /&gt;
&lt;br /&gt;
The Ruby on Rails Security project [http://www.rorsecurity.info/] started this year and is the only security initiative for Ruby on Rails. Ruby is the fastest growing level A programming language, according to the Tiobe programming community index [http://www.tiobe.com/tpci.htm], partly because of its advertised simplicity. This is dangerous, as programmers could be enticed to do cargo cult programming [http://en.wikipedia.org/wiki/Cargo_cult_programming] without knowing the security impacts. I found several security holes in popular modules, and even the Rails framework itself generates potentially insecure code. Nevertheless, Rails provides good means against many of the OWASP Top Ten security flaws, but I believe these means have to be popularized much more.&lt;br /&gt;
&lt;br /&gt;
== Objectives ==&lt;br /&gt;
* Create a security guide to the most popular web server software, Apache&lt;br /&gt;
* Create a security guide to the popular database software, MySQL&lt;br /&gt;
* Ruby on Rails security guide and code examples for each of the OWASP Top Ten&lt;br /&gt;
&lt;br /&gt;
== Spring Of Code 007 ==&lt;br /&gt;
This project was selected for the spring of code 007 [http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Applications#Heiko_-_Web_Application_Security_put_into_practice].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Resources ==&lt;br /&gt;
* The Ruby on Rails Security project [http://www.rorsecurity.info/]&lt;br /&gt;
* The Guide: [https://www.owasp.org/index.php/Image:Owasp-rails-security.pdf]&lt;br /&gt;
&lt;br /&gt;
'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_Practice_-_Progress_Page&amp;diff=22788</id>
		<title>SpoC 007 - Web Application Security put into Practice - Progress Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_Practice_-_Progress_Page&amp;diff=22788"/>
				<updated>2007-10-31T15:33:12Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Apache Guide (done)&lt;br /&gt;
* MySQL Guide (done)&lt;br /&gt;
* Ruby On Rails Guide for the OWASP Top 10 (done)&lt;br /&gt;
** A1 - Cross Site Scripting (XSS)&lt;br /&gt;
** A2 - Injection Flaws&lt;br /&gt;
** A3 - Malicious File Execution&lt;br /&gt;
** A4 - Insecure Direct Object Reference&lt;br /&gt;
** A5 - Cross Site Request Forgery (CSRF)&lt;br /&gt;
** A6 - Information Leakage and Improper Error Handling&lt;br /&gt;
** A7 - Broken Authentication and Session Management&lt;br /&gt;
** A8 - Insecure Cryptographic Storage&lt;br /&gt;
** A9 - Insecure Communications&lt;br /&gt;
** A10 - Failure to Restrict URL Access&lt;br /&gt;
&lt;br /&gt;
Web Application Put Into Practice: [https://www.owasp.org/index.php/Image:Owasp-rails-security.pdf]&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Owasp-rails-security.pdf&amp;diff=22787</id>
		<title>File:Owasp-rails-security.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Owasp-rails-security.pdf&amp;diff=22787"/>
				<updated>2007-10-31T15:31:18Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: uploaded a new version of &amp;quot;Image:Owasp-rails-security.pdf&amp;quot;: Web Application Security Put Into Practice by Heiko Webers&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Web Application Security Put Into Practice - Ruby On Rails Security&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_practice&amp;diff=21398</id>
		<title>SpoC 007 - Web Application Security put into practice</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_practice&amp;diff=21398"/>
				<updated>2007-09-03T07:57:10Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AoC Candidate''': Heiko&lt;br /&gt;
&lt;br /&gt;
'''Project coordinator''': Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
'''Project Progress''': 60% Complete, [[SpoC 007 - Web Application Security put into Practice - Progress Page|Progress Page]]&lt;br /&gt;
&lt;br /&gt;
== Heiko - Web Application Security put into practice ==&lt;br /&gt;
&lt;br /&gt;
This project is about web application security put into practice, because I understand that clear examples in the specific programming language and best practices with explanation educate the best.&lt;br /&gt;
&lt;br /&gt;
The Ruby on Rails Security project [http://www.rorsecurity.info/] started this year and is the only security initiative for Ruby on Rails. Ruby is the fastest growing level A programming language, according to the Tiobe programming community index [http://www.tiobe.com/tpci.htm], partly because of its advertised simplicity. This is dangerous, as programmers could be enticed to do cargo cult programming [http://en.wikipedia.org/wiki/Cargo_cult_programming] without knowing the security impacts. I found several security holes in popular modules, and even the Rails framework itself generates potentially insecure code. Nevertheless, Rails provides good means against many of the OWASP Top Ten security flaws, but I believe these means have to be popularized much more.&lt;br /&gt;
&lt;br /&gt;
== Objectives ==&lt;br /&gt;
* Create a security guide to the most popular web server software, Apache&lt;br /&gt;
* Create a security guide to the popular database software, MySQL&lt;br /&gt;
* Ruby on Rails security guide and code examples for each of the OWASP Top Ten&lt;br /&gt;
&lt;br /&gt;
== Spring Of Code 007 ==&lt;br /&gt;
This project was selected for the spring of code 007 [http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Applications#Heiko_-_Web_Application_Security_put_into_practice].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Resources ==&lt;br /&gt;
* The Ruby on Rails Security project [http://www.rorsecurity.info/]&lt;br /&gt;
* The Guide: [https://www.owasp.org/index.php/Image:Owasp-rails-security.pdf]&lt;br /&gt;
&lt;br /&gt;
'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_Practice_-_Progress_Page&amp;diff=20736</id>
		<title>SpoC 007 - Web Application Security put into Practice - Progress Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_Practice_-_Progress_Page&amp;diff=20736"/>
				<updated>2007-08-12T09:31:00Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Apache Guide (done)&lt;br /&gt;
* MySQL Guide (done)&lt;br /&gt;
* Ruby On Rails Guide for the OWASP Top 10 (on the way)&lt;br /&gt;
** A1 - Cross Site Scripting (XSS)&lt;br /&gt;
** A2 - Injection Flaws&lt;br /&gt;
** A3 - Malicious File Execution&lt;br /&gt;
** A4 - Insecure Direct Object Reference&lt;br /&gt;
** A5 - Cross Site Request Forgery (CSRF)&lt;br /&gt;
** A6 - Information Leakage and Improper Error Handling&lt;br /&gt;
** A7 - Broken Authentication and Session Management&lt;br /&gt;
** A8 - Insecure Cryptographic Storage&lt;br /&gt;
** A9 - Insecure Communications&lt;br /&gt;
** A10 - Failure to Restrict URL Access&lt;br /&gt;
&lt;br /&gt;
Web Application Put Into Practice: [https://www.owasp.org/index.php/Image:Owasp-rails-security.pdf]&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Owasp-rails-security.pdf&amp;diff=20735</id>
		<title>File:Owasp-rails-security.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Owasp-rails-security.pdf&amp;diff=20735"/>
				<updated>2007-08-12T09:27:03Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: Web Application Security Put Into Practice - Ruby On Rails Security&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Web Application Security Put Into Practice - Ruby On Rails Security&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_Practice_-_Progress_Page&amp;diff=20489</id>
		<title>SpoC 007 - Web Application Security put into Practice - Progress Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_Practice_-_Progress_Page&amp;diff=20489"/>
				<updated>2007-07-30T15:31:32Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: New page: * Apache Guide (done) * MySQL Guide (done) * Ruby On Rails Guide for the OWASP Top 10 (on the way) ** A1 - Cross Site Scripting (XSS) ** A2 - Injection Flaws ** A3 - Malicious File Executi...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Apache Guide (done)&lt;br /&gt;
* MySQL Guide (done)&lt;br /&gt;
* Ruby On Rails Guide for the OWASP Top 10 (on the way)&lt;br /&gt;
** A1 - Cross Site Scripting (XSS)&lt;br /&gt;
** A2 - Injection Flaws&lt;br /&gt;
** A3 - Malicious File Execution&lt;br /&gt;
** A4 - Insecure Direct Object Reference&lt;br /&gt;
** A5 - Cross Site Request Forgery (CSRF)&lt;br /&gt;
** A6 - Information Leakage and Improper Error Handling&lt;br /&gt;
** A7 - Broken Authentication and Session Management&lt;br /&gt;
** A8 - Insecure Cryptographic Storage&lt;br /&gt;
** A9 - Insecure Communications&lt;br /&gt;
** A10 - Failure to Restrict URL Access&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_practice&amp;diff=20488</id>
		<title>SpoC 007 - Web Application Security put into practice</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_practice&amp;diff=20488"/>
				<updated>2007-07-30T15:27:16Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AoC Candidate''': Heiko&lt;br /&gt;
&lt;br /&gt;
'''Project coordinator''': Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
'''Project Progress''': 60% Complete, [[SpoC 007 - Web Application Security put into Practice - Progress Page|Progress Page]]&lt;br /&gt;
&lt;br /&gt;
== Heiko - Web Application Security put into practice ==&lt;br /&gt;
&lt;br /&gt;
This project is about web application security put into practice, because I understand that clear examples in the specific programming language and best practices with explanation educate the best.&lt;br /&gt;
&lt;br /&gt;
The Ruby on Rails Security project [http://www.rorsecurity.info/] started this year and is the only security initiative for Ruby on Rails. Ruby is the fastest growing level A programming language, according to the Tiobe programming community index [http://www.tiobe.com/tpci.htm], partly because of its advertised simplicity. This is dangerous, as programmers could be enticed to do cargo cult programming [http://en.wikipedia.org/wiki/Cargo_cult_programming] without knowing the security impacts. I found several security holes in popular modules, and even the Rails framework itself generates potentially insecure code. Nevertheless, Rails provides good means against many of the OWASP Top Ten security flaws, but I believe these means have to be popularized much more.&lt;br /&gt;
&lt;br /&gt;
== Objectives ==&lt;br /&gt;
* Create a security guide to the most popular web server software, Apache&lt;br /&gt;
* Create a security guide to the popular database software, MySQL&lt;br /&gt;
* Ruby on Rails security guide and code examples for each of the OWASP Top Ten&lt;br /&gt;
&lt;br /&gt;
== Spring Of Code 007 ==&lt;br /&gt;
This project was selected for the spring of code 007 [http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Applications#Heiko_-_Web_Application_Security_put_into_practice].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Resources ==&lt;br /&gt;
* The Ruby on Rails Security project [http://www.rorsecurity.info/]&lt;br /&gt;
&lt;br /&gt;
'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Spring_Of_Code_2007_-_Projects&amp;diff=19866</id>
		<title>OWASP Spring Of Code 2007 - Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Spring_Of_Code_2007_-_Projects&amp;diff=19866"/>
				<updated>2007-07-14T09:59:34Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: /* All SpoC Projects */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== All SpoC Projects ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; WIDTH=100%&lt;br /&gt;
|-&lt;br /&gt;
! SpoC Project Name&lt;br /&gt;
! Author&lt;br /&gt;
! Confirmed&lt;br /&gt;
! Status&lt;br /&gt;
! Coordinated by &lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - The OWASP Web Security Certification Framework|The OWASP Web Security Certification Framework]]&lt;br /&gt;
| Mark Curphey&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - SqlMap|SqlMap]]&lt;br /&gt;
| Bernardo Damele&lt;br /&gt;
| Yes&lt;br /&gt;
| 60% &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Site Generator|OWASP Site Generator]]&lt;br /&gt;
| Boris&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Report Generator]]&lt;br /&gt;
| Boris&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Tiger]]&lt;br /&gt;
| Boris&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Attacks Reference Guide|Attacks Reference Guide]]&lt;br /&gt;
| NSRAV Security Research Group&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - The Scholastic Application Security Assessment Project|The Scholastic Application Security Assessment Project]]&lt;br /&gt;
| Eric Sheridan and &lt;br /&gt;
Dr. Goran Trajkovski&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Inspekt|Inspekt: Input filtering and validation library for PHP]]&lt;br /&gt;
| Ed Finkler&lt;br /&gt;
| Yes&lt;br /&gt;
| 50% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Code review Project|Code review Project]]&lt;br /&gt;
| Eoin Keary&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Certification Project|OWASP Certification Project]]&lt;br /&gt;
| Mateo Meucci&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Education Project|OWASP Education Project]]&lt;br /&gt;
| Sebastien Deleersnyder&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP The Anti-Samy Project|OWASP The Anti-Samy Project]]&lt;br /&gt;
| Arshan Dabirsiaghi&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Security throughout the SDLC|Security throughout the SDLC]]&lt;br /&gt;
| Keith Casey&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP WebGoat Solutions Guide|OWASP WebGoat Solutions Guide]]&lt;br /&gt;
| Erwin Geirnaert&lt;br /&gt;
| Yes&lt;br /&gt;
| 90% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP WeBekci Project|OWASP WeBekci Project]]&lt;br /&gt;
| Bunyamin Demir&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Python Tainted Mode|Python Tainted Mode]]&lt;br /&gt;
| Denis&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - WebScarab NG Security Test Automation|WebScarab NG Security Test Automation]]&lt;br /&gt;
| Darren Edmonds&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Refresh Attacks list|Refresh Attacks list]]&lt;br /&gt;
| Przemyslaw 'rezos' Skowron&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Best Practices &amp;amp; Countermeasures|Best Practices &amp;amp; Countermeasures]]&lt;br /&gt;
| Jim&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Brand|OWASP brand]]&lt;br /&gt;
| Paulo Coimbra&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Web Application Security put into practice|Web Application Security put into practice]]&lt;br /&gt;
| Heiko Webers&lt;br /&gt;
| Yes&lt;br /&gt;
| 60% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP JBroFuzz Project|OWASP JBroFuzz Project]]&lt;br /&gt;
| Subere&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Owasp Orizon Project|Owasp Orizon Project]]&lt;br /&gt;
| Paolo Perego&lt;br /&gt;
| Yes&lt;br /&gt;
| 15% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Enigform: Firefox Addon for OpenPGP signing of HTTP requests]]&lt;br /&gt;
| Arturo (Buanzo) Busleiman&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP LiveCD Education Project|OWASP LiveCD Education Project]]&lt;br /&gt;
| Josh Sweeney&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Java Project|OWASP Java Project]]&lt;br /&gt;
| Erwin Geirnaert&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP LiveCD Project|OWASP LiveCD Project]]&lt;br /&gt;
| Joshua Perrymon&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Interim @ Aspect Offices|Interim @ Aspect Offices]]&lt;br /&gt;
| Andy Gocke&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - 10x 1000USD to FOSS projects we all use |10x 1000USD to FOSS projects we all use ]]&lt;br /&gt;
| (tbd)&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Help with SpoC project management|Help with SpoC project management]]&lt;br /&gt;
| Paulo Coimbra&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_practice&amp;diff=19865</id>
		<title>SpoC 007 - Web Application Security put into practice</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Web_Application_Security_put_into_practice&amp;diff=19865"/>
				<updated>2007-07-14T09:58:51Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AoC Candidate''': Heiko&lt;br /&gt;
&lt;br /&gt;
'''Project coordinator''': Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
'''Project Progress''': 60% Complete, [[SpoC 007 - Web Application Security put into Practice - Progress Page|Progress Page]]&lt;br /&gt;
&lt;br /&gt;
== Heiko - Web Application Security put into practice ==&lt;br /&gt;
&lt;br /&gt;
This project is about web application security put into practice, because I understand that clear examples in the specific programming language and best practices with explanation educate the best.&lt;br /&gt;
&lt;br /&gt;
The Ruby on Rails Security project [http://www.rorsecurity.info/] started this year and is the only security initiative for Ruby on Rails. Ruby is the fastest growing level A programming language, according to the Tiobe programming community index [http://www.tiobe.com/tpci.htm], partly because of its advertised simplicity. This is dangerous, as programmers could be enticed to do cargo cult programming [http://en.wikipedia.org/wiki/Cargo_cult_programming] without knowing the security impacts. I found several security holes in popular modules, and even the Rails framework itself generates potentially insecure code. Nevertheless, Rails provides good means against many of the OWASP Top Ten security flaws, but I believe these means have to be popularized much more.&lt;br /&gt;
&lt;br /&gt;
== Objectives ==&lt;br /&gt;
* Create a security guide to the most popular web server software, Apache&lt;br /&gt;
* Create a security guide to the popular database software, MySQL&lt;br /&gt;
* Ruby on Rails security guide and code examples for each of the OWASP Top Ten&lt;br /&gt;
&lt;br /&gt;
== Spring Of Code 007 ==&lt;br /&gt;
This project was selected for the spring of code 007 [http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Applications#Heiko_-_Web_Application_Security_put_into_practice].&lt;br /&gt;
&lt;br /&gt;
'''Progress'''&lt;br /&gt;
* Apache Guide (done)&lt;br /&gt;
* MySQL Guide (done)&lt;br /&gt;
* Ruby On Rails Guide (on the way)&lt;br /&gt;
&lt;br /&gt;
== Resources ==&lt;br /&gt;
* The Ruby on Rails Security project [http://www.rorsecurity.info/]&lt;br /&gt;
&lt;br /&gt;
'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Application_Security_Put_Into_Practice&amp;diff=19484</id>
		<title>Category:OWASP Web Application Security Put Into Practice</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Application_Security_Put_Into_Practice&amp;diff=19484"/>
				<updated>2007-06-28T19:54:50Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: New page: == About ==  This project is about web application security put into practice, because I understand that clear examples in the specific programming language and best practices with explana...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== About ==&lt;br /&gt;
&lt;br /&gt;
This project is about web application security put into practice, because I understand that clear examples in the specific programming language and best practices with explanation educate the best.&lt;br /&gt;
&lt;br /&gt;
The Ruby on Rails Security project [http://www.rorsecurity.info/] started this year and is the only security initiative for Ruby on Rails. Ruby is the fastest growing level A programming language, according to the Tiobe programming community index [http://www.tiobe.com/tpci.htm], partly because of its advertised simplicity. This is dangerous, as programmers could be enticed to do cargo cult programming [http://en.wikipedia.org/wiki/Cargo_cult_programming] without knowing the security impacts. I found several security holes in popular modules, and even the Rails framework itself generates potentially insecure code. Nevertheless, Rails provides good means against many of the OWASP Top Ten security flaws, but I believe these means have to be popularized much more.&lt;br /&gt;
&lt;br /&gt;
== Objectives ==&lt;br /&gt;
* Create a security guide to the most popular web server software, Apache&lt;br /&gt;
* Create a security guide to the popular database software, MySQL&lt;br /&gt;
* Ruby on Rails security guide and code examples for each of the OWASP Top Ten&lt;br /&gt;
&lt;br /&gt;
== Spring Of Code 007 ==&lt;br /&gt;
This project was selected for the spring of code 007 [http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Applications#Heiko_-_Web_Application_Security_put_into_practice].&lt;br /&gt;
&lt;br /&gt;
'''Progress'''&lt;br /&gt;
* Apache Guide (done)&lt;br /&gt;
* MySQL Guide (done)&lt;br /&gt;
* Ruby On Rails Guide (on the way)&lt;br /&gt;
&lt;br /&gt;
== Resources ==&lt;br /&gt;
* The Ruby on Rails Security project [http://www.rorsecurity.info/]&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Project&amp;diff=19483</id>
		<title>Category:OWASP Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Project&amp;diff=19483"/>
				<updated>2007-06-28T19:38:53Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: /* Alpha Status Projects */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An OWASP project is a collection of related tasks that have a defined roadmap and team members. OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team.&lt;br /&gt;
&lt;br /&gt;
To propose a new project, please send an email to [mailto:owasp@owasp.org?subject=New_OWASP_Project_idea owasp@owasp.org]&lt;br /&gt;
&lt;br /&gt;
Every project has an associated mail list. You can view all the lists, examine their archives, and subscribe to any of them on the [http://lists.owasp.org/mailman/listinfo OWASP Project Mailing Lists] page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Release Quality Projects==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;th width=&amp;quot;50%&amp;quot;&amp;gt;Tools&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;Documentation&amp;lt;/th&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP WebGoat Project|OWASP WebGoat Project]]&lt;br /&gt;
: an online training environment for hands-on learning about application security&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP WebScarab Project|OWASP WebScarab Project]]&lt;br /&gt;
: a tool for performing all types of security testing on web applications and web services&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP AppSec FAQ Project|OWASP AppSec FAQ Project]]&lt;br /&gt;
: FAQ covering many application security topics&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Guide Project|OWASP Guide Project]]&lt;br /&gt;
: a massive document covering all aspects of web application and web service security&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Legal Project|OWASP Legal Project]]&lt;br /&gt;
: a project focused on contracting for secure software&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Testing Project|OWASP Testing Guide]]&lt;br /&gt;
: a project focused on application security testing procedures and checklists&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Top Ten Project|OWASP Top Ten Project]]&lt;br /&gt;
: an awareness document that describes the top ten web application security vulnerabilities&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Beta Status Projects==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;th width=&amp;quot;50%&amp;quot;&amp;gt;Tools&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;Documentation&amp;lt;/th&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP CAL9000 Project|OWASP CAL9000 Project]]&lt;br /&gt;
: a JavaScript based web application security testing suite&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP DirBuster Project|OWASP DirBuster Project]]&lt;br /&gt;
:DirBuster is a multi threaded java application designed to brute force directories and files names on web/application servers.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Encoding Project|OWASP Encoding Project]]&lt;br /&gt;
: a project focused on the development of encoding best practices for web applications.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP LAPSE Project|OWASP LAPSE Project]]&lt;br /&gt;
: an Eclipse-based source-code static analysis tool for Java&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Live CD Project|OWASP Live CD Project]]&lt;br /&gt;
: a CD containing ready to use versions of application security analysis and testing tools&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP .NET Project|OWASP .NET Research]]&lt;br /&gt;
: a project focused on helping .NET developers build secure applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Pantera Web Assessment Studio Project|OWASP Pantera Web Assessment Studio Project]]&lt;br /&gt;
: a project focused on combining automated capabilities with complete manual testing to get the best results&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Sprajax Project|OWASP Sprajax Project]]&lt;br /&gt;
: an open source black box security scanner used to assess the security of AJAX-enabled applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP SQLiX Project|OWASP SQLiX Project]]&lt;br /&gt;
: a project focused on the development of SQLiX, a full perl-based SQL scanner&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP WSFuzzer Project|OWASP WSFuzzer Project]]&lt;br /&gt;
: a project focused on the development of WSFuzzer, a full python-based Web Services SOAP fuzzer&lt;br /&gt;
&lt;br /&gt;
; [[ORG_%28Owasp_Report_Generator%29|OWASP Report Generator]]&lt;br /&gt;
: a project giving security professionals a way to report and keep track of their projects&lt;br /&gt;
&lt;br /&gt;
; [[Owasp_SiteGenerator|OWASP Site Generator]]&lt;br /&gt;
: a project allowing users to create dynamic sites for use in training, web application scanner testing, etc...&lt;br /&gt;
&lt;br /&gt;
; [[OWASP_Tiger|OWASP Tiger]]&lt;br /&gt;
: OWASP Tiger is a Windows application originally intended to be used for automating the process of testing various known ASP.NET security issues in hosted environments. However, it is much more versatile than that: it can help you construct and send a HTTP requests, receive and analyze the responses, match them against a set of conditions to produce alerts, notifications that something is wrong with the application(s) or service(s) being tested.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP WeBekci Project|OWASP WeBekci Project]]&lt;br /&gt;
: OWASP WeBekci is a web based ModSecurity 2.x management tool. WeBekci is written in PHP, Its backend is powered by MySQL and the frontend by XAJAX framework.&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP CLASP Project|OWASP CLASP Project]]&lt;br /&gt;
: a project focused on defining process elements that reinforce application security&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Code Review Project|OWASP Code Review Project]]&lt;br /&gt;
: a project to capture best practices for reviewing code&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Tools Project|OWASP Tools Project]]&lt;br /&gt;
: The OWASP Tools Project's goal is to provide unbiased, practical information and guidance about application security tools.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Alpha Status Projects==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;th width=&amp;quot;50%&amp;quot;&amp;gt;Tools&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;Documentation&amp;lt;/th&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP PHP AntiXSS Library Project|OWASP PHP AntiXSS Library Project]]&lt;br /&gt;
: reduce cross-site scripting vulnerabilities by encoding your output&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Insecure Web App Project|OWASP Insecure Web App Project]]&lt;br /&gt;
: a web application that includes common web application vulnerabilities&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Interceptor Project|OWASP Interceptor Project]]&lt;br /&gt;
: a testing tool for XML web service and Ajax interfaces&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP JBroFuzz|OWASP JBroFuzz Project]]&lt;br /&gt;
: a fuzzer application, supporting a number of automated security checks including basic cross site scripting checks (XSS) as well as basic SQL injection testing.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Orizon Project|OWASP Orizon Project]]&lt;br /&gt;
: a project focused on the development of a flexible code review engine&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Stinger Project|OWASP Stinger Project]]&lt;br /&gt;
: a project focus on the development of a centralized input validation mechanism which can be easily applied to existing or developmental applications&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP AJAX Security Project|OWASP AJAX Security Guide]]&lt;br /&gt;
: investigating the security of AJAX enabled applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Application Security Assessment Standards Project|OWASP Application Security Assessment Standards Project]]&lt;br /&gt;
: establish a set of standards defining baseline approaches to conducting differing types/levels of application security assessment&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Application Security Requirements Project|OWASP Application Security Requirements]]&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Application Security Metrics Project|OWASP Application Security Metrics Project]]&lt;br /&gt;
: identify and provide a set of application security metrics that have been found by contributors to be effective in measuring application security  &lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Career Development Project|OWASP Career Development Project]]&lt;br /&gt;
: The OWASP Career Development project is focused on helping application security professionals understand the job market, roles, career paths, and skills to work in the field.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Certification Criteria Project|OWASP Certification Criteria Project]]&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Certification Project|OWASP Certification Project]]&lt;br /&gt;
: our challenge is to create a plan for certification: a set of OWASP Certification for Developers and Testers. &lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Communications Project|OWASP Communications Project]]&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Honeycomb Project|OWASP Honeycomb Project]]&lt;br /&gt;
: a comprehensive and integrated guide to the fundamental building blocks of application security&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Java Project|OWASP Java Project]]&lt;br /&gt;
: a project focused on helping Java and J2EE developers build secure applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Logging Project|OWASP Logging Guide]]&lt;br /&gt;
: a project to define best practices for logging and log management&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP PHP Project|OWASP PHP Project]]&lt;br /&gt;
: a project focused on helping PHP developers build secure applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Validation Project|OWASP Validation Project]]&lt;br /&gt;
: a project that provides guidance and tools related to validation&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP WASS Project|OWASP WASS Guide]]&lt;br /&gt;
: a standards project to develop more concrete criteria for secure applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Web Application Security Put Into Practice|OWASP Web Application Security Put Into Practice]]&lt;br /&gt;
: real-world web application security for Ruby on Rails, Apache and MySQL&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP XML Security Gateway Evaluation Criteria Project|OWASP XML Security Gateway Evaluation Criteria]]&lt;br /&gt;
: a project to define evaluation criteria for XML Security Gateways&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Education Project|OWASP Education Project]]&lt;br /&gt;
: a project to build educational tracks and modules for different audiences&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Spring_Of_Code_2007_Applications&amp;diff=17535</id>
		<title>OWASP Spring Of Code 2007 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Spring_Of_Code_2007_Applications&amp;diff=17535"/>
				<updated>2007-03-29T12:55:24Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: Heiko's application&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page contains project Applications to the [[OWASP_Spring_Of_Code_2007]]&lt;br /&gt;
&lt;br /&gt;
'''If you want to apply for a SpoC 007 sponsorship you HAVE TO USE THIS PAGE for your application'''&lt;br /&gt;
&lt;br /&gt;
See [[OWASP_Spring_Of_Code_2007#How_To_Participate]] for what do to one you completed your Application&lt;br /&gt;
&lt;br /&gt;
---------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Proposed template:''' {for longer proposals, in addition to these details you can create a PDF}:&lt;br /&gt;
&lt;br /&gt;
== {Your first name or Alias} - {Project name} ==&lt;br /&gt;
Please remember that projects will be selected and funded based on how well they meet the [[OWASP_Spring_Of_Code_2007_:_Selection|Selection Criteria]].&lt;br /&gt;
&lt;br /&gt;
You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include the following information in your proposal.&lt;br /&gt;
&lt;br /&gt;
* Your educational and professional background&lt;br /&gt;
&lt;br /&gt;
* Application security experience and accomplishments&lt;br /&gt;
&lt;br /&gt;
* Participation and leadership in open communities&lt;br /&gt;
&lt;br /&gt;
* The opportunity, challenges, issues or need your proposal addresses&lt;br /&gt;
&lt;br /&gt;
* Objectives or ways in which you will meet the goal(s)&lt;br /&gt;
&lt;br /&gt;
* Specific activities and who will carry out these activities&lt;br /&gt;
&lt;br /&gt;
* Specific deliverables and a rough project schedule so we can track progress&lt;br /&gt;
&lt;br /&gt;
* Long-term vision for the project&lt;br /&gt;
&lt;br /&gt;
* Any other reasons why you and your project should be selected&lt;br /&gt;
&lt;br /&gt;
== Buanzo - Enigform: Firefox Addon for OpenPGP signing of HTTP requests ==&lt;br /&gt;
&lt;br /&gt;
I am a 25 year old Independent security consultant from Buenos Aires, Argentina, that has contributed to the world of&lt;br /&gt;
information systems security since 1994, when BBSes and Linux still lived together.&lt;br /&gt;
&lt;br /&gt;
A quick search for buanzo on google [http://www.google.com/search?hl=en&amp;amp;q=buanzo&amp;amp;btnG=Google+Search] will provide all necessary details about my professional and community background. For comprobable experience, you could also check my Rent a Coder profile.[http://www.rentacoder.com/RentACoder/SoftwareCoders/showBioInfo.asp?lngAuthorId=735204].&lt;br /&gt;
&lt;br /&gt;
In my free time I like playing with my Punk-Pop band [http://www.purevolume.com/futurabandapunkpop], Futurabanda. [http://www.futurabanda.com.ar], and maintaining my Restaurants, Wines and Recipes site. [http://www.vivamoslavida.com.ar]. I have to admit that my first priorities are my beloved son [http://www.fotolog.com/buanzo] and my wonderful wife [http://www.fotolog.com/buanzo].&lt;br /&gt;
&lt;br /&gt;
=== Accomplishments ===&lt;br /&gt;
&lt;br /&gt;
I've contributed scripts, fixes and translations to the Nmap project. I've also acted as Expert Contributor for SANS TOP-20 2004, 2005 and 2006. I've developed &lt;br /&gt;
tools that can be found in Freshmeat, like mprl (a getty enhancement to allow remote logins from the login: prompt of the console). I've also written&lt;br /&gt;
the Unix chapter of the OISSG's Information Systems Security Assessment Framework, v0.1 [http://www.oissg.org/content/view/71/71/]. I'm currently writing&lt;br /&gt;
an Internet Draft to be proposed for RFC regarding Enigform.&lt;br /&gt;
&lt;br /&gt;
=== Community ===&lt;br /&gt;
&lt;br /&gt;
I run the official 2600 meetings site for Argentina [http://www.2600.com/meetings/pages.html], I've been proposed, but I refused, for President of the Argentinian Free Software group called SOLAR [www.solar.org.ar]. I'm an active member of the FLOSS community since 1996, having written articles in magazines http://www.net-security.org/dl/articles/Detecting_and_Understanding_rootkits.txt, made TV, radio&lt;br /&gt;
and newspaper appearances [http://codigoabierto.bitacoras.com/archivos/2005/04/01/buanzo-hacks] and led different security research groups of Spain, Mexico and Argentina. Currently I contribute time thorugh my sites, forums and blogs,&lt;br /&gt;
answering questions in mailing lists and helping coordinate some local LUGs. I do also manager the Linux Counter for Argentina [http://counter.li.org/reports/place.php?place=AR].&lt;br /&gt;
&lt;br /&gt;
=== My Project ===&lt;br /&gt;
&lt;br /&gt;
Enigform [http://enigform.mozdev.org] is a Firefox extension that enhances HTTP with OpenPGP functionality. It digitally signs outgoing HTTP requests so that a web server can authenticate the identity and data of the incoming request. It is a Web Security tool because it can, if correctly implemented as any OpenPGP based technology, render man in the middle attacks useless. I think OpenPGP already speaks for itself regarding eMail. Imagine the same benefits for http and web applications. I think Enigform can fit into the OWASP Validation Project [http://www.owasp.org/index.php/Category:OWASP_Validation_Project].&lt;br /&gt;
&lt;br /&gt;
Enigform is the reference implementation of the Internet Draft I'm working on, in discussion with members of the IETF's OpenPGP Working Group.&lt;br /&gt;
&lt;br /&gt;
Some simple PHP code is enough to make a web application Enigform-aware [http://enigformtest.buanzo.com.ar]. The Smutty PHP MVC Framework already supports Enigform [http://smutty.pu-gh.com/demo/enigform].&lt;br /&gt;
&lt;br /&gt;
=== Long Term ===&lt;br /&gt;
&lt;br /&gt;
Have the Draft be proposed as a Standards Track RFC document, have Enigform support directly in Apache and IIS, and port Enigform to other browsers&lt;br /&gt;
and/or programming languages, and also provide OpenPGP De/Encryption support.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Why should I be selected ===&lt;br /&gt;
&lt;br /&gt;
I have the experience, security awareness and means to make this project THE web security project of the decade. I am a respected member of the&lt;br /&gt;
international security community, and I firmly believe Enigform is my greatest idea so far.&lt;br /&gt;
&lt;br /&gt;
== Eoin Keary - Code review Project ==&lt;br /&gt;
* '''Executive Summary''':&lt;br /&gt;
I am proposing that I complete the OWASP Code review guide during this period.&lt;br /&gt;
The code review guide was started by me in 2005 and has much information on reviewing code for common vulnerabilities. It is frequently accessed (looking at the stats on the OWASP site) and therefore is useful to practitioners. &lt;br /&gt;
&lt;br /&gt;
I believe the code review guide is an integral part of the OWASP BOK (Body of Knowledge). Ensuring secure development is key to secure applications and code review is of paramount importance in this domain.&lt;br /&gt;
&lt;br /&gt;
There are many sections still to be added and more to be readjusted and rewritten to reflect the current state of the security world.&lt;br /&gt;
Much needs to be written on Web 2.0 technologies and distributed B2B technologies such as Webservices.&lt;br /&gt;
 &lt;br /&gt;
The Code review process and procedure needs also to be covered. A guide to establishing a mature code review process also needs to be done.&lt;br /&gt;
Code review methodologies also need to be discussed.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* '''Objectives and Deliverables''':&lt;br /&gt;
&lt;br /&gt;
Update of the code review guide:&lt;br /&gt;
* Add additional areas relating to the code review process such as:&lt;br /&gt;
** Benefits and pitfalls&lt;br /&gt;
** Methodology&lt;br /&gt;
** The code review process&lt;br /&gt;
*** Transactional analysis&lt;br /&gt;
*** Managing the code review process&lt;br /&gt;
*** Assigning risk to findings&lt;br /&gt;
&lt;br /&gt;
** Technical guides&lt;br /&gt;
*** Language specific best practice &lt;br /&gt;
*** Java &lt;br /&gt;
*** .NET &lt;br /&gt;
*** PHP &lt;br /&gt;
*** MySQL &lt;br /&gt;
*** Stored Procs &lt;br /&gt;
*** C/C++ &lt;br /&gt;
&lt;br /&gt;
** Code review by vulnerability:&lt;br /&gt;
*** Reviewing Code for Buffer Overruns and Overflows &lt;br /&gt;
*** Reviewing Code for OS Injection&lt;br /&gt;
*** Reviewing Code for SQL Injection&lt;br /&gt;
*** Reviewing Code for Data Validation&lt;br /&gt;
*** Reviewing code for XSS issues&lt;br /&gt;
*** Reviewing Code for Error Handling&lt;br /&gt;
*** Reviewing Code for Logging Issues&lt;br /&gt;
*** Reviewing The Secure Code Environment&lt;br /&gt;
*** Reviewing code for Authorization Issues&lt;br /&gt;
*** Reviewing code for Authentication Issues&lt;br /&gt;
*** Reviewing code for Session Integrity&lt;br /&gt;
*** Reviewing code for Cross Site Request Forgery&lt;br /&gt;
*** Reviewing code for Cryptography implementation issues&lt;br /&gt;
*** Reviewing code Dangerous HTTP Methods (Deployment)&lt;br /&gt;
*** Race Conditions &lt;br /&gt;
&lt;br /&gt;
The areas of code are structured giving a brief explanation, the anti-pattern (vulnerable pattern to look for) and a suggested fix.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* '''Why I should be sponsored for the project''':&lt;br /&gt;
&lt;br /&gt;
I used to head up the code review team as part of the application security group in fidelity investments and have 5+ years of the secure code review process. &lt;br /&gt;
I also was the lead of the Testing guide until V2 was published via the Autumn of Code. &lt;br /&gt;
&lt;br /&gt;
I have always  delivered any work I have volunteered for on time. &lt;br /&gt;
 &lt;br /&gt;
I have been involved in OWASP projects for 2/3 years now and have always been an active contributor.&lt;br /&gt;
&lt;br /&gt;
== Paolo Perego - Owasp Orizon Project ==&lt;br /&gt;
* '''Executive Summary''':&lt;br /&gt;
Owasp Orizon [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project] Project born in 2006 as answer to the lack of common engine and library usable by opensource code review related tools.&lt;br /&gt;
&lt;br /&gt;
I'm proposing that, during the Spring of Code 2007 period, I'll complete static analisys API and java source code enforment objects.&lt;br /&gt;
&lt;br /&gt;
Sometimes a complete code review approach is not suitable for most customers who wants to harden their code which is being approaching release stage. For such a reason, I started writing Java objects that embeds most of the security checks against common web vulnerabilities (XSS, SQL injection, Session handling, ...) so that source code can be hardened with a small effort in terms of code rewriting.&lt;br /&gt;
&lt;br /&gt;
I do believe that a common set of API and a common safe coding best practices library is one of the most important goals to bring application security to the developers.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* '''Objectives and Deliverables''':&lt;br /&gt;
Completing the static code review API section&lt;br /&gt;
* improving programming language to XML translator&lt;br /&gt;
* improving security best practices code review scan library&lt;br /&gt;
* improving secure coding fashion best practices library&lt;br /&gt;
* writing the pattern matching scan using the aformentioned libraries&lt;br /&gt;
Writing the java source code enforment objects&lt;br /&gt;
* writing an object to handle form data values to avoid XSS&lt;br /&gt;
* writing an object to handle form data values to avoid SQL Injection&lt;br /&gt;
* writing an object to handle HttpRequest and HttpSession objects&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* '''Why I should be sponsored for the project''':&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now.&lt;br /&gt;
I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with.&lt;br /&gt;
&lt;br /&gt;
== Sebastien Deleersnyder - OWASP Education Project ==&lt;br /&gt;
* '''Executive Summary''':&lt;br /&gt;
This Education project aims to provide in building blocks of web application security information. These modules can be combined together in education tracks targeting different audiences. &lt;br /&gt;
&lt;br /&gt;
Web Application Security Education and Awareness is needed throughout the entire organization, each area and level of organizations have specific needs and requirements regarding education. A manager needs other information than a security professional or developer. Novices to the profession require other training than people with several years of experience. &lt;br /&gt;
&lt;br /&gt;
* '''Objectives and Deliverables''':&lt;br /&gt;
Currently the project goals are to create Educational Tracks: &lt;br /&gt;
* Complete the [[OWASP Education Presentation|consolidation page of OWASP presentations]] performed in the past&lt;br /&gt;
* A &amp;quot;Web Application Security Primer&amp;quot; Track for beginners (4 hours) &lt;br /&gt;
* A &amp;quot;What developers should know on Web Application Security&amp;quot; Track for developers (4 hours) &lt;br /&gt;
&lt;br /&gt;
* '''Why you should be sponsored for the project''': &lt;br /&gt;
I started the successful Belgian Chapter 3 years ago and have actively contributed to OWASP since then. I also co-organized the European conference last year in Belgium.&lt;br /&gt;
&lt;br /&gt;
This is the first separate project that I started, originating from a local demand to set up educational tracks for people that are new to Web Application Security. There are literally hundreds of presentations and an enormous amount of information on the OWASP web site. The goal of this project is to restructure pieces of that information in reusable modules that can be combined in educational tracks. It is my believe that awareness is an important cornerstone of building secure web applications, and this project will actively support that.&lt;br /&gt;
&lt;br /&gt;
If we are granted Spoc 007 participation, I will be sharing the budget with all active participants. This will be an extra motivation for project participation. I will reinvest my part in the project to set up a web conferencing / web casting solution to be used to disseminate the project results and make them available for later use.&lt;br /&gt;
&lt;br /&gt;
* '''More details''': &lt;br /&gt;
The detailed [[OWASP Education Project Roadmap|road map]] can be found here.&lt;br /&gt;
The SpoC 007 goal is to finish Sub Goals 1, 2, 3 and 4. If time permits we can start with sub goal 5.&lt;br /&gt;
&lt;br /&gt;
== Subere - OWASP JBroFuzz Project ==&lt;br /&gt;
&lt;br /&gt;
==== Overview ==== &lt;br /&gt;
&lt;br /&gt;
JBroFuzz is a stateless network protocol fuzzer that emerged from the needs of penetration testing. The purpose of this application is to provide a single, portable application that offers stable cross-platform network protocol fuzzing capabilities. At the same time, JBroFuzz attempts to keep the User Interface (UI) as intuitive as possible.&lt;br /&gt;
&lt;br /&gt;
==== Fuzzing ==== &lt;br /&gt;
&lt;br /&gt;
As seen by the emphasis given on the subject of fuzzing in the 2007 Testing Guide (v2), network protocol fuzzing serves as a fundamental cornerstone of application security testing. For this, many different categories and types of fuzzing have been defined.&lt;br /&gt;
&lt;br /&gt;
==== Objectives ==== &lt;br /&gt;
&lt;br /&gt;
JBroFuzz needs to expand and grow in order to cover network fuzzing in a more complete manner. Its modular implementation allows for the addtion of new functionality by means of independent tabs. The key tabs proposed to be added during the spring of code 2007 are (details in next section):&lt;br /&gt;
&lt;br /&gt;
* '''Open Source Tab'''&lt;br /&gt;
* '''NTLM Brute Force over HTTP/S Tab'''&lt;br /&gt;
* '''Pure HTTP/S Fuzzing using HTTPClient'''&lt;br /&gt;
* '''Blind SQL Injection Fuzzing Tab'''&lt;br /&gt;
&lt;br /&gt;
At the same time, the following existing tabs need to be updated and made more robust (details in next section):&lt;br /&gt;
&lt;br /&gt;
* '''TCP Fuzzing tab allowing graph outputs'''&lt;br /&gt;
* '''TCP Sniffing tab update thread Agent Queue'''&lt;br /&gt;
* '''Update Generators file format'''&lt;br /&gt;
* '''Include SOAP and XML fuzzing'''&lt;br /&gt;
&lt;br /&gt;
This expansion process relates to stabilising code that is presently included in JBroFuzz, thus allowing it to run for extensive periods of time (24h+) as well as adding more functionality in terms of the three new tabs.&lt;br /&gt;
&lt;br /&gt;
==== Deliverables ==== &lt;br /&gt;
&lt;br /&gt;
Based on the above, the new code elements that will be added are as follows:&lt;br /&gt;
&lt;br /&gt;
* '''Open Source Tab:''' ''Provide the ability to enumerate e-mails from newsgroups without breaching google automated search rules''&lt;br /&gt;
* '''NTLM Brute Force over HTTP/S Tab:''' ''Provide the ability to enumerate NTLM as well as brute over HTTP/S NTLM.''&lt;br /&gt;
* '''Pure HTTP/S Fuzzing:''' ''Implement a fuzzing tab utilising HTTPClient from Jakarta that will also allow for multi-threading''&lt;br /&gt;
* '''Blind SQL Fuzzing Tab''' ''Implement a tab that extracts information from a blind SQL injection point identified on web server over HTTP/HTTPS.''&lt;br /&gt;
&lt;br /&gt;
For updating existing code elements that require a partial rewrite, the following areas of focus are presented in detail: &lt;br /&gt;
&lt;br /&gt;
* '''TCP Fuzzing tab allowing graph outputs:''' ''Provide the ability to graph fuzzing results during a particular session run. This will give the ability to integrate and pickup potential fuzzing patterns.''&lt;br /&gt;
* '''TCP Sniffing tab update thread Agent Queue:''' ''Update the code of the sniffing panel in order to handle threaded agents in a more memory efficient way.''&lt;br /&gt;
* '''Update Generators file format:''' ''Update the generators file format to allow for the parsing and creation of recursive generators.''&lt;br /&gt;
* '''Include SOAP and XML fuzzing:''' ''Include an up to date list of SOAP and XML fuzzing templates.''&lt;br /&gt;
&lt;br /&gt;
Overall, the above two lists of changes should provide sufficient complexity and output for the spring of code 2007, forming a challenging implementation project.&lt;br /&gt;
&lt;br /&gt;
==== Background ==== &lt;br /&gt;
&lt;br /&gt;
In its short life, the OWASP JBroFuzz Project has attracted the interest of the online security community with a total of appr. 5000 downloads in the last months. &lt;br /&gt;
&lt;br /&gt;
Coming from a strong java background (5+ years) I decided to implement and release JBroFuzz in order to initially simplify penetrations testing processes that relate to web application and network protocol fuzzing.&lt;br /&gt;
&lt;br /&gt;
I see the spring of code 2007 as a unique opportunity to industrialise network protocol fuzzing (and in particular HTTP/S fuzzing) within a single application, residing within OWASP.&lt;br /&gt;
&lt;br /&gt;
==== Why should JBroFuzz be sponsored? ==== &lt;br /&gt;
&lt;br /&gt;
Centralising fuzzing resources into one application that has the ability to handle network protocol fuzzing over HTTP and HTTPS in a simple and intuitive manner forms an area of focus that should not be dismissed in building secure software applications.&lt;br /&gt;
&lt;br /&gt;
Keep the code platform independent adds a huge advantage. &lt;br /&gt;
&lt;br /&gt;
Receving an OWASP grant from the spring of code 2007 will trigger a share in the budget with all active participants depending on their level of involvement. This will be a direct function of the number of tabs and/or user functionality that they have assisted in implementing.&lt;br /&gt;
&lt;br /&gt;
== Joshua Perrymon - OWASP LiveCD Project ==&lt;br /&gt;
* '''Executive Summary''':&lt;br /&gt;
I am proposing that I complete the second version of the OWASP LiveCD during this period.&lt;br /&gt;
The first version of the LiveCD is now available and include many of the current OWASP documents and tools. I believe the LiveCD is one of the best mediums to promote OWASP tools and documentation. It is portable and already being used by thousands of security proffesionals to perform application testing and training. &lt;br /&gt;
&lt;br /&gt;
In the current state the CD is stable and contains a lot of tools. However, this is just the beginning. There is a LOT of work that needs to be completed. The entire CD experience needs to be branded using OWASP graphics. This shouls start with the boot screen and carry all the way through to the icons and desktop graphics. The CD should also inlcude the wiki and ALL the tools developed for OWASP.&lt;br /&gt;
&lt;br /&gt;
* '''Objectives and Deliverables''':&lt;br /&gt;
&lt;br /&gt;
Update of the LiveCD:&lt;br /&gt;
* Complete OWASP branding&lt;br /&gt;
* Add OWASP wiki&lt;br /&gt;
* Add encryption capabilities&lt;br /&gt;
* Add more OWASP tools&lt;br /&gt;
* Add more pen-test tools such as;&lt;br /&gt;
 VOIP, RFID, BlueTooth, Wireless, etc..&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* '''Why I should be sponsored for the project''':&lt;br /&gt;
&lt;br /&gt;
I had the idea of the LiveCD about a year ago and have worked very hard to get the first version developed. This was driven by my vision to make all of the OWASP tools available on a portable medium. The main difference in the OWASP liveCD vs. other live CDs is going to be the regularity of updates. If sponsorship can be obtained the CD could be updated on a monthly basis. Not once a year like other liveCDs. The CD will also include specialty tools and documentation to perform VOIP, RFID,Bluetooth, and wireless security assessments.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Mark Curphey – The OWASP Web Security Certification Framework ==&lt;br /&gt;
&lt;br /&gt;
'''Problem'''&lt;br /&gt;
 &lt;br /&gt;
PCI DSS is attracting a lot of criticism for a lot of valid reasons. &lt;br /&gt;
 &lt;br /&gt;
http://securitybuddha.com/2007/03/23/the-problems-with-the-pci-data-security-standard-part-1/&lt;br /&gt;
&lt;br /&gt;
http://blogs.csoonline.com/node/210&lt;br /&gt;
&lt;br /&gt;
http://www.computerweekly.com/blogs/stuart_king/2007/03/more-on-pci---the-audit-guide.html&lt;br /&gt;
&lt;br /&gt;
The list is of course long and not appropriate here……and while its easy to knock PCI, there is nothing better out there. &lt;br /&gt;
&lt;br /&gt;
'''Solution and Deliverables'''&lt;br /&gt;
&lt;br /&gt;
As opposed to me continuing saying what’s wrong with PCI DSS, it seems to me that OWASP is a perfect forum to simply create and publish a “better criteria”. This can either be adopted and implemented by an organization like OWASP or considered to be incorporated into the PCI or other security standards. We won't get bogged down in the politics up-front, but hold something good up to the world for people to adopt. This project would of course draw on and bring together many of the other OWASP Projects including the Guide (What is a secure web app), Testing Guides (How to test for a secure web app), WebGoat (part of how to certify an individual understands and can find web app issues) etc. Many of those projects may not be complete or a perfect fit today, but this project can bring a common connecting theme to a lot of very valuable IP that OWASP has built over the years. I will also create it in such as way that a corporate could adopt/adapt it themseles as well as an industry. Where other OWASP projects are not complete or currently suitable I will build a requirements doc that can be considered by those teams if they feel appropriate. &lt;br /&gt;
&lt;br /&gt;
This project would address the;&lt;br /&gt;
&lt;br /&gt;
'''Standard''' &lt;br /&gt;
*A complete auditable (important) web site security standard suitable for modern e-commerce companies including&lt;br /&gt;
**The technical things people should care about&lt;br /&gt;
**The operational  / management things people should care about&lt;br /&gt;
'''Certification Model''' &lt;br /&gt;
*A complete framework for certification (ongoing) and implementation (including certifying auditors, ongoing validation etc). This will include for example the model for certifying auditors (including the actual test program); checklists and forms for auditors to complete and other supporting material. &lt;br /&gt;
&lt;br /&gt;
Essentially its a complete blueprint for an organisation like OWASP or a regulatory body need to run a web site security certification program complete with the supporting material to implement it.&lt;br /&gt;
&lt;br /&gt;
Note:  This is no trivial task to get right. I would need to ensure I can commit to completing the work to a good quality. I think this will take at least 2 months from start to finish to complete but I think is very important for the industry and for potentially for OWASP.  I wanted to gauge the interest by first posting this.&lt;br /&gt;
&lt;br /&gt;
== Erwin Geirnaert - OWASP Java Project ==&lt;br /&gt;
&lt;br /&gt;
* '''Executive Summary''':&lt;br /&gt;
I would like to help the OWASP Java Project to gather all Java security related information and to document any domains that lack documentation.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* '''Objectives and Deliverables''':&lt;br /&gt;
The main objective I see is to gather all information in one place, where security experts and developers can find the information they need.&lt;br /&gt;
In order to get there, I need to collect all information in the OWASP Wiki, ask people if they want to donate it to OWASP so that we can include it as public material, add URLs, white-papers, references to books, ... And if time permits, write some documentation myself.&lt;br /&gt;
&lt;br /&gt;
One deliverable is the OWASP Top 10 for J2EE applications with clear examples of vulnerabilities and mitigations.&lt;br /&gt;
&lt;br /&gt;
* '''Why you should be sponsored for the project''':&lt;br /&gt;
I have more then 10 years experience in Java and J2EE and the last 6 years I have tested and broke a lot of web applications. I gave also some very successful J2EE security courses and web security courses. I spoke at different conferences about application security in Europe.&lt;br /&gt;
And I am responsible for the security track at Javapolis, one of the biggest Jave conferences in Europe.&lt;br /&gt;
I am the co-founder of ZION SECURITY where we do security testing, code review, design reviews, training,...&lt;br /&gt;
I'm also member of the OWASP Belgium board that started in March 2007.&lt;br /&gt;
&lt;br /&gt;
== Erwin Geirnaert - OWASP WebGoat Solutions Guide ==&lt;br /&gt;
&lt;br /&gt;
* '''Executive Summary''':&lt;br /&gt;
WebGoat is used by a lot of people to learn about web application security and the different vulnerabilities. But it takes a lot of time to grasp how the tools like WebScarab work and how to use them effectively in WebGoat. I propose to create a walkthrough of the lessons in WebGoat so that people can learn from the solutions, without spoiling the fun.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* '''Objectives and Deliverables''':&lt;br /&gt;
The WebGoat Solutions Guide is a document that can be bundled with WebGoat. Each lesson contains a detailed solution with screenshots and tools. I created a PDF with the solution for WebGoat 4.0 but this is too big to load (15 MB) and is not very practical.&lt;br /&gt;
&lt;br /&gt;
After a discussion with Bruce about this, we think that the solutions should be made like the existing Lessons Plan so it is easier to maintain and update when a lesson changes. This means that there will be documentation folder and an individual solution for each lesson. &lt;br /&gt;
&lt;br /&gt;
* '''Why you should be sponsored for the project''':&lt;br /&gt;
I have more then 10 years experience in Java and J2EE and the last 6 years I have tested and broke a lot of web applications. I gave also some very successful J2EE security courses and web security courses. I spoke at different conferences about application security in Europe.&lt;br /&gt;
And I am responsible for the security track at Javapolis, one of the biggest Jave conferences in Europe.&lt;br /&gt;
I am the co-founder of ZION SECURITY where we do security testing, code review, design reviews, training,...&lt;br /&gt;
I'm also member of the OWASP Belgium board that started in March 2007.&lt;br /&gt;
&lt;br /&gt;
== Bunyamin Demir – OWASP WeBekci Project ==&lt;br /&gt;
&lt;br /&gt;
==== Executive Summary: ====&lt;br /&gt;
&lt;br /&gt;
Web application firewalls (WAF) are gaining importance among the information security technologies designed to protect web sites from attack. WAF solutions prevent attacks that network firewalls and intrusion detection systems can't and they require no modification of application source code. ModSecurity [http://www.modsecurity.org/] is an open source web application firewall that runs as an Apache module. It is an embeddable web application firewall and it provides protection from a range of attacks against web applications. It is an open source project available to everyone; it however does not come with an admin panel. &lt;br /&gt;
&lt;br /&gt;
I decided to provide this essential tool with a control panel which I believe will ease and thus encourage its usage.&lt;br /&gt;
&lt;br /&gt;
ModSecurity allows for HTTP traffic monitoring and real-time analysis with no changes to existing infrastructure. My main goal is to analyze attacks and generate rules to change the configuration of the ModSecurity accordingly.&lt;br /&gt;
&lt;br /&gt;
ModSecurity  has a feature called “flexible rule engine” as its heart of Attack Prevention capability . It uses ModSecurity’s “Rule Language,” (a programming language designed to work with HTTP transaction data). It is easy to use and flexible; yet the system administrators need to learn its own rules to create what is called “Certified ModSecurity Rules” to be implemented. My control panel will automate the major code-generation in Rule Language. &lt;br /&gt;
&lt;br /&gt;
==== Objectives and Deliverables: ====&lt;br /&gt;
&lt;br /&gt;
* '''Configuration''' : Will add all configuration parameter&lt;br /&gt;
* '''Rule Generator''': Will write all the Rules in Rule Language&lt;br /&gt;
* '''Logging'''       : Auditlog and debuglog will be added.&lt;br /&gt;
* '''Multiple-DB'''   : Will add PostgreSql and Sqlite support.&lt;br /&gt;
&lt;br /&gt;
==== Why I should be sponsored for the project: ====&lt;br /&gt;
&lt;br /&gt;
I am  involved with OWASP Turkey [http://www.owasp.org/index.php/Turkey] and interested very much in WAF. Even though this is my first project for OWASP, I am very much interested in every aspect of ModSecurity. With SpoC007’s support I will finalize my work on OWASP WeBekci [http://www.owasp.org/index.php/Category:OWASP_WeBekci_Project].&lt;br /&gt;
&lt;br /&gt;
== Eric Sheridan and Dr. Goran Trajkovski - The Scholastic Application Security Assessment Project ==&lt;br /&gt;
&lt;br /&gt;
=== ABSTRACT ===&lt;br /&gt;
&lt;br /&gt;
One of the major goals of the Open Web Application Security Project is to educate developers in the field of application software security. Understanding the risks and threats associated with web application software is pivotal in building a mature application security process. While OWASP has made a significant impact in the professional industry, more time and energy should be focused towards the academic community. It is an unfortunate fact that most universities do not require a stringent software security course for their computer science students. Consequently, most young developers do not have the ability to assess and mitigate the risks and threats for their own applications. It is for this reason that we believe the Open Web Application Security Project should fund an initiative to encourage the adaptation of application software security methodologies in the academic course curriculum.&lt;br /&gt;
&lt;br /&gt;
The Scholastic Application Security Project is intended to be the first step towards integrating security requirements in academic course curriculums. The primary goal of the project is to give students hands-on experience performing application security assessments using the tools and documentation found at http:///www.owasp.org. The assessment, lead by an application security professional, will demonstrate to students how the information and tools found at OWASP can be used to assess and ultimately increase the overall security posture of a web application. &lt;br /&gt;
&lt;br /&gt;
This project contributes towards bridging the gap between academia and industry, by equipping students with hands-on ready-for-the-job-market skills in the application software securing industry.&lt;br /&gt;
&lt;br /&gt;
=== PARTICIPANTS ===&lt;br /&gt;
&lt;br /&gt;
The Scholastic Application Security Assessment Project requires that college level students, lead by an application security professional, perform a security audit on an open source web application using the tools and information available at OWASP.&lt;br /&gt;
&lt;br /&gt;
::*'''Application Security Professional''' – Eric Sheridan ([http://www.aspectsecurity.com Aspect Security])&lt;br /&gt;
::*'''Towson University (TU) Partner''' – Dr. Goran Trajkovski, Towson University (http://www.towson.edu)&lt;br /&gt;
::*'''Students''' – Students of TU’s Application Software Security Course (COSC 458), nominated by the TU Partner&lt;br /&gt;
::*'''Web Application''' – The Open WebMail Project (http://openwebmail.org/)&lt;br /&gt;
&lt;br /&gt;
=== OWASP UTILIZATION ===&lt;br /&gt;
&lt;br /&gt;
The Scholastic Application Security Assessment Project requires heavy utilization of existing OWASP tools and utilities. Through this requirement, the project will illustrate the fact that existing OWASP resources can be used and heavily relied upon in a professional security audit. The following is a list of notable OWASP resources whose use will be documented throughout the assessment:&lt;br /&gt;
&lt;br /&gt;
::*'''OWASP Top Ten 2007''' - The security critical areas that the students will assess in the review&lt;br /&gt;
::*'''OWASP Testing Guide v2''' – The primary resource for building penetration testing cases&lt;br /&gt;
::*'''OWASP Guide''' – The primary resource for technical details pertaining to a technology and/or vulnerability&lt;br /&gt;
::*'''OWASP WebScarabNG''' – The primary proxy utility used throughout the assessment&lt;br /&gt;
&lt;br /&gt;
=== THE FINAL REPORT ===&lt;br /&gt;
&lt;br /&gt;
Students are required to follow the principle of “responsible disclosure” during the course of the security assessment. The developers of the open source application will be notified if any significant issues are found. Once the assessment is complete, a final report will be delivered to the application developers and the appropriate OWASP Spring of Code personnel. For each finding in the report, the students will be required to describe how the tools and information found at OWASP were used in the discovery.&lt;br /&gt;
&lt;br /&gt;
=== HOW DOES OWASP BENEFIT? ===&lt;br /&gt;
&lt;br /&gt;
The Scholastic Application Security Assessment Project is specifically designed to benefit the OWASP brand:&lt;br /&gt;
&lt;br /&gt;
''The OWASP Community…''&lt;br /&gt;
::*will be provided a case study proving that the resources available at OWASP can be utilized in an academic  environment, that can be later used in advertising the OWASP efforts to similar programs as the one at TU.&lt;br /&gt;
::*will be providing students a hands on experience in learning and testing for the latest web application security threats, thus potentially enlarging the OWASP community of contributors and supporters.&lt;br /&gt;
::*will be addressing the need to educate developers in the security critical areas.&lt;br /&gt;
::*will be seen as offering a professional level service to another open source project.&lt;br /&gt;
::*will be addressing one of the root causes of application software insecurity.&lt;br /&gt;
&lt;br /&gt;
=== BACKGROUND ===&lt;br /&gt;
&lt;br /&gt;
'''Eric Sheridan:'''&lt;br /&gt;
&lt;br /&gt;
::*Earned a Bachelor’s of Science in Computer Science from Towson University&lt;br /&gt;
::*Graduate Student in Information Security at Johns Hopkins University&lt;br /&gt;
::*Application Security Engineer at Aspect Security&lt;br /&gt;
::*Lead of the OWASP Stinger Project and the OWASP Validation Project&lt;br /&gt;
&lt;br /&gt;
'''Goran Trajkovski, PhD:'''&lt;br /&gt;
&lt;br /&gt;
::*Has been teaching the Application Software Security course for the Computer Security undergraduate and master-level majors at TU since 2004 (TU has been a Center of Excellence in Information Assurance, designated by the NSA since 2002).&lt;br /&gt;
::*Assistant professor of Computer and Information Sciences at Towson University, and Director of its Cognitive Agency and Robotics Lab (CARoL).&lt;br /&gt;
::*Has lead curricular efforts in integrating application software security topics throughout the Computer Science and Computer Information Sciences curriculum&lt;br /&gt;
::*12 years of full time teaching experience in higher ed.&lt;br /&gt;
&lt;br /&gt;
==Boris - OWASP Site Generator==&lt;br /&gt;
OWASP Site Generator is a great tool, but it could be even better and more widespread. There’s a lot room for improvements to both its functionality and user experience. The way I see it, main user needs to be addressed and specific development objectives for the next release of OWASP Site Generator would be:&lt;br /&gt;
===User Needs===&lt;br /&gt;
*Create multiple types of sites easily&lt;br /&gt;
*Track and analyze requests easily&lt;br /&gt;
*Change the look and feel of the resulting sites easily&lt;br /&gt;
*Create sites for multiple web backend technologies easily&lt;br /&gt;
*Learn how to use OWASP Site Generator easily&lt;br /&gt;
&lt;br /&gt;
===Development Objectives===&lt;br /&gt;
*Create a vulnerability library that can be used for web services, HTML forms, AJAX, etc. instead of having to craft the same attack for each&lt;br /&gt;
*Add support for logging of all received requests, as well as querying resulting log files&lt;br /&gt;
*&amp;amp;quot;Templatize&amp;amp;quot; the code generation process, so it can support skinning of the resulting sites&lt;br /&gt;
*&amp;amp;quot;Templatize&amp;amp;quot; the code generation process, so it can support different backend web technologies&lt;br /&gt;
*Fix all significant defects in the current release of OWASP Site Generator&lt;br /&gt;
*Redesign the GUI to make it more efficient and user friendly&lt;br /&gt;
*Create a smooth setup program which would install both client and server components as effortlessly as possible&lt;br /&gt;
*Write documentation and articles about it&lt;br /&gt;
*Make the development process open to the public and, hopefully, driven by its feedback from day one&lt;br /&gt;
&lt;br /&gt;
===Why should I be sponsored for this project===&lt;br /&gt;
Well, probably because of my past work on AoC (I just hope that won’t be the reason for me ''not'' to be sponsored :)&lt;br /&gt;
&lt;br /&gt;
==Boris - OWASP Report Generator==&lt;br /&gt;
There is no doubt that OWASP Report Generator is a very handy tool for penetration testers and other security researchers, but it would be even better if some enhancements were made:&lt;br /&gt;
===User Needs===&lt;br /&gt;
*More robustness&lt;br /&gt;
*Ease of use (more efficient and intuitive GUI)&lt;br /&gt;
*Automated reporting for some typical (or not so typical) scenarios&lt;br /&gt;
*More documentation&lt;br /&gt;
*More samples&lt;br /&gt;
&lt;br /&gt;
===Development Objectives===&lt;br /&gt;
*Redesign the GUI to make it more efficient and user friendly&lt;br /&gt;
*Clean up the code&lt;br /&gt;
*Add functionality to import, execute and create reports for OWASP Tiger automated tests&lt;br /&gt;
*Create some samples&lt;br /&gt;
*Create a smooth setup program&lt;br /&gt;
*Write documentation and articles about it&lt;br /&gt;
*Make the development process open to the public and, hopefully, driven by its feedback from day one&lt;br /&gt;
===Why should I be sponsored for this project===&lt;br /&gt;
Well, probably because of my past work on AoC (I just hope that won’t be the reason for me ''not'' to be sponsored :)&lt;br /&gt;
&lt;br /&gt;
==Boris - OWASP Tiger==&lt;br /&gt;
OWASP Tiger project is at its very beginning. Some new features are needed in order for it to become more useful. Here’s a short list:&lt;br /&gt;
===User Needs===&lt;br /&gt;
*Easier editing of test projects&lt;br /&gt;
*Support for testing sites that require authentication&lt;br /&gt;
*Support for testing sites that require use of cookies&lt;br /&gt;
*An easy way of specifying vulnerability data, ideally an automated one&lt;br /&gt;
*More flexible reporting&lt;br /&gt;
*More project templates&lt;br /&gt;
*More documentation&lt;br /&gt;
===Development Objectives===&lt;br /&gt;
*Add support for cookies&lt;br /&gt;
*Add support for standard authentication schemes&lt;br /&gt;
*Add support for importing vulnerability data from a test definition (or a vulnerability library)&lt;br /&gt;
*Make use of OWASP Report Generator for more advanced reports&lt;br /&gt;
*Create a setup program that would install both client and project templates and also allow for adding new templates after the initial installation&lt;br /&gt;
*Write documentation and articles about it&lt;br /&gt;
*Make the development process open to the public and, hopefully, driven by its feedback from day one&lt;br /&gt;
===Why should I be sponsored for this project===&lt;br /&gt;
Well, probably because of my past work on AoC (I just hope that won’t be the reason for me ''not'' to be sponsored :)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Heiko - Web Application Security put into practice==&lt;br /&gt;
I'm trying to make the OWASP Top Ten and Guide project known in the programming community, but I understand that clear examples in the specific programming language and best practices with explanation educate the best. I'm at the chair for secure software at my university and I want to contribute practical examples, because I believe not to teach secure programming is a great oversight in today's education. Not only the programmers in large companies have to be aware of security impacts, but also their future employees and their freelance programmers. I'm with a large organization of freelance programmers, which I want to make aware of security flaws.&lt;br /&gt;
&lt;br /&gt;
The Ruby on Rails Security project [http://www.rorsecurity.info/] started this year and is the only security initiative for Ruby on Rails. Ruby is the fastest growing level A programming language, according to the Tiobe programming community index [http://www.tiobe.com/tpci.htm], partly because of its advertised simplicity. This is dangerous, as programmers could be enticed to do cargo cult programming [http://en.wikipedia.org/wiki/Cargo_cult_programming] without knowing the security impacts. I found several security holes in popular modules, and even the Rails framework itself generates potentially insecure code. Nevertheless, Rails provides good means against many of the OWASP Top Ten security flaws, but I believe these means have to be popularized much more.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Objectives and Deliverables===&lt;br /&gt;
* Create a security guide to the most popular web server software, Apache&lt;br /&gt;
** Installation&lt;br /&gt;
** secure configuration, emphasis on Rails, but not limited to it&lt;br /&gt;
** file system privileges for Rails and Apache&lt;br /&gt;
** anti profiling techniques for Apache&lt;br /&gt;
** Modules and Mod_security configuration&lt;br /&gt;
&lt;br /&gt;
* Create a security guide to the popular database software, MySQL, as practical contribution to the OWASP Top 10 Insecure storage section&lt;br /&gt;
** Installation&lt;br /&gt;
** secure configuration, emphasis on Rails, but not limited to it&lt;br /&gt;
** file system privileges for Rails and MySQL&lt;br /&gt;
** MySQL access restriction techniques&lt;br /&gt;
** encryption methods&lt;br /&gt;
&lt;br /&gt;
* Ruby on Rails security guide and code examples, with at least the following topics:&lt;br /&gt;
** Anti profiling techniques&lt;br /&gt;
** Rails routes security&lt;br /&gt;
** error handling and presentation, as in OWASP Top 10 Improper Error Handling&lt;br /&gt;
** OWASP Top 10: XSS in Rails&lt;br /&gt;
** OWASP Top 10: SQL injection in Rails&lt;br /&gt;
** OWASP Top 10: Parameter injection in Rails&lt;br /&gt;
** OWASP Top 10: Session handling in Rails&lt;br /&gt;
** OWASP Top 10: Access control in Rails&lt;br /&gt;
** handling of files&lt;br /&gt;
** integrity&lt;br /&gt;
** encryption and SSL&lt;br /&gt;
** logging flaws&lt;br /&gt;
** Ajax security&lt;br /&gt;
&lt;br /&gt;
* Code &amp;amp; other&lt;br /&gt;
** means to check the security of MySQL&lt;br /&gt;
** input validation guide, and implement it in Ruby&lt;br /&gt;
** update the poorly documented guide at http://manuals.rubyonrails.com/read/chapter/40 which is the only official guide to security&lt;br /&gt;
** usage guide for OWASP tools, also in connection with Rails&lt;br /&gt;
** make the results known in the several communities I'm in&lt;br /&gt;
** if applicable: submit code to Rails for security holes found&lt;br /&gt;
&lt;br /&gt;
===Why I should be sponsored for the project===&lt;br /&gt;
I have been programming professionally for 10 years and created several software products, including Internet applications, and I always focused on security. I am currently graduating university, my thesis is about web application security. Recently, I started the Ruby on Rails security project, which is the only security project for Rails. I have always delivered my work on time, and I believe I have the knowledge to deliver good quality.&lt;br /&gt;
&lt;br /&gt;
===Long-term vision for the project===&lt;br /&gt;
Make it available to the community and accept security notices and best practices from other users to constantly improve it.&lt;br /&gt;
&lt;br /&gt;
===Benefits to the OWASP===&lt;br /&gt;
* practical guides on how to put security into practice: the most popular web server software Apache and the popular database software MySQL&lt;br /&gt;
* if applicable: additional examples and chapters for the OWASP Guide&lt;br /&gt;
* the first and only fully-fledged security guide to a programming language and framework which is used by many large companies&lt;br /&gt;
* security awareness of future employees and freelancers&lt;br /&gt;
* more exposure of the OWASP&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:Ruby_on_Rails&amp;diff=16625</id>
		<title>Category:Ruby on Rails</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:Ruby_on_Rails&amp;diff=16625"/>
				<updated>2007-02-21T22:38:57Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Many share the perception of Rails being a &amp;quot;secure&amp;quot; framework.&lt;br /&gt;
And that might well be true, because we need less code to get things done and less&lt;br /&gt;
code means a better overview of what's happening.&lt;br /&gt;
But though Rails seems to be safer, doesn't allow to lean back. There has&lt;br /&gt;
been a [http://weblog.rubyonrails.org/2006/8/10/rails-1-1-6-backports-and-full-disclosure security bug] ([http://blog.evanweaver.com/articles/2006/08/12/anatomy-of-an-attack-against-1-1-4 more detailed]) in Rails last year and even in [http://www.ruby-lang.org/en/news/2006/11/03/CVE-2006-5467/ Ruby].&lt;br /&gt;
&lt;br /&gt;
'''Starting point'''&lt;br /&gt;
As a good starting point, here's a good Ruby on Rails example, which deliberately&lt;br /&gt;
includes several security vulnerabilities: [http://www.foundstone.com/resources/proddesc/hacmecasino.htm The Hacme Casino]. Especially reading the [http://www.foundstone.com/resources/whitepapers/hacmecasino_userguide.pdf user guide] gives you a good insight on what can go wrong.&lt;br /&gt;
&lt;br /&gt;
'''[http://www.rorsecurity.info More on the Ruby on Rails Security site]'''&lt;br /&gt;
&lt;br /&gt;
[[Category:Technology]]&lt;br /&gt;
[[Category:Language]]&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:Ruby_on_Rails&amp;diff=16621</id>
		<title>Category:Ruby on Rails</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:Ruby_on_Rails&amp;diff=16621"/>
				<updated>2007-02-21T22:35:18Z</updated>
		
		<summary type="html">&lt;p&gt;Hawe: New page: Many share the perception of Rails being a &amp;quot;secure&amp;quot; framework. And that might well be true, because we need less code to get things done and less code means a better overview of what's hap...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Many share the perception of Rails being a &amp;quot;secure&amp;quot; framework.&lt;br /&gt;
And that might well be true, because we need less code to get things done and less&lt;br /&gt;
code means a better overview of what's happening.&lt;br /&gt;
But though Rails seems to be safer, doesn't allow to lean back. There has&lt;br /&gt;
been a [http://weblog.rubyonrails.org/2006/8/10/rails-1-1-6-backports-and-full-disclosure security bug] ([http://blog.evanweaver.com/articles/2006/08/12/anatomy-of-an-attack-against-1-1-4 more detailed]) in Rails last year and even in [http://www.ruby-lang.org/en/news/2006/11/03/CVE-2006-5467/ Ruby].&lt;br /&gt;
&lt;br /&gt;
'''Starting point'''&lt;br /&gt;
As a good starting point, here's a good Ruby on Rails example, which deliberately&lt;br /&gt;
includes several security vulnerabilities: [http://www.foundstone.com/resources/proddesc/hacmecasino.htm The Hacme Casino]. Especially reading the [http://www.foundstone.com/resources/whitepapers/hacmecasino_userguide.pdf user guide] gives you a good insight on what can go wrong.&lt;br /&gt;
&lt;br /&gt;
'''[http://www.rorsecurity.info More on the Ruby on Rails Security site]'''&lt;/div&gt;</summary>
		<author><name>Hawe</name></author>	</entry>

	</feed>