<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Heleng</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Heleng"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Heleng"/>
		<updated>2026-05-10T10:40:58Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=82349</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=82349"/>
				<updated>2010-04-23T21:59:24Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* External Links */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form995438520/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10 Thursday&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210  [http://www.adelphi.edu/visitors/campus.php Campus Map]&amp;lt;i&amp;gt;The University Center is in the center of the campus, all the way to the North (marked as UNC)&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.linkedin.com/in/blakecornell Blake Cornell], OWASP Board Member NY/NJ/LI&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Session Initiation Protocol Bounce Attacks: Enumeration of Networked Addressing and Services With Timing Attacks and Other Vectors&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SIP Bounce Attack is similar in nature to the File Transfer Protocol (FTP) Bounce Attack.  SIP allows an attacker the ability to communicate with any Internet Protocol (IP) address or Fully Qualified Domain Name (FQDN) and their respective UDP or TCP port numbers.  Utilizing precise timing algorithms it is possible to enumerate the address allocation of private networks (2) and determine the state of their ports.   This is possible without authentication.&lt;br /&gt;
&lt;br /&gt;
There is an increasing trend to host SIP services publicly on the internet behind Demilitarized Zones (DMZ), firewalls and Access Control Lists (ACLs).  Having the ability to bounce traffic through a protected system and allowing analysis of response data is quite risky.&lt;br /&gt;
&lt;br /&gt;
If a consumer grade VoIP product were reliably vulnerable to SIP bouncing an attacker could have a plethora of possible zombie proxies to choose from.&lt;br /&gt;
&lt;br /&gt;
These and other risks will be discussed.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
[http://pentest.cryptocity.net/blog/ Dan Guido], OWASP NY/NJ Board Member&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Threat Modeling APT: A discussion of tactics behind recent targeted intrusions.&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;Free pizza and beverage will be provided.  After event networking will be held at a local bar.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for an evening of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://owasptop10.googlecode.com/files/OWASP%20Top%2010%20-%202010.pdf OWASP Top 10 for 2010 was released on April 19, 2010]&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=82348</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=82348"/>
				<updated>2010-04-23T21:58:53Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* External Links */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form995438520/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10 Thursday&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210  [http://www.adelphi.edu/visitors/campus.php Campus Map]&amp;lt;i&amp;gt;The University Center is in the center of the campus, all the way to the North (marked as UNC)&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.linkedin.com/in/blakecornell Blake Cornell], OWASP Board Member NY/NJ/LI&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Session Initiation Protocol Bounce Attacks: Enumeration of Networked Addressing and Services With Timing Attacks and Other Vectors&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SIP Bounce Attack is similar in nature to the File Transfer Protocol (FTP) Bounce Attack.  SIP allows an attacker the ability to communicate with any Internet Protocol (IP) address or Fully Qualified Domain Name (FQDN) and their respective UDP or TCP port numbers.  Utilizing precise timing algorithms it is possible to enumerate the address allocation of private networks (2) and determine the state of their ports.   This is possible without authentication.&lt;br /&gt;
&lt;br /&gt;
There is an increasing trend to host SIP services publicly on the internet behind Demilitarized Zones (DMZ), firewalls and Access Control Lists (ACLs).  Having the ability to bounce traffic through a protected system and allowing analysis of response data is quite risky.&lt;br /&gt;
&lt;br /&gt;
If a consumer grade VoIP product were reliably vulnerable to SIP bouncing an attacker could have a plethora of possible zombie proxies to choose from.&lt;br /&gt;
&lt;br /&gt;
These and other risks will be discussed.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
[http://pentest.cryptocity.net/blog/ Dan Guido], OWASP NY/NJ Board Member&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Threat Modeling APT: A discussion of tactics behind recent targeted intrusions.&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;Free pizza and beverage will be provided.  After event networking will be held at a local bar.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for an evening of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://owasptop10.googlecode.com/files/OWASP%20Top%2010%20-%202010.pdf OWASP Top 10 for 2010]&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78398</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78398"/>
				<updated>2010-02-15T16:11:37Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form995438520/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10 Thursday&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210  [http://www.adelphi.edu/visitors/campus.php Campus Map]&amp;lt;i&amp;gt;The University Center is in the center of the campus, all the way to the North (marked as UNC)&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;Free pizza and beverage will be provided.  After event networking will be held at a local bar.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for an evening of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78397</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78397"/>
				<updated>2010-02-15T16:07:47Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form995438520/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10 Thursday&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210  [http://www.adelphi.edu/visitors/campus.php Campus Map]&amp;lt;i&amp;gt;The University Center is in the center of the campus, all the way to the North (marked as UNC)&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;Free pizza and beverage will be provided.  After Event Networking will be held at a local bar.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a evening of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78394</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78394"/>
				<updated>2010-02-15T15:55:42Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form995438520/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210  [http://www.adelphi.edu/visitors/campus.php Campus Map]&amp;lt;i&amp;gt;The University Center is in the center of the campus, all the way to the North (marked as UNC)&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;Free pizza and beverage will be provided.  After Event Networking will be held at a local bar.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a evening of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78393</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78393"/>
				<updated>2010-02-15T15:33:54Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form995438520/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210  [http://www.adelphi.edu/visitors/campus.php Campus Map]&amp;lt;i&amp;gt;The University Center is in the center of the campus, all the way to the North (marked as UNC)&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;Free pizza and beverage will be provided.  After Event Networking will be held at a local bar.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a day of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78297</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78297"/>
				<updated>2010-02-12T02:24:25Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form933354881/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210  [http://www.adelphi.edu/visitors/campus.php Campus Map]&amp;lt;i&amp;gt;The University Center is in the center of the campus, all the way to the North (marked as UNC)&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;Free pizza and beverage will be provided.  After Event Networking will be held at a local bar.&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a day of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78296</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78296"/>
				<updated>2010-02-12T02:22:46Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form933354881/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210  [http://www.adelphi.edu/visitors/campus.php Campus Map]&amp;lt;i&amp;gt;The University Center is in the center of the campus, all the way to the North (marked as UNC)&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;After Event Networking will be held at a local bar&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a day of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78295</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78295"/>
				<updated>2010-02-12T02:21:28Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form933354881/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210  [http://www.adelphi.edu/visitors/campus.php Campus Map]The University Center is in the center of the campus, all the way to the North (marked as UNC)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;After Event Networking will be held at a local bar&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a day of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78294</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78294"/>
				<updated>2010-02-12T02:20:17Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form933354881/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210 [http://www.adelphi.edu/visitors/directions.php Direction]&amp;lt;br&amp;gt;  The University Center is in the center of the campus, all the way to the North (marked as UNC) [http://www.adelphi.edu/visitors/campus.php Campus Map]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;After Event Networking will be held at a local bar&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a day of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78293</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78293"/>
				<updated>2010-02-12T02:18:12Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form933354881/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210 [http://www.adelphi.edu/visitors/directions.php MAP]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495) &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling east&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Traveling west&amp;lt;br&amp;gt;&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Speakers: (TBD)&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;After Event Networking will be held at a local bar&amp;lt;/i&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a day of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78292</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=78292"/>
				<updated>2010-02-12T02:13:00Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form933354881/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  3/18/10&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  6:30 - 8pm&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Adelphi Garden City Campus  Ruth S. Harley University Center, room 210 [http://www.adelphi.edu/visitors/directions.php MAP]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Via the Long Island Expressway (Route 495)&lt;br /&gt;
Traveling east&lt;br /&gt;
Take the L.I.E. to Exit 34 South or the Northern State Parkway to Exit 26 South (New Hyde Park Road). Turn right onto New Hyde Park Road. Continue south on New Hyde Park Road for approximately 3 miles. Turn left onto Stewart Avenue. At the fourth light, turn right onto Nassau Boulevard. Continue approximately for a quarter of a mile. At the first light (as soon as you cross over the railroad tracks), make a left onto South Avenue. The entrance to campus will be on your right.&lt;br /&gt;
&lt;br /&gt;
Traveling west&lt;br /&gt;
Take the L.I.E. to Exit 39 South or the Northern State Parkway to Exit 31 (Glen Cove Road). Go south. (Note: the road will change from Guinea Woods Road to Glen Cove Road to Clinton Road). Turn right onto Stewart Avenue. Go one mile and at T-junction turn left onto Hilton Avenue. Immediately after crossing the railroad tracks, turn right onto Sixth Street. Continue onto South Avenue. The entrance to campus will be on your left..&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;u&amp;gt;Speakers(TBD)&amp;lt;/u&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;After Event Networking will be held at a local bar&amp;lt;/u&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a day of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Internationalization&amp;diff=77015</id>
		<title>OWASP Internationalization</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Internationalization&amp;diff=77015"/>
				<updated>2010-01-27T23:07:27Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt; [[:Project Information:template Internationalization Guidelines|Click here to see (&amp;amp;amp; edit, if wanted) the template.]] {{:Project Information:template Internationalization Guidelines}} &lt;br /&gt;
&lt;br /&gt;
=== Why this project? ===&lt;br /&gt;
&lt;br /&gt;
The main goal of OWASP is to spread the word about security (“Our mission is to make application security &amp;quot;visible,&amp;quot; so that people and organizations can make informed decisions about application security risks.”) and OWASP has done great work so far. The number of native and secondary speakers in the world for Chinese, Spanish, French, Russian, Arabic and Indi languages are estimated in similar number to English speaking or even more (Some References at [http://en.wikipedia.org/wiki/Ethnologue_list_of_most_spoken_languages Ethnologue], [http://encarta.msn.com/media_701500404/Languages_Spoken_by_More_Than_10_Million_People.html Encarta], [http://en.wikipedia.org/wiki/List_of_languages_by_number_of_native_speakers Wikipedia]). It is a good time for OWASP to reach those that do not speak English to have full access to all the OWASP materials, not just a couple of documents. &lt;br /&gt;
&lt;br /&gt;
=== Objectives ===&lt;br /&gt;
&lt;br /&gt;
This project is the pioneer of an effort to define basic guidelines for the localization of OWASP site and OWASP projects (both documentation and software). Also define a way to do a continuous effort to keep information across the different languages in synchrony. &amp;lt;br&amp;gt; The main objective is to provide a framework for new translation efforts, those effort will have 2 main objectives: &lt;br /&gt;
&lt;br /&gt;
#Make OWASP information currently available, reach the people speaking of a specific language &lt;br /&gt;
#Allow non-English speaking people to contribute to OWASP and have internationalization projects transfer that knowledge to English and other languages. So as you can imagine the replication effect will have great benefits to the OWASP community and the world of application security.&lt;br /&gt;
&lt;br /&gt;
=== I want to translate OWASP Materials to [Put your language here], Where should I start? ===&lt;br /&gt;
&lt;br /&gt;
Good for you, we are always happy to have more people to spread the OWASP message. Our suggestion is: &lt;br /&gt;
&lt;br /&gt;
#You Identify the project you like or can translate, you can go to page or contact [[User:Paulo Coimbra|Paulo Coimbra]] for a suggestion (he manages all the OWASP projects). Check [[#Active_Translation_Projects]] to see if there is an existing or ongoing translation to the materials you want to translate, ask the language project mailing list (OWASP-Spanish mailing list) or the material project leader (e.g OWASP Top 10 Leader, Dave Wickers) &lt;br /&gt;
#Check if there is an existent Language-specific project, that is look for a [[OWASP_Spanish]] project if you are willing to translate to Spanish, There might be existing guidelines to help you out do the translation smoothly. &lt;br /&gt;
#Choose you approach: &lt;br /&gt;
#*If you want to translate only a small document or one page, just go and do it, follow the Language guidelines or [[#General_Translation_Guidelines]] below. &lt;br /&gt;
#*If you want to translate various documents, consider to [[#Creating a Language Specific OWASP Project | create a Language-Specific Project]] that way there will be a solid baseline for all the translations. &lt;br /&gt;
#That's it&lt;br /&gt;
&lt;br /&gt;
=== Creating a Language Specific OWASP Project ===&lt;br /&gt;
&lt;br /&gt;
If you have decided to start a formal project to host all the translations to your native/desired language, here is what you have to do. &lt;br /&gt;
&lt;br /&gt;
#Follow the [[How to Start an OWASP Project|How to Start an OWASP Project]] page instructions, we suggest you call the project as the language not the country, e.g. OWASP-Spanish not OWASP-Spain, as languages use to spread across more than just one country. &lt;br /&gt;
#Create a new translation guidelines (for documents, pages and tools) based on the [[#General_Translation_Guidelines]] below. It should include all the knowledge needed to make a quality translation in your native languages. Make sure to provide the necessary resources to at least avoid common pitfalls like false cognates and similar. &lt;br /&gt;
#Link your language specific project to this project, add a reference in &amp;quot;Related Projects&amp;quot; section at top template of this page&lt;br /&gt;
#Ask OWASP Wiki Admin (Larry Casey in this case) to enable your language in the Wiki Site, in case is not available in the languages list. &lt;br /&gt;
#OWASP is open and and you are free to modify or add new content to OWASP Materials, however it is always recommendable to contact project leaders and let them know on your intentions before you start a translation effort, at least as a courtesy.&lt;br /&gt;
#Update this page. Please feel free to modify this page, or add new pages if required, for your specific language. But make the content generic to the language family of your language as the idea of this project is to be used as a framework to develop language specific information. &lt;br /&gt;
&lt;br /&gt;
'''Remember Language projects could be more than just translating, the idea is that knowledge in your native language could also be brought to English speaking people, so think on the project as a link between both languages.''' &lt;br /&gt;
&lt;br /&gt;
=== General Translation Guidelines ===&lt;br /&gt;
&lt;br /&gt;
Usually a document translation involves several people in order to facilitate the translation it is necessary to provide general guidelines for the translation. First of all, we strongly support language neutrality, this is especially important when the language is spoken in many different countries or regions. &lt;br /&gt;
&lt;br /&gt;
Translation guidelines should include the following information: &lt;br /&gt;
&lt;br /&gt;
*Glossaries for the target language, &lt;br /&gt;
*Basic orthography rules &lt;br /&gt;
*Basic grammar rules &lt;br /&gt;
*English-Target Language dictionary. &lt;br /&gt;
*Enumeration and examples of special cases, for example use of dashes, quotes, etc. &lt;br /&gt;
*False cognates &lt;br /&gt;
*Remind the translation must remain loyal to the original text, do not add content to the document (at least on this stage)+ &lt;br /&gt;
*Recommendation to avoid slang language &lt;br /&gt;
*Policy for using automated tools &lt;br /&gt;
*Rules to handle terms that cannot be translated. &lt;br /&gt;
*Recommend to run Spell and Grammar check &lt;br /&gt;
*Examples to the rules described &lt;br /&gt;
*Include a peer review strategy &lt;br /&gt;
*Supportive readings and links&lt;br /&gt;
&lt;br /&gt;
+ Although the objective of the project is to enable people speaking foreign languages to learn from OWASP and enrich OWASP documentation. This process must be done in separated stages, initially it is desirable to have a loyal version of the official release. &lt;br /&gt;
&lt;br /&gt;
We strongly suggest you ask for help of an experienced person to give the document a final look before it is published to OWASP site. &lt;br /&gt;
&lt;br /&gt;
=== Organization ===&lt;br /&gt;
&lt;br /&gt;
The first thing is to have a good communication and coordination strategy, we propose the following organization for a translation effort: &lt;br /&gt;
&lt;br /&gt;
==== Roles ====&lt;br /&gt;
&lt;br /&gt;
Although OWASP is an open project, minimum skills should be procured to ensure the translation has good quality and takes just the needed amount of time. Believe me, you won’t like to fix dozens of small mistakes for common computer world terms just because the translator is a totally outside the computer world with null knowledge on what is a hard disk&amp;amp;nbsp;:). &lt;br /&gt;
&lt;br /&gt;
The proposed skills are: &lt;br /&gt;
&lt;br /&gt;
*'''Translator(s)''' &lt;br /&gt;
**Basic computer related knowledge. &lt;br /&gt;
**Good English skills &lt;br /&gt;
**Fluent in foreign language &lt;br /&gt;
**Working knowledge in application security skills &lt;br /&gt;
*'''Editor(s)''' &lt;br /&gt;
**Strong computer related knowledge &lt;br /&gt;
**Strong English skills &lt;br /&gt;
**Strong skills in foreign language, participation in translation project of other open source projects is a plus. &lt;br /&gt;
**Strong knowledge in application security skills &lt;br /&gt;
*'''Translation leader.''' Person in charge of coordinate the translation effort. There are no special requirements, just the ability to manage a team of people and deliver on proposed time.&lt;br /&gt;
&lt;br /&gt;
=== Translating Documents ===&lt;br /&gt;
&lt;br /&gt;
This is the first release of the section, expect changed during the following weeks as we are requesting feedback from people involved in previous translations of OWASP documents, if you know one of these people please ask them to contact [mailto:johnccr@yahoo.com me] &lt;br /&gt;
&lt;br /&gt;
==== Setup ====&lt;br /&gt;
&lt;br /&gt;
Translation Project leader and/or translation leader should create set of basic guidelines for translation as defined in [[#General_Translation_Guidelines]] section If the translation is going to be on a MS Word document is highly recommended to create a document template with web established styles for headers, so consolidating the document is easier The translation leader will distribute the work and set up tentative due dates for the sections based on the translators workload. &lt;br /&gt;
&lt;br /&gt;
==== While Translating ====&lt;br /&gt;
&lt;br /&gt;
It is suggested that once the distributed sections are ready, they are sent to the distribution list and the editor is notified &lt;br /&gt;
&lt;br /&gt;
==== Before Delivering ====&lt;br /&gt;
&lt;br /&gt;
In parallel to translation or after everyone has finished, the editor (or the person designated by the editor) will do the following actions &lt;br /&gt;
&lt;br /&gt;
*Consolidate the whole document &lt;br /&gt;
*Do spelling and grammar check &lt;br /&gt;
*Ensure document &amp;quot;harmony&amp;quot;. This is: &lt;br /&gt;
**make sure the same terms are using across the document &lt;br /&gt;
**topics sequence is natural. &lt;br /&gt;
**Font type, size and style are the same for the same types of text. &lt;br /&gt;
*Add the official cover page translated to the foreign language (OWASP logo, title and trademark information) &lt;br /&gt;
*Add GNU license (all the OWASP work is done under this license so translation work should also be GNU) &lt;br /&gt;
*Add OWASP internationalization project and the specific translation project explanation and references to let readers know where they go in case of interest in the translation project. Add this page after cover page. &lt;br /&gt;
*Add translation credit for project leader, editor and translators just after the author name. &lt;br /&gt;
*Convert the document to PDF format for portability, but also let the editable version available to the public.&lt;br /&gt;
&lt;br /&gt;
Finally If there is a translation project, you can send the document to the project leader for its publication in the translation project and in the original project page. &lt;br /&gt;
&lt;br /&gt;
=== Translating OWASP pages ===&lt;br /&gt;
&lt;br /&gt;
To make more clear the process of creating a translated page, consider the following assumptions. Our example foreign language code is “es” for Spanish and the page we want to translate is called “TranslationTest”. (Actually this page is there for you to use it ans tes for translation support of the portal on your specific language). So let’s start &lt;br /&gt;
&lt;br /&gt;
You should first classify the page to translate as a main page (project description page, project content page) or support page (roadmap, links, quotes, etc) &lt;br /&gt;
&lt;br /&gt;
==== For Main Pages (project pages only) ====&lt;br /&gt;
&lt;br /&gt;
#Add a new page called “PruebaTraduccion” (“Translation Test” in Spanish) &lt;br /&gt;
#At the beginning of the page add the TranslatedPageHeader template by adding ''&amp;lt;nowiki&amp;gt;{{TranslatedPageHeader}}&amp;lt;/nowiki&amp;gt;'' &lt;br /&gt;
#At the end of the page add the TranslationInProgress template by adding ''&amp;lt;nowiki&amp;gt;{{TranslationInProgress}}&amp;lt;/nowiki&amp;gt;'' in page code. &lt;br /&gt;
#Go to “TranslationTest” page and click on “View Source” tab. &lt;br /&gt;
#Copy the source code and start translating it locally. Then paste it in “PruebaTraduccion” page as you progress. &lt;br /&gt;
#If there is links to pages that are not translated, let the reader know by adding a “(In English only)” note after the link. &lt;br /&gt;
#Just before the end of the page, add a recognition section for the people that helped in the translation. Make sure to mention their role in the translation, their full name and Security certifications, refain to mention companies unless they are OWASP members or you have permission from OWASP Board to mention them. &lt;br /&gt;
#Once you are done remove the TranslationInProgress template in “PruebaTraduccion” page. &lt;br /&gt;
#Add a new sub-page for “TranslationTest” using your language code. This is, for Spanish, you should create a sub-page called “TranslationTest/es”. &lt;br /&gt;
#In “TranslationTest/es” page just enter the following redirect statement ''&amp;lt;nowiki&amp;gt;#REDIRECT [[PruebaTraduccion]]&amp;lt;/nowiki&amp;gt;''&lt;br /&gt;
&lt;br /&gt;
==== For Support Pages ====&lt;br /&gt;
&lt;br /&gt;
For support pages, you do not need to add a third page in the foreign language (like PruebaTraduccion in previous example). Rather, you add the translated content directly to the “TranslationTest/es” page. Adding the ''TranslatedPageHeader'' is also not necessary. &lt;br /&gt;
&lt;br /&gt;
==== Translating Links ====&lt;br /&gt;
&lt;br /&gt;
Similar to templates, links are enclosed in special characters, in this case square braces. There are 2 types of links, external links will look like this &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;[http://www.mediawiki.org/wiki/Help:Templates here]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
And should be translated as Links like this &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;[http://www.mediawiki.org/wiki/Help:Templates aqui]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Internal links, or links that point to pages in the OWASP site will look like this &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;[[OWASP WebGoat Project Roadmap|Roadmap]]&amp;lt;/nowiki&amp;gt; &lt;br /&gt;
&lt;br /&gt;
And should be translated to &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;[[OWASP WebGoat Project Roadmap|Plan de trabajo]]&amp;lt;/nowiki&amp;gt; &lt;br /&gt;
&lt;br /&gt;
For links without the second part (the one after the pipe character) just add it, '''Avoid changing the content if this is case otherwise you will break the link or link to a non existent page'''. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Translating Templates ====&lt;br /&gt;
&lt;br /&gt;
Templates are an special type of pages that can be included as part of regular pages contents, you can learn more about them [http://www.mediawiki.org/wiki/Help:Templates here], you can identify it in wiki code as text enclosed in curly braces like the following: &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;{{OWASP Book|1416452}}&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To access wiki code of the template above you have to go to http://www.owasp.org/index.php/Template:MainLink. Templates do not support &amp;quot;/es&amp;quot; for translations as regular pages, instead we need to use special tags to support multiple languages in the same page. So edit the template code and change it from: &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;[[{{{1}}}| Main&amp;lt;br&amp;gt;({{{1}}})]]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To &lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
&amp;lt;IfLanguage Is=&amp;quot;en&amp;quot;&amp;gt;&lt;br /&gt;
[[{{{1}}}| Main&amp;lt;br&amp;gt;({{{1}}})]]&lt;br /&gt;
&amp;lt;/IfLanguage&amp;gt;&lt;br /&gt;
&amp;lt;IfLanguage Is=&amp;quot;es&amp;quot;&amp;gt;&lt;br /&gt;
[[{{{1}}}| Principal&amp;lt;br&amp;gt;({{{1}}})]]&lt;br /&gt;
&amp;lt;/IfLanguage&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The previous code displays the text in the first ''IfLanguage'' tag to people with browsers in English and the second to people with browsers in Spanish language. &lt;br /&gt;
&lt;br /&gt;
That is it. Now visitors with browsers configured in your foreign language will be automatically redirected to the page in that language. &lt;br /&gt;
&lt;br /&gt;
=== Tracking Changes in Pages ===&lt;br /&gt;
&lt;br /&gt;
In order to track changes of pages for a translation project to keep translated pages up to date, you have to track changes doing the following: &lt;br /&gt;
&lt;br /&gt;
#Login to OWASP Portal (register if you haven't, its free!) &lt;br /&gt;
#Go to the page you want to track and click on the &amp;quot;watch&amp;quot; tab. After that you will be able to see all the change to that page at the [[Special:Watchlist|Watchlist special page]]. &lt;br /&gt;
#You can always go back to the [[Special:Watchlist|Watchlist special page]] by clicking on [[Special:Specialpages|Special Pages]] link at the left bottom of the site. and then click on the [[Special:Watchlist|Watchlist special page]].&lt;br /&gt;
&lt;br /&gt;
There is a drawback, you will have to click the watch tab for every single page you want to track. This simple process will be enough to keep track of pages updates. &lt;br /&gt;
&lt;br /&gt;
You can find more information on here:&amp;lt;br&amp;gt; http://www.mediawiki.org/wiki/Help:Tracking_changes&amp;lt;br&amp;gt; http://meta.wikimedia.org/wiki/Help:Contents#For_readers &lt;br /&gt;
&lt;br /&gt;
=== Translating OWASP Software ===&lt;br /&gt;
&lt;br /&gt;
Here you can find a series of basic guidelines document to help you make your OWASP tool project internationalizable. &lt;br /&gt;
&lt;br /&gt;
The guidelines are available for: &lt;br /&gt;
&lt;br /&gt;
*[[OWASP Internationalization Java Software|Java]]&lt;br /&gt;
&lt;br /&gt;
=== Active Translation Projects ===&lt;br /&gt;
&lt;br /&gt;
*[[OWASP Spanish|Spanish]]&lt;br /&gt;
&lt;br /&gt;
===Future Plans ===&lt;br /&gt;
&lt;br /&gt;
*Have people that help us ot enhance the guidelines and develop recommendations for arabic, slavic(Russian, Polish), ideographic (Chinese), Hindi and Japaneese (among others).&lt;br /&gt;
&lt;br /&gt;
=== News  ===&lt;br /&gt;
&lt;br /&gt;
'''23rd Jan 2010: OWASP Newsletter has been translated into Chinese by [mailto:heleng(at)owasp.org Helen Gao]'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''24th Nov 2009: Weilin Zong will translate ASVS and create the Chinese guidelines for future translations'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''5th May 2008: First Draft of General Translation Guidelines are published''' RC1 of general recommendations to start a translation of an OWASP document in a foreign language is released.&amp;lt;br&amp;gt; '''5th May 2008: Translating an OWASP document section is added''' Guidelines on how to do a document translation is released.&amp;lt;br&amp;gt;&lt;br /&gt;
'''7th April 2008: The OWASP Internationalization project starts''' Juan Carlos Calderon starts the effort as part of the [[OWASP Summer of Code 2008|SoC 2008]].&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SoC 2008 Road map ===&lt;br /&gt;
&lt;br /&gt;
This information is included just as reference &lt;br /&gt;
&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;3&amp;quot; border=&amp;quot;1&amp;quot; style=&amp;quot;border: 1px solid black;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;border-left: 1px solid black;&amp;quot; | Objective&lt;br /&gt;
! Status&lt;br /&gt;
! (Expected) Competition Date&lt;br /&gt;
! Evidence&lt;br /&gt;
|-&lt;br /&gt;
| 1. Team up with Larry Casey to implement Multi language support in OWASP.org Mediawiki.&lt;br /&gt;
| Done&lt;br /&gt;
| June 20, 2008&lt;br /&gt;
| [[PaginaPrincipal]]&lt;br /&gt;
|-&lt;br /&gt;
| 2. General Guidelines on minimum/recommended requirements to start a new language translation for OWASP Document and Site Pages.&lt;br /&gt;
| Done&lt;br /&gt;
| May 2nd, 2008&lt;br /&gt;
| [[#General_Translation_Guidelines]]&lt;br /&gt;
|-&lt;br /&gt;
| 3. General Guidelines on minimum/recommended requirements to implement internationalization and localization ([http://www.w3.org/International/ i18n]) on OWASP Software.&lt;br /&gt;
| Done&lt;br /&gt;
| Sep 4, 2008&lt;br /&gt;
| [[OWASP Internationalization Java Software]]&lt;br /&gt;
|-&lt;br /&gt;
| 4. Create a Communication strategy to help and keep track on new pages or changes in significant pages so all the translations are in sync.&lt;br /&gt;
| Done&lt;br /&gt;
| Sep 3, 2008&lt;br /&gt;
| [[#Tracking_Changes_in_Pages]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project]]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=71096</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=71096"/>
				<updated>2009-10-08T12:56:25Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
RSVP REQUESTED [http://fs18.formsite.com/owaspli/form933354881/index.html http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  10/24/2009&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  11:00-14:00&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Sunrise Business Center, 3500 Sunrise Hwy, Great River, NY 11730, Building 200 [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=3500+Sunrise+Hwy,+NY,+Great+River,+NY,+Building+200&amp;amp;sll=40.748249,-73.163388&amp;amp;sspn=0.009298,0.022745&amp;amp;ie=UTF8&amp;amp;ll=40.748249,-73.163388&amp;amp;spn=0.009298,0.022745&amp;amp;t=h&amp;amp;z=16&amp;amp;iwloc=A MAP]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Enter from the service road on the East Bound side of Sunrise Hwy.  Turn right after passing the security gate.  Attendees can park in front of Building 200 and enter through the Building 200 entrance.  We must ask that all attendees do not park in any spot marked as RESERVED.  Once you enter building 200, pass through security, turn right and head down the hall, pass through the first set of doors.  Our conference room is your first right.  There will be signs posted along this path directing attendees to the room.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;u&amp;gt;Agenda:&amp;lt;/u&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
;11-00 - Opening Remarks &amp;amp; Welcome to [http://www.owasp.org/images/9/9f/2009-OWASP_KeyNote-V2.pdf OWASP Foundation]&lt;br /&gt;
:--'''Helen Gao, OWASP LI Board  &lt;br /&gt;
;11-20 - Attacking VoIP With The OWASP Top 10&lt;br /&gt;
:VoIP systems allow for cheap and easy telephony communication.  Current VoIP implementations may be more vulnerable then you believe.  How could an attacker own your PBX with the OWASP Top 10?  Topics will include Vulnerability Research, Protocol Fuzzing, VoIP and the OWASP Top 10.  Proof of concept zero day vectors will be discovered and exploited.  This is going to be fun!&lt;br /&gt;
:--'''[http://www.linkedin.com/in/blakecornell Blake Cornell] Security Consultant [http://www.net2s-us.com/ Net2S/BT-INS], OWASP NY/NJ/LI Board Member&lt;br /&gt;
&lt;br /&gt;
;12-10 - Lunch&lt;br /&gt;
:&lt;br /&gt;
&lt;br /&gt;
;12-20 - Network Version Control&lt;br /&gt;
:Leveraging Python, Nmap, Ndiff and Subversion to create baselines of your hosts and services.  Together, these form a basic foundation to detect unapproved changes and alert accordingly.&lt;br /&gt;
:--'''[http://www.linkedin.com/pub/ryan-behan/9/746/a12 Ryan Behan], OWASP LI Board Member&lt;br /&gt;
;13-20 - Passive Web Application Analysis &lt;br /&gt;
:Discover ways to leverage the tools you currently use to find potential vulnerabilities in web applications as early as during an initial application walk through. This talk will cover the current state of passive web application analysis as well as discuss how to set up a framework for your own testing needs.&lt;br /&gt;
:--'''[http://www.linkedin.com/in/phillipames Phil Ames], Security Consultant&lt;br /&gt;
&lt;br /&gt;
;All Day Event - Capture the Flag&lt;br /&gt;
:There will be a day long CTF event.  Test your skills, learn new exploitation techniques, hack in a team, get the highest score, win prizes?  Hack the day away with your friends and peers.&lt;br /&gt;
:--'''[http://pentest.cryptocity.net/blog/ Dan Guido], OWASP NY/NJ Board Member&lt;br /&gt;
&lt;br /&gt;
;AFTER EVENT NETWORKING WILL BE HELD AT '''[http://www.bluepointbrewing.com/ THE BLUE POINT BREWERY]!!&lt;br /&gt;
Rides will be provided to the Blue Point Brewery.  When you are done with enjoying the best brews on the East Coast, the train station is only '''[http://maps.google.com/maps?saddr=161+River+Ave,+Patchogue,+NY+11772-3304+(Blue+Point+Brewing+Co)&amp;amp;geocode=CcnpYL67h5V6FVfvbQIdy8el-yEHMT9JQF0-7g&amp;amp;dirflg=&amp;amp;daddr=patchogue+train+station,+patchogue,+ny+11772&amp;amp;f=d&amp;amp;dq=blue+point+brewery,+loc:+patchogue,+ny+11772&amp;amp;sll=40.759127,-73.021493&amp;amp;sspn=0.014359,0.014046&amp;amp;ie=UTF8&amp;amp;ll=40.761691,-73.020887&amp;amp;spn=0.02919,0.055876&amp;amp;z=15 a short walk]''' away!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a day of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local venue TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you can host an upcoming meeting please contact a LI board member.&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=68719</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=68719"/>
				<updated>2009-09-10T12:33:43Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  10/24/2009&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  11:00-14:00&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Sunrise Business Center, 3500 Sunrise Hwy, Great River, NY 11730, Building 200 [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=3500+Sunrise+Hwy,+NY,+Great+River,+NY,+Building+200&amp;amp;sll=40.748249,-73.163388&amp;amp;sspn=0.009298,0.022745&amp;amp;ie=UTF8&amp;amp;ll=40.748249,-73.163388&amp;amp;spn=0.009298,0.022745&amp;amp;t=h&amp;amp;z=16&amp;amp;iwloc=A MAP]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Enter from the service road on the East Bound side of Sunrise Hwy.  Turn right after passing the security gate.  Attendees can park in front of Building 200 and enter through the Building 200 entrance.  We must ask that all attendees do not park in any spot marked as RESERVED.  Once you enter building 200, pass through security, turn right and head down the hall, pass through the first set of doors.  Our conference room is your first right.  There will be signs posted along this path directing attendees to the room.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;u&amp;gt;Agenda:&amp;lt;/u&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
;11-00 - Opening Remarks &amp;amp; Welcome to [http://www.owasp.org/images/9/9f/2009-OWASP_KeyNote-V2.pdf OWASP Foundation]&lt;br /&gt;
:--'''Helen Gao, OWASP LI Board  &lt;br /&gt;
;11-20 - Attacking VoIP With The OWASP Top 10&lt;br /&gt;
:VoIP systems allow for cheap and easy telephony communication.  How can an attacker 0wn your PBX with the OWASP Top 10?  Proof of concept 0day attacks will be demonstrated and detailed.&lt;br /&gt;
:--'''[http://www.linkedin.com/in/blakecornell Blake Cornell] Security Consultant [http://www.net2s-us.com/ Net2S/BT-INS], OWASP NY/NJ/LI Board Member&lt;br /&gt;
&lt;br /&gt;
;12-10 - Lunch&lt;br /&gt;
:&lt;br /&gt;
&lt;br /&gt;
;12-20 - Network Version Control&lt;br /&gt;
:Leveraging Python, Nmap, Ndiff and Subversion to create baselines of your hosts and services.  Together, these form a basic foundation to detect unapproved changes and alert accordingly.&lt;br /&gt;
:--'''[http://www.linkedin.com/pub/ryan-behan/9/746/a12 Ryan Behan], OWASP LI Board Member&lt;br /&gt;
;13-20 - TBD&lt;br /&gt;
:--TBD&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
AFTER EVENT NETWORKING ON THE WATER!!&lt;br /&gt;
&lt;br /&gt;
'''[http://maps.google.com/maps?f=d&amp;amp;source=s_d&amp;amp;saddr=3500+Sunrise+Hwy,+Great+River,+NY+11739&amp;amp;daddr=445+Vanderbilt+Blvd,+Oakdale,+NY+11769-2009&amp;amp;hl=en&amp;amp;geocode=%3BFTN1bQIdVfuj-w&amp;amp;gl=us&amp;amp;mra=ls&amp;amp;sll=40.727859,-73.139371&amp;amp;sspn=0.011155,0.027938&amp;amp;ie=UTF8&amp;amp;ll=40.737925,-73.149204&amp;amp;spn=0.022307,0.055876&amp;amp;t=h&amp;amp;z=15 THE WHARF]&lt;br /&gt;
&lt;br /&gt;
445 Vanderbilt Blvd, Oakdale, NY 11769&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a day of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local restaurant TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=64297</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=64297"/>
				<updated>2009-06-16T12:43:23Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island | extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland | emailarchives=http://lists.owasp.org/pipermail/owasp-longisland }}&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&amp;lt;p style=&amp;quot;margin:0; background:#cef2e0; font-size:120%; font-weight:bold; border:1px solid #a3bfb1; text-align:left; color:#000; padding:0.2em 0.4em; &amp;quot;&amp;gt;Scroll down to see the upcoming Long Island OWASP events&amp;lt;/p&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt;  Saturday June 27th 2009&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt;  10:00-14:00&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Place:&amp;lt;/b&amp;gt;  Sunrise Business Center, 3500 Sunrise Hwy, Great River, NY 11730, Building 200 [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=3500+Sunrise+Hwy,+NY,+Great+River,+NY,+Building+200&amp;amp;sll=40.748249,-73.163388&amp;amp;sspn=0.009298,0.022745&amp;amp;ie=UTF8&amp;amp;ll=40.748249,-73.163388&amp;amp;spn=0.009298,0.022745&amp;amp;t=h&amp;amp;z=16&amp;amp;iwloc=A MAP]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Directions:&amp;lt;/b&amp;gt;  Enter from the service road on the East Bound side of Sunrise Hwy.  Attendees can park in front of Building 200 and enter through the Building 200 entrance.  We must ask that all Attendees do not park in any spot marked as RESERVED.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;RSVP REQUIRED [http://fs18.formsite.com/owaspli/form562038653/index.html http://www.owasp.org/images/7/7f/Register.gif] &amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;u&amp;gt;Agenda:&amp;lt;/u&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
;10-00 - Opening Remarks &amp;amp; Welcome&lt;br /&gt;
:--'''Helen Gao, OWASP LI Board&lt;br /&gt;
;10-20 - Who is OWASP and how could we help you?&lt;br /&gt;
:--'''[http://www.linkedin.com/in/tombrennan Tom Brennan]&lt;br /&gt;
;11-20 - Incident Response - Identify, Contain, Eradicate, Recover, Lessons Learned&lt;br /&gt;
:Breaches happen.  Proper audit compliance enables an organization the ability to detect and prevent attacks.  A case study will be examined.&lt;br /&gt;
:--'''[http://www.linkedin.com/pub/ryan-behan/9/746/a12 Ryan Behan] Manager of Network Technologies at [http://www.ntst.com/ Netsmart Technologies]&lt;br /&gt;
;12-10 - Lunch TBD&lt;br /&gt;
:TBD&lt;br /&gt;
;12-25 - Code Blue - The Unhealthy State of Your Medical Records (And What Can Be Done to Save Them)&lt;br /&gt;
:Millions of patient records have been disclosed to unauthorized third parties.  Some of these records were stolen, some were lost yet all could have been prevented.&lt;br /&gt;
&lt;br /&gt;
:A North Carolina hospital loses a laptop with 14,000 records.  The Peninsula Orthopedic Associates lost backup tapes that help 100,000 patient records.  The Wallgreens Health Initiative emailed 28,000 records to the state of Kentucky without using encryption.  Confiker infects three University of Utah hospitals.  Kaiser fires 15 employees for inappropriately accessing medical records.  Two Scottish hospitals were infected by a computer worm.  Researchers find 20,000 medical records using peer-to-peer software.  The Mytob worm infects 4,700 computers at three UK hospitals.  Confiker infects 8,000 computers at the Sheffield Teaching Hospitals Trust.  Criminals tried to extort Express Scripts with the threat of releasing millions of patient records.  SRA International was breached when malicious software allowed an attacker the ability to access patient data maintained by SRA.  The list goes on.&lt;br /&gt;
&lt;br /&gt;
:All of these incidents were reported in the news within a five month period of each other.  News like this is being reported with an increasing frequency.  &lt;br /&gt;
&lt;br /&gt;
:Most of these incidents could have been easily avoided by conducting compliance audits and vulnerability assessments.&lt;br /&gt;
&lt;br /&gt;
We will walk through some recent incidents involving health care facilities around the world and detail how they could have been prevented.&lt;br /&gt;
:--'''[http://www.linkedin.com/in/blakecornell Blake Cornell] Security Consultant [http://www.net2s-us.com/ Net2S/BT-INS], OWASP NY/NJ/LI Board Member&lt;br /&gt;
;13-25 - Round Table Discussion - Successes, challenges, efforts, hopes and predictions for OWASP Long Island&lt;br /&gt;
:--'''[http://www.linkedin.com/in/tombrennan Tom Brennan], Global Board Member, OWASP Foundation&lt;br /&gt;
:--'''[http://www.linkedin.com/in/helengao Helen Gao], Board Member, OWASP LI&lt;br /&gt;
:--'''[http://www.linkedin.com/pub/ryan-behan/9/746/a12 Ryan Behan], Board Member, OWASP LI&lt;br /&gt;
:--'''[http://www.linkedin.com/in/blakecornell Blake Cornell], Board Member, OWASP NYNJ/LI&lt;br /&gt;
&amp;lt;center&amp;gt;Come prepared for a day of networking with your industry peers.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;We invite all attendees to food and libations after the meeting at a local restaurant TBA.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;To be a co-sponsor for this or a future meeting consider [http://www.owasp.org/index.php/Membership annual chapter sponsorship]&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leaders/Contacts ====&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*[mailto:heleng@owasp.org Helen Gao, CISSP]&lt;br /&gt;
*[mailto:ryan.behan@owasp.org Ryan C Behan]&lt;br /&gt;
*[mailto:blake@owasp.org Blake Cornell] 212-202-6704&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62848</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62848"/>
				<updated>2009-05-27T21:54:35Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* External Links */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island|extra=The chapter leader is [mailto:HelenG@Proginet.com Helen Gao, CISSP]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland|emailarchives=http://lists.owasp.org/pipermail/owasp-longisland}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Long Island&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== 2009 Meetings ==&lt;br /&gt;
&lt;br /&gt;
The next chapter meeting will be held at the end of June, 2009.  Details will be announced soon.  Please check back often for details.&lt;br /&gt;
&lt;br /&gt;
If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;br /&gt;
&lt;br /&gt;
[[Category:New York]]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62847</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62847"/>
				<updated>2009-05-27T21:52:57Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* 2009 Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island|extra=The chapter leader is [mailto:HelenG@Proginet.com Helen Gao, CISSP]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland|emailarchives=http://lists.owasp.org/pipermail/owasp-longisland}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Long Island&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== 2009 Meetings ==&lt;br /&gt;
&lt;br /&gt;
The next chapter meeting will be held at the end of June, 2009.  Details will be announced soon.  Please check back often for details.&lt;br /&gt;
&lt;br /&gt;
If you join our [http://lists.owasp.org/mailman/listinfo/owasp-longisland mailing list], then you will receive details of the meeting as soon as they are finalized.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;br /&gt;
* [http://www.cio.com/archive/030107/fea_security.html Bad Neighborhood from CIO magazine]&lt;br /&gt;
&lt;br /&gt;
[[Category:New York]]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62846</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62846"/>
				<updated>2009-05-27T21:50:03Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* OWASP News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island|extra=The chapter leader is [mailto:HelenG@Proginet.com Helen Gao, CISSP]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland|emailarchives=http://lists.owasp.org/pipermail/owasp-longisland}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Long Island&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== 2009 Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''When''': &lt;br /&gt;
'''Where''':&lt;br /&gt;
'''Speaker''':&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;br /&gt;
* [http://www.cio.com/archive/030107/fea_security.html Bad Neighborhood from CIO magazine]&lt;br /&gt;
&lt;br /&gt;
[[Category:New York]]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62845</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62845"/>
				<updated>2009-05-27T21:49:46Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* OWASP News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island|extra=The chapter leader is [mailto:HelenG@Proginet.com Helen Gao, CISSP]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland|emailarchives=http://lists.owasp.org/pipermail/owasp-longisland}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Long Island&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== 2009 Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''When''': &lt;br /&gt;
'''Where''':&lt;br /&gt;
'''Speaker''':&lt;br /&gt;
&lt;br /&gt;
==OWASP News==&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;br /&gt;
* [http://www.cio.com/archive/030107/fea_security.html Bad Neighborhood from CIO magazine]&lt;br /&gt;
&lt;br /&gt;
[[Category:New York]]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62844</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62844"/>
				<updated>2009-05-27T21:12:51Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* 2009 Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island|extra=The chapter leader is [mailto:HelenG@Proginet.com Helen Gao, CISSP]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland|emailarchives=http://lists.owasp.org/pipermail/owasp-longisland}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Long Island&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== 2009 Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''When''': &lt;br /&gt;
'''Where''':&lt;br /&gt;
'''Speaker''':&lt;br /&gt;
&lt;br /&gt;
==OWASP News==&lt;br /&gt;
&lt;br /&gt;
* [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference OWASP NYC Cyber Security 2008 Conference - Sept 22nd - 25th 2008]&lt;br /&gt;
* [http://www.owasp.org/index.php/OWASP_News OWASP News]&lt;br /&gt;
* [http://www.owasp.org/index.php/OWASP_News OWASP Application Security News]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;br /&gt;
* [http://www.cio.com/archive/030107/fea_security.html Bad Neighborhood from CIO magazine]&lt;br /&gt;
&lt;br /&gt;
[[Category:New York]]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62843</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=62843"/>
				<updated>2009-05-27T21:11:03Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Sponsors */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island|extra=The chapter leader is [mailto:HelenG@Proginet.com Helen Gao, CISSP]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland|emailarchives=http://lists.owasp.org/pipermail/owasp-longisland}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Long Island&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== 2008 Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''When''': &lt;br /&gt;
'''Where''':&lt;br /&gt;
'''Speaker''':&lt;br /&gt;
&lt;br /&gt;
==OWASP News==&lt;br /&gt;
&lt;br /&gt;
* [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference OWASP NYC Cyber Security 2008 Conference - Sept 22nd - 25th 2008]&lt;br /&gt;
* [http://www.owasp.org/index.php/OWASP_News OWASP News]&lt;br /&gt;
* [http://www.owasp.org/index.php/OWASP_News OWASP Application Security News]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.qualityit.net/Resources/WhitePapers/IEEEP1074-2005-RoadmapForOptimizingSecurityInTheSystemAndSoftwareLifeCycle.pdf IEEE considers security as a software lifecycle development requirement]&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;br /&gt;
* [http://www.cio.com/archive/030107/fea_security.html Bad Neighborhood from CIO magazine]&lt;br /&gt;
&lt;br /&gt;
[[Category:New York]]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Reviewing_Code_for_Logging_Issues&amp;diff=15449</id>
		<title>Reviewing Code for Logging Issues</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Reviewing_Code_for_Logging_Issues&amp;diff=15449"/>
				<updated>2007-01-16T17:01:16Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[OWASP Code Review Guide Table of Contents]]__TOC__&lt;br /&gt;
=== In Brief===&lt;br /&gt;
Logging is the recording of information into storage that details who performed what and when they did it (like an audit trail) This can also cover debug messages implemented during development as well as any messages reflecting problems or states within the application. It should be an audit of everything that the business deems important to track about the applications use. Logging provides a detective method to ensure that the other security mechanisms being used are performing correctly. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There are three categories of logs, application, operation system and security software.  While the general principles are similar for all logging needs, the practices stated in this document is specially applicable to application logs.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A good logging strategy should include log generation, storage, protection, analysis and reporting.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Log Generation====&lt;br /&gt;
Logging should be at least done at the following events:&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Authentication: Successful &amp;amp; unsuccessful attempts.&amp;lt;br&amp;gt;&lt;br /&gt;
Authorization requests.&amp;lt;br&amp;gt;&lt;br /&gt;
Data manipulation: Any (CUD) Create, Update, Delete actions performed on the application.&lt;br /&gt;
Session activity: Termination/Logout events.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The application should have the ability to detect and record possible malicious use such as events that cause unexpected errors or defy the state model of the application. Users who attempt to get access to data that they shouldn’t, and incoming data that does not meet validation rules or has been tampered with. In general any error condition which could not occur without an attempt by the user to circumvent the application logic.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Logging should give us the information required to form a proper audit trail of a users actions.&amp;lt;br&amp;gt; &lt;br /&gt;
Leading from this the date/time the actions were performed would be useful.  But make sure the application uses a clock that is synched to a common time source.&lt;br /&gt;
Logging functionality should not log a any personal or sensitive data pertaining to the user of function at hand that is being recorded; An example of this if your application is accepting HTTP GET the payload is in the URL and the GET shall be loged. This may result in logging sensitive data.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Logging should follow best practice regarding data validation; maximum length of information, malicious characters….&amp;lt;br&amp;gt;&lt;br /&gt;
We should ensure that logging functionality only log’s messages of a reasonable length and that this length is enforced.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Log Storage====&lt;br /&gt;
In order to preserve log entries and keep the sizes of log files manageable, log rotation is recommend.  Log rotation means closing a log file and opening a new one when the first file is considered to be either complete or becoming too big.  Log rotation is typically performed according to a schedule (e.g. daily) or when a file reaches a certain size.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Log Protection====&lt;br /&gt;
Because logs contain records of user account and other sensitive information, they need to be protected from breaches of their confidentiality, integrity and availability, the triad of information security.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Log Analysis and Reporting====&lt;br /&gt;
Log analysis is the studying of log entries to identify events of interest or suppress log entries for insignificant events.  Log reporting is the displaying of log analysis.&lt;br /&gt;
Although these are normally the responsibilities of the system administrator, an application must generate logs that are consistent and contains info that will allow the administrator to prioritize the records.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common open source logging solutions:&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Log4J:		 http://logging.apache.org/log4j/docs/index.html&lt;br /&gt;
&lt;br /&gt;
 Log4net:	 http://logging.apache.org/log4net/&lt;br /&gt;
&lt;br /&gt;
 Commons Logging: http://jakarta.apache.org/commons/logging/index.html&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In Tomcat(5.5), if no custom logger is defined (log4J) then everything is logged via Commons Logging and ultimately ends up in catalina.out.&amp;lt;br&amp;gt;&lt;br /&gt;
catalina.out grows endlessly and does not recycle/rollover. Log4J provides “Rollover” functionality, which limits the size of the log. Log4J also gives the option to specify “appenders” which can redirect the log data to other destinations such as a port, syslog or even a database or JMS.&lt;br /&gt;
&lt;br /&gt;
The parts of log4J which should be considered apart from the actual data being logged by the application are contained in the log4j.properties file:&lt;br /&gt;
&lt;br /&gt;
 #&lt;br /&gt;
 # Configures Log4j as the Tomcat system logger&lt;br /&gt;
 #&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # Configure the logger to output info level messages into a rolling log file.&lt;br /&gt;
 #&lt;br /&gt;
 log4j.rootLogger=INFO, R&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # To continue using the &amp;quot;catalina.out&amp;quot; file (which grows forever),&lt;br /&gt;
 # comment out the above line and uncomment the next.&lt;br /&gt;
 #&lt;br /&gt;
 #log4j.rootLogger=ERROR, A1&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # Configuration for standard output (&amp;quot;catalina.out&amp;quot;).&lt;br /&gt;
 #&lt;br /&gt;
 log4j.appender.A1=org.apache.log4j.ConsoleAppender&lt;br /&gt;
 log4j.appender.A1.layout=org.apache.log4j.PatternLayout&lt;br /&gt;
 #&lt;br /&gt;
 # Print the date in ISO 8601 format&lt;br /&gt;
 #&lt;br /&gt;
 log4j.appender.A1.layout.ConversionPattern=%d [%t] %-5p %c - %m%n&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # Configuration for a rolling log file (&amp;quot;tomcat.log&amp;quot;).&lt;br /&gt;
 #&lt;br /&gt;
 log4j.appender.R=org.apache.log4j.DailyRollingFileAppender&lt;br /&gt;
 log4j.appender.R.DatePattern='.'yyyy-MM-dd&lt;br /&gt;
 #&lt;br /&gt;
 # Edit the next line to point to your logs directory.&lt;br /&gt;
 # The last part of the name is the log file name.&lt;br /&gt;
 #&lt;br /&gt;
 log4j.appender.R.File=/usr/local/tomcat/logs/tomcat.log&lt;br /&gt;
 log4j.appender.R.layout=org.apache.log4j.PatternLayout&lt;br /&gt;
 #&lt;br /&gt;
 # Print the date in ISO 8601 format&lt;br /&gt;
 #&lt;br /&gt;
 log4j.appender.R.layout.ConversionPattern=%d [%t] %-5p %c - %m%n&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # Application logging options&lt;br /&gt;
 #&lt;br /&gt;
 #log4j.logger.org.apache=DEBUG&lt;br /&gt;
 #log4j.logger.org.apache=INFO&lt;br /&gt;
 #log4j.logger.org.apache.struts=DEBUG&lt;br /&gt;
 #log4j.logger.org.apache.struts=INFO&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable patterns examples for Logging===&lt;br /&gt;
&lt;br /&gt;
====.NET====&lt;br /&gt;
The following are issues one may look out for or question the development team /deployment team.&lt;br /&gt;
Logging and auditing are detective methods of fraud prevention. Much overlooked in the industry, which enables attackers to continue to attack/commit fraud without being detected.&lt;br /&gt;
&lt;br /&gt;
They cover Windows and .NET issues:&lt;br /&gt;
'''Check that:'''&lt;br /&gt;
#Windows native log puts a timestamp on all log entries.&lt;br /&gt;
#GMT is set as the default time.&lt;br /&gt;
#The Windows operating system can be configured to use network timeservers.&lt;br /&gt;
#By default the event log will show: Name of the computer that generated the event; The application in the source field of the viewer. Additional information such as request identifier,username,and destination should be included in the body of the error event.&lt;br /&gt;
#No sensitive or business critical information is sent to the application logs.&lt;br /&gt;
#Application logs are not located in the web root directory.&lt;br /&gt;
#Log policy allows different levels of log severity.&lt;br /&gt;
&lt;br /&gt;
===== Writing to the Event Log=====&lt;br /&gt;
In the course of reviewing .NET code ensure that calls the EventLog object do not provide any confidential information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 EventLog.WriteEntry( &amp;quot;&amp;lt;password&amp;gt;&amp;quot;,EventLogEntryType.Information);&lt;br /&gt;
&lt;br /&gt;
====JAVA====&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Code Review Project]]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Reviewing_Code_for_Logging_Issues&amp;diff=15448</id>
		<title>Reviewing Code for Logging Issues</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Reviewing_Code_for_Logging_Issues&amp;diff=15448"/>
				<updated>2007-01-16T16:57:59Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* In Brief */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[OWASP Code Review Guide Table of Contents]]__TOC__&lt;br /&gt;
=== In Brief===&lt;br /&gt;
Logging is the recording of information into storage that details who performed what and when they did it (like an audit trail) This can also cover debug messages implemented during development as well as any messages reflecting problems or states within the application. It should be an audit of everything that the business deems important to track about the applications use. Logging provides a detective method to ensure that the other security mechanisms being used are performing correctly. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There are three categories of logs, application, operation system and security software.  While the general principles are similar for all logging needs, the practices stated in this document is specially applicable to application logs.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A good logging strategy should include log generation, storage, protection, analysis and reporting.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Log Generation&amp;lt;br&amp;gt;&lt;br /&gt;
Logging should be at least done at the following events:&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Authentication: Successful &amp;amp; unsuccessful attempts.&amp;lt;br&amp;gt;&lt;br /&gt;
Authorization requests.&amp;lt;br&amp;gt;&lt;br /&gt;
Data manipulation: Any (CUD) Create, Update, Delete actions performed on the application.&lt;br /&gt;
Session activity: Termination/Logout events.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The application should have the ability to detect and record possible malicious use such as events that cause unexpected errors or defy the state model of the application. Users who attempt to get access to data that they shouldn’t, and incoming data that does not meet validation rules or has been tampered with. In general any error condition which could not occur without an attempt by the user to circumvent the application logic.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Logging should give us the information required to form a proper audit trail of a users actions.&amp;lt;br&amp;gt; &lt;br /&gt;
Leading from this the date/time the actions were performed would be useful.  But make sure the application uses a clock that is synched to a common time source.&lt;br /&gt;
Logging functionality should not log a any personal or sensitive data pertaining to the user of function at hand that is being recorded; An example of this if your application is accepting HTTP GET the payload is in the URL and the GET shall be loged. This may result in logging sensitive data.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Logging should follow best practice regarding data validation; maximum length of information, malicious characters….&amp;lt;br&amp;gt;&lt;br /&gt;
We should ensure that logging functionality only log’s messages of a reasonable length and that this length is enforced.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Log Storage[br]&lt;br /&gt;
In order to preserve log entries and keep the sizes of log files manageable, log rotation is recommend.  Log rotation means closing a log file and opening a new one when the first file is considered to be either complete or becoming too big.  Log rotation is typically performed according to a schedule (e.g. daily) or when a file reaches a certain size.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Log Protection&amp;lt;br&amp;gt;&lt;br /&gt;
Because logs contain records of user account and other sensitive information, they need to be protected from breaches of their confidentiality, integrity and availability, the triad of information security.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Log Analysis and Reporting&amp;lt;br&amp;gt;&lt;br /&gt;
Log analysis is the studying of log entries to identify events of interest or suppress log entries for insignificant events.  Log reporting is the displaying of log analysis.&lt;br /&gt;
Although these are normally the responsibilities of the system administrator, an application must generate logs that are consistent and contains info that will allow the administrator to prioritize the records.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common open source logging solutions:&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 Log4J:		 http://logging.apache.org/log4j/docs/index.html&lt;br /&gt;
&lt;br /&gt;
 Log4net:	 http://logging.apache.org/log4net/&lt;br /&gt;
&lt;br /&gt;
 Commons Logging: http://jakarta.apache.org/commons/logging/index.html&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In Tomcat(5.5), if no custom logger is defined (log4J) then everything is logged via Commons Logging and ultimately ends up in catalina.out.&amp;lt;br&amp;gt;&lt;br /&gt;
catalina.out grows endlessly and does not recycle/rollover. Log4J provides “Rollover” functionality, which limits the size of the log. Log4J also gives the option to specify “appenders” which can redirect the log data to other destinations such as a port, syslog or even a database or JMS.&lt;br /&gt;
&lt;br /&gt;
The parts of log4J which should be considered apart from the actual data being logged by the application are contained in the log4j.properties file:&lt;br /&gt;
&lt;br /&gt;
 #&lt;br /&gt;
 # Configures Log4j as the Tomcat system logger&lt;br /&gt;
 #&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # Configure the logger to output info level messages into a rolling log file.&lt;br /&gt;
 #&lt;br /&gt;
 log4j.rootLogger=INFO, R&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # To continue using the &amp;quot;catalina.out&amp;quot; file (which grows forever),&lt;br /&gt;
 # comment out the above line and uncomment the next.&lt;br /&gt;
 #&lt;br /&gt;
 #log4j.rootLogger=ERROR, A1&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # Configuration for standard output (&amp;quot;catalina.out&amp;quot;).&lt;br /&gt;
 #&lt;br /&gt;
 log4j.appender.A1=org.apache.log4j.ConsoleAppender&lt;br /&gt;
 log4j.appender.A1.layout=org.apache.log4j.PatternLayout&lt;br /&gt;
 #&lt;br /&gt;
 # Print the date in ISO 8601 format&lt;br /&gt;
 #&lt;br /&gt;
 log4j.appender.A1.layout.ConversionPattern=%d [%t] %-5p %c - %m%n&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # Configuration for a rolling log file (&amp;quot;tomcat.log&amp;quot;).&lt;br /&gt;
 #&lt;br /&gt;
 log4j.appender.R=org.apache.log4j.DailyRollingFileAppender&lt;br /&gt;
 log4j.appender.R.DatePattern='.'yyyy-MM-dd&lt;br /&gt;
 #&lt;br /&gt;
 # Edit the next line to point to your logs directory.&lt;br /&gt;
 # The last part of the name is the log file name.&lt;br /&gt;
 #&lt;br /&gt;
 log4j.appender.R.File=/usr/local/tomcat/logs/tomcat.log&lt;br /&gt;
 log4j.appender.R.layout=org.apache.log4j.PatternLayout&lt;br /&gt;
 #&lt;br /&gt;
 # Print the date in ISO 8601 format&lt;br /&gt;
 #&lt;br /&gt;
 log4j.appender.R.layout.ConversionPattern=%d [%t] %-5p %c - %m%n&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # Application logging options&lt;br /&gt;
 #&lt;br /&gt;
 #log4j.logger.org.apache=DEBUG&lt;br /&gt;
 #log4j.logger.org.apache=INFO&lt;br /&gt;
 #log4j.logger.org.apache.struts=DEBUG&lt;br /&gt;
 #log4j.logger.org.apache.struts=INFO&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable patterns examples for Logging===&lt;br /&gt;
&lt;br /&gt;
====.NET====&lt;br /&gt;
The following are issues one may look out for or question the development team /deployment team.&lt;br /&gt;
Logging and auditing are detective methods of fraud prevention. Much overlooked in the industry, which enables attackers to continue to attack/commit fraud without being detected.&lt;br /&gt;
&lt;br /&gt;
They cover Windows and .NET issues:&lt;br /&gt;
'''Check that:'''&lt;br /&gt;
#Windows native log puts a timestamp on all log entries.&lt;br /&gt;
#GMT is set as the default time.&lt;br /&gt;
#The Windows operating system can be configured to use network timeservers.&lt;br /&gt;
#By default the event log will show: Name of the computer that generated the event; The application in the source field of the viewer. Additional information such as request identifier,username,and destination should be included in the body of the error event.&lt;br /&gt;
#No sensitive or business critical information is sent to the application logs.&lt;br /&gt;
#Application logs are not located in the web root directory.&lt;br /&gt;
#Log policy allows different levels of log severity.&lt;br /&gt;
&lt;br /&gt;
===== Writing to the Event Log=====&lt;br /&gt;
In the course of reviewing .NET code ensure that calls the EventLog object do not provide any confidential information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 EventLog.WriteEntry( &amp;quot;&amp;lt;password&amp;gt;&amp;quot;,EventLogEntryType.Information);&lt;br /&gt;
&lt;br /&gt;
====JAVA====&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Code Review Project]]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=14249</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=14249"/>
				<updated>2006-12-12T14:39:39Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* External links */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island|extra=The chapter leader is [mailto:HelenG@Proginet.com Helen Gao, CISSP]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland|emailarchives=http://lists.owasp.org/pipermail/owasp-longisland}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''OWASP Moves to MediaWiki Portal - 11:16, 20 May 2006 (EDT)'''&lt;br /&gt;
&lt;br /&gt;
OWASP is pleased to announce the arrival of OWASP 2.0!&lt;br /&gt;
&lt;br /&gt;
OWASP 2.0 utilizes the MediaWiki portal to manage and provide&lt;br /&gt;
the latest OWASP related information. Enjoy!&lt;br /&gt;
&lt;br /&gt;
==External links==&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;br /&gt;
* [http://www.ietf.org/rfc/rfc2828.txt Internet Security Glossary]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=14248</id>
		<title>Long Island</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Long_Island&amp;diff=14248"/>
				<updated>2006-12-12T14:12:21Z</updated>
		
		<summary type="html">&lt;p&gt;Heleng: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Long Island|extra=The chapter leader is [mailto:HelenG@Proginet.com Helen Gao, CISSP]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-longisland|emailarchives=http://lists.owasp.org/pipermail/owasp-longisland}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''OWASP Moves to MediaWiki Portal - 11:16, 20 May 2006 (EDT)'''&lt;br /&gt;
&lt;br /&gt;
OWASP is pleased to announce the arrival of OWASP 2.0!&lt;br /&gt;
&lt;br /&gt;
OWASP 2.0 utilizes the MediaWiki portal to manage and provide&lt;br /&gt;
the latest OWASP related information. Enjoy!&lt;br /&gt;
&lt;br /&gt;
==External links==&lt;br /&gt;
* [http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf OWASP is a recommended secure coding guideline in PCI DSS]&lt;/div&gt;</summary>
		<author><name>Heleng</name></author>	</entry>

	</feed>