<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Joshuaq</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Joshuaq"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Joshuaq"/>
		<updated>2026-05-28T07:38:18Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Joshuaq&amp;diff=87664</id>
		<title>User talk:Joshuaq</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Joshuaq&amp;diff=87664"/>
				<updated>2010-08-16T05:49:29Z</updated>
		
		<summary type="html">&lt;p&gt;Joshuaq: Created page with '&amp;quot;Security Event and Incident Management&amp;quot; Panel Session - 17 August 2010'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;quot;Security Event and Incident Management&amp;quot; Panel Session - 17 August 2010&lt;/div&gt;</summary>
		<author><name>Joshuaq</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=87663</id>
		<title>Perth Australia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=87663"/>
				<updated>2010-08-16T04:37:53Z</updated>
		
		<summary type="html">&lt;p&gt;Joshuaq: /* Upcoming OWASP Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Perth, Western Australia|extra=The chapter leaders are:&lt;br /&gt;
* [http://www.owasp.org/index.php/User:Xntrik Christian Frichot]&lt;br /&gt;
* [mailto:joshua@qwek.com Joshua Qwek]&lt;br /&gt;
* Timothy Bessant&lt;br /&gt;
* [mailto:david.taylor@bankwest.com.au David Taylor]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Perth|emailarchives=http://lists.owasp.org/pipermail/owasp-Perth}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Perth Australia&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Upcoming OWASP Events ==&lt;br /&gt;
&lt;br /&gt;
17 Aug 2010 Topic: &amp;quot;Security Event and Incident Management&amp;quot; Panel Session&lt;br /&gt;
&lt;br /&gt;
Joshua Qwek, one of Perth's OWASP chapter lead, will be one of the panellist in the above event organised by AISA (www.aisa.org.au). &lt;br /&gt;
&lt;br /&gt;
When: 5:15pm&lt;br /&gt;
Where: L7 Training&lt;br /&gt;
Level 14, 256 Adelaide Tce (Septimus Row Square, cnr of Victoria Ave)&lt;br /&gt;
Perth WA 6000&lt;br /&gt;
&lt;br /&gt;
Below is a brief summary from AISA's event page:&lt;br /&gt;
&lt;br /&gt;
Log management is a necessary task in Security Management, but is often neglected. There are various pressures being placed on businesses, such as audit and compliance, industry standards (eg PCI, APRA), internal security maturity which have allowed organisations to understand the benefits to be gained from undertaking a SEIM project.&lt;br /&gt;
&lt;br /&gt;
There are many options for organisations looking to develop log management and security incident response processes, which range from open source syslog solutions, through to vendor supplied SEIM products and cloud based monitoring solutions.&lt;br /&gt;
&lt;br /&gt;
A panel selected from a variety of industries including representation from security consulting, corporate and vendor will discuss the considerations, options and benefits of employing SEIM technology and processes.&lt;br /&gt;
&lt;br /&gt;
Our MC: Steve Schupp - AISA Perth Branch Executive&lt;br /&gt;
&lt;br /&gt;
A panel selected from a variety of industries including representation from security consulting, corporate and vendor will discuss the considerations, options and benefits of employing SEIM technology and processes.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For more event information, please refer to AISA's website.&lt;br /&gt;
&lt;br /&gt;
== Previous OWASP Meetings ==&lt;br /&gt;
&lt;br /&gt;
=== How mature is your software security process? (Perth AISA May 2010) ===&lt;br /&gt;
&lt;br /&gt;
==== [http://www.aisa.org.au/index.php?page=287 AISA Details] ====&lt;br /&gt;
&lt;br /&gt;
As the security industry continues to change its focus to application &lt;br /&gt;
security a lot of companies who rely on software, developed either &lt;br /&gt;
internally or externally, are wondering what they can do reduce the risk &lt;br /&gt;
of security flaws. &lt;br /&gt;
&lt;br /&gt;
Microsoft's Security Development Lifecycle (SDL) model can look &lt;br /&gt;
appealing, however without a clear understanding of what your software &lt;br /&gt;
security processes look like, it may be difficult to achieve any real &lt;br /&gt;
improvements. &lt;br /&gt;
&lt;br /&gt;
Implementing a holistic end-to-end software security process can often &lt;br /&gt;
look like an impossible task, and while the end picture resembles Eden, &lt;br /&gt;
it's often the first steps that everyone stumbles on. As the saying goes &lt;br /&gt;
&amp;quot;You can't manage what you can't measure&amp;quot;, and without a clear &lt;br /&gt;
understanding of what your software security processes look like now it's &lt;br /&gt;
unlikely that you can achieve any real improvements. &lt;br /&gt;
&lt;br /&gt;
OWASP's Open Software Assurance Maturity Model, or OpenSAMM, aims &lt;br /&gt;
to assist organisations, both big and small, in evaluating their existing &lt;br /&gt;
software security practices and constructing a measurable, balanced &lt;br /&gt;
program to increase their software security. &lt;br /&gt;
&lt;br /&gt;
Wondering how this can help your internal development processes? Want &lt;br /&gt;
to have a more rigid process to audit your externally developed software &lt;br /&gt;
processes? Then perhaps OWASP's OpenSAMM project can assist.&lt;br /&gt;
&lt;br /&gt;
This meeting will be co-hosted by both the local AISA chapter and the Perth OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
=== Perth OWASP - Perth AISA Technical Day (Dec 2009) ===&lt;br /&gt;
&lt;br /&gt;
==== [http://www.owasp.org/index.php/File:AISA_Perth_TSD_2009_Brochure_-Final.pdf Brochure] ====&lt;br /&gt;
&lt;br /&gt;
The local OWASP boys will be whipping out their flux capacitor to fit as much information as they possibly can into a 2 hour jam-packed session on web app security testing. By providing a flyby of the OWASP Testing Guide, David and Christian aim to demonstrate and explain how to detect security vulnerabilities in your own web applications, including: Cross Site Scripting; Injection Flaws; Cross Site Request Forgery and Session Management Flaws.&lt;br /&gt;
&lt;br /&gt;
Demonstrations will utilise a number of open source and freely available tools, including OWASP's own WebScarab. To provide a yoga-like flexibility to the session all materials and testing environments (an Ubuntu wrapped VMware virtual machine) will be provided to attendees, allowing you to either chase us rapidly down the rabbit hole of the OWASP Top 10, or to take your own time after the session...&lt;br /&gt;
&lt;br /&gt;
The perfect way to spend a lazy Sunday afternoon.&lt;br /&gt;
&lt;br /&gt;
=== Web-based Malware (Sep 2009) ===&lt;br /&gt;
&lt;br /&gt;
==== About the presenter ====&lt;br /&gt;
Shlomi Cohen joined IBM with the Watchfire acquisition at August 2007.&lt;br /&gt;
Over nine years of experience in web application security in both start-ups and established companies. Emphasis in strategic selling, sales consulting, technical sales and management.&lt;br /&gt;
* Leading the Security solution on the WW Rational Tiger sales team&lt;br /&gt;
* Work with the customers and the local sales team to form the right security solution&lt;br /&gt;
* Development of sale process for multiple products&lt;br /&gt;
* Working closely with customers and the product management team in driving the products roadmaps&lt;br /&gt;
* Assisting IBM’s growth in acquisition portfolio&lt;br /&gt;
&lt;br /&gt;
Previous to the WW Rational Security Solution leader:&lt;br /&gt;
* Managing the technical sales team for Watchfire in the Americas group of IBM&lt;br /&gt;
* Watchfire Security Research team manager - A team responsible for various web application security aspects including web application vulnerability research, security product rule updates, enhanced security feature definition, security audits, customer support, marketing and sales assistance&lt;br /&gt;
* AppShield Development Manager - Managed the development and QA teams for the AppShield product - a client Server Web Application Firewall&lt;br /&gt;
&lt;br /&gt;
=== Threat Modelling in the Software Development Lifecycle (Feb 2009) ===&lt;br /&gt;
&lt;br /&gt;
One of the most important concepts being promoted in the security industry is security in the software development lifecycle. This concept is important due to two primary factors:&lt;br /&gt;
* It is generally recognised that by shifting security activities closer towards the requirements gathering stage, or the design stage, that less vulnerabilities will make their way into the production systems.&lt;br /&gt;
* It is also recognised that the cost of mitigating vulnerabilities increases later in the lifecycle.&lt;br /&gt;
By walking through a case study I hope to demonstrate the effectiveness of addressing risk during the earlier stage of the software development lifecycle, and that these activities are not solely the responsibility of the &amp;quot;security guy&amp;quot;, but all participants in a software project including the project manager, business stakeholders and software designer.&lt;br /&gt;
==== About the presenter ====&lt;br /&gt;
Christian Frichot is currently employed by Bankwest working within the Security Consulting Services team. His core responsibilities include phishing and online fraud response, security assessments, information risk assessments and other ad-hoc information security consulting. Christian hopes to spend more time in '09 focusing on education and application security, where he feels more effort needs to be applied.&lt;br /&gt;
&lt;br /&gt;
-Updated 18/11/09 by [mailto:xntrik@gmail.com Christian Frichot]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:Australia]]&lt;/div&gt;</summary>
		<author><name>Joshuaq</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=87662</id>
		<title>Perth Australia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=87662"/>
				<updated>2010-08-16T04:14:13Z</updated>
		
		<summary type="html">&lt;p&gt;Joshuaq: /* Upcoming OWASP Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Perth, Western Australia|extra=The chapter leaders are:&lt;br /&gt;
* [http://www.owasp.org/index.php/User:Xntrik Christian Frichot]&lt;br /&gt;
* [mailto:joshua@qwek.com Joshua Qwek]&lt;br /&gt;
* Timothy Bessant&lt;br /&gt;
* [mailto:david.taylor@bankwest.com.au David Taylor]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Perth|emailarchives=http://lists.owasp.org/pipermail/owasp-Perth}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Perth Australia&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Upcoming OWASP Events ==&lt;br /&gt;
&lt;br /&gt;
17 Aug 2010 Topic: &amp;quot;Security Event and Incident Management&amp;quot; Panel Session&lt;br /&gt;
&lt;br /&gt;
Joshua Qwek, one of Perth's OWASP chapter lead, will be one of the panelistin the above event organised by AISA (www.aisa.org.au). &lt;br /&gt;
&lt;br /&gt;
When: 5:15pm&lt;br /&gt;
Where: L7 Training&lt;br /&gt;
Level 14, 256 Adelaide Tce (Septimus Row Square, cnr of Victoria Ave)&lt;br /&gt;
Perth WA 6000&lt;br /&gt;
&lt;br /&gt;
Below is a brief summary from AISA's event page:&lt;br /&gt;
''&lt;br /&gt;
Log management is a necessary task in Security Management, but is often neglected. There are various pressures being placed on businesses, such as audit and compliance, industry standards (eg PCI, APRA), internal security maturity which have allowed organisations to understand the benefits to be gained from undertaking a SEIM project.&lt;br /&gt;
&lt;br /&gt;
There are many options for organisations looking to develop log management and security incident response processes, which range from open source syslog solutions, through to vendor supplied SEIM products and cloud based monitoring solutions.&lt;br /&gt;
&lt;br /&gt;
A panel selected from a variety of industries including representation from security consulting, corporate and vendor will discuss the considerations, options and benefits of employing SEIM technology and processes.&lt;br /&gt;
&lt;br /&gt;
Our MC: Steve Schupp - AISA Perth Branch Executive&lt;br /&gt;
&lt;br /&gt;
A panel selected from a variety of industries including representation from security consulting, corporate and vendor will discuss the considerations, options and benefits of employing SEIM technology and processes.&lt;br /&gt;
''&lt;br /&gt;
&lt;br /&gt;
For more event information, please refer to AISA's website.&lt;br /&gt;
&lt;br /&gt;
== Previous OWASP Meetings ==&lt;br /&gt;
&lt;br /&gt;
=== How mature is your software security process? (Perth AISA May 2010) ===&lt;br /&gt;
&lt;br /&gt;
==== [http://www.aisa.org.au/index.php?page=287 AISA Details] ====&lt;br /&gt;
&lt;br /&gt;
As the security industry continues to change its focus to application &lt;br /&gt;
security a lot of companies who rely on software, developed either &lt;br /&gt;
internally or externally, are wondering what they can do reduce the risk &lt;br /&gt;
of security flaws. &lt;br /&gt;
&lt;br /&gt;
Microsoft's Security Development Lifecycle (SDL) model can look &lt;br /&gt;
appealing, however without a clear understanding of what your software &lt;br /&gt;
security processes look like, it may be difficult to achieve any real &lt;br /&gt;
improvements. &lt;br /&gt;
&lt;br /&gt;
Implementing a holistic end-to-end software security process can often &lt;br /&gt;
look like an impossible task, and while the end picture resembles Eden, &lt;br /&gt;
it's often the first steps that everyone stumbles on. As the saying goes &lt;br /&gt;
&amp;quot;You can't manage what you can't measure&amp;quot;, and without a clear &lt;br /&gt;
understanding of what your software security processes look like now it's &lt;br /&gt;
unlikely that you can achieve any real improvements. &lt;br /&gt;
&lt;br /&gt;
OWASP's Open Software Assurance Maturity Model, or OpenSAMM, aims &lt;br /&gt;
to assist organisations, both big and small, in evaluating their existing &lt;br /&gt;
software security practices and constructing a measurable, balanced &lt;br /&gt;
program to increase their software security. &lt;br /&gt;
&lt;br /&gt;
Wondering how this can help your internal development processes? Want &lt;br /&gt;
to have a more rigid process to audit your externally developed software &lt;br /&gt;
processes? Then perhaps OWASP's OpenSAMM project can assist.&lt;br /&gt;
&lt;br /&gt;
This meeting will be co-hosted by both the local AISA chapter and the Perth OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
=== Perth OWASP - Perth AISA Technical Day (Dec 2009) ===&lt;br /&gt;
&lt;br /&gt;
==== [http://www.owasp.org/index.php/File:AISA_Perth_TSD_2009_Brochure_-Final.pdf Brochure] ====&lt;br /&gt;
&lt;br /&gt;
The local OWASP boys will be whipping out their flux capacitor to fit as much information as they possibly can into a 2 hour jam-packed session on web app security testing. By providing a flyby of the OWASP Testing Guide, David and Christian aim to demonstrate and explain how to detect security vulnerabilities in your own web applications, including: Cross Site Scripting; Injection Flaws; Cross Site Request Forgery and Session Management Flaws.&lt;br /&gt;
&lt;br /&gt;
Demonstrations will utilise a number of open source and freely available tools, including OWASP's own WebScarab. To provide a yoga-like flexibility to the session all materials and testing environments (an Ubuntu wrapped VMware virtual machine) will be provided to attendees, allowing you to either chase us rapidly down the rabbit hole of the OWASP Top 10, or to take your own time after the session...&lt;br /&gt;
&lt;br /&gt;
The perfect way to spend a lazy Sunday afternoon.&lt;br /&gt;
&lt;br /&gt;
=== Web-based Malware (Sep 2009) ===&lt;br /&gt;
&lt;br /&gt;
==== About the presenter ====&lt;br /&gt;
Shlomi Cohen joined IBM with the Watchfire acquisition at August 2007.&lt;br /&gt;
Over nine years of experience in web application security in both start-ups and established companies. Emphasis in strategic selling, sales consulting, technical sales and management.&lt;br /&gt;
* Leading the Security solution on the WW Rational Tiger sales team&lt;br /&gt;
* Work with the customers and the local sales team to form the right security solution&lt;br /&gt;
* Development of sale process for multiple products&lt;br /&gt;
* Working closely with customers and the product management team in driving the products roadmaps&lt;br /&gt;
* Assisting IBM’s growth in acquisition portfolio&lt;br /&gt;
&lt;br /&gt;
Previous to the WW Rational Security Solution leader:&lt;br /&gt;
* Managing the technical sales team for Watchfire in the Americas group of IBM&lt;br /&gt;
* Watchfire Security Research team manager - A team responsible for various web application security aspects including web application vulnerability research, security product rule updates, enhanced security feature definition, security audits, customer support, marketing and sales assistance&lt;br /&gt;
* AppShield Development Manager - Managed the development and QA teams for the AppShield product - a client Server Web Application Firewall&lt;br /&gt;
&lt;br /&gt;
=== Threat Modelling in the Software Development Lifecycle (Feb 2009) ===&lt;br /&gt;
&lt;br /&gt;
One of the most important concepts being promoted in the security industry is security in the software development lifecycle. This concept is important due to two primary factors:&lt;br /&gt;
* It is generally recognised that by shifting security activities closer towards the requirements gathering stage, or the design stage, that less vulnerabilities will make their way into the production systems.&lt;br /&gt;
* It is also recognised that the cost of mitigating vulnerabilities increases later in the lifecycle.&lt;br /&gt;
By walking through a case study I hope to demonstrate the effectiveness of addressing risk during the earlier stage of the software development lifecycle, and that these activities are not solely the responsibility of the &amp;quot;security guy&amp;quot;, but all participants in a software project including the project manager, business stakeholders and software designer.&lt;br /&gt;
==== About the presenter ====&lt;br /&gt;
Christian Frichot is currently employed by Bankwest working within the Security Consulting Services team. His core responsibilities include phishing and online fraud response, security assessments, information risk assessments and other ad-hoc information security consulting. Christian hopes to spend more time in '09 focusing on education and application security, where he feels more effort needs to be applied.&lt;br /&gt;
&lt;br /&gt;
-Updated 18/11/09 by [mailto:xntrik@gmail.com Christian Frichot]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:Australia]]&lt;/div&gt;</summary>
		<author><name>Joshuaq</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=87661</id>
		<title>Perth Australia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=87661"/>
				<updated>2010-08-16T04:12:43Z</updated>
		
		<summary type="html">&lt;p&gt;Joshuaq: /* Upcoming OWASP Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Perth, Western Australia|extra=The chapter leaders are:&lt;br /&gt;
* [http://www.owasp.org/index.php/User:Xntrik Christian Frichot]&lt;br /&gt;
* [mailto:joshua@qwek.com Joshua Qwek]&lt;br /&gt;
* Timothy Bessant&lt;br /&gt;
* [mailto:david.taylor@bankwest.com.au David Taylor]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Perth|emailarchives=http://lists.owasp.org/pipermail/owasp-Perth}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Perth Australia&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Upcoming OWASP Events ==&lt;br /&gt;
&lt;br /&gt;
17 Aug 2010 Topic: &amp;quot;Security Event and Incident Management&amp;quot; Panel Session&lt;br /&gt;
Joshua Qwek, one of Perth's OWASP chapter lead, will be one of the panelistin the above event organised by AISA (www.aisa.org.au). Below is a brief summary from AISA's event page:&lt;br /&gt;
''&lt;br /&gt;
Log management is a necessary task in Security Management, but is often neglected. There are various pressures being placed on businesses, such as audit and compliance, industry standards (eg PCI, APRA), internal security maturity which have allowed organisations to understand the benefits to be gained from undertaking a SEIM project.&lt;br /&gt;
&lt;br /&gt;
There are many options for organisations looking to develop log management and security incident response processes, which range from open source syslog solutions, through to vendor supplied SEIM products and cloud based monitoring solutions.&lt;br /&gt;
&lt;br /&gt;
A panel selected from a variety of industries including representation from security consulting, corporate and vendor will discuss the considerations, options and benefits of employing SEIM technology and processes.&lt;br /&gt;
&lt;br /&gt;
Our MC: Steve Schupp - AISA Perth Branch Executive&lt;br /&gt;
&lt;br /&gt;
A panel selected from a variety of industries including representation from security consulting, corporate and vendor will discuss the considerations, options and benefits of employing SEIM technology and processes.&lt;br /&gt;
''&lt;br /&gt;
&lt;br /&gt;
For more event information, please refer to AISA's website.&lt;br /&gt;
&lt;br /&gt;
== Previous OWASP Meetings ==&lt;br /&gt;
&lt;br /&gt;
=== How mature is your software security process? (Perth AISA May 2010) ===&lt;br /&gt;
&lt;br /&gt;
==== [http://www.aisa.org.au/index.php?page=287 AISA Details] ====&lt;br /&gt;
&lt;br /&gt;
As the security industry continues to change its focus to application &lt;br /&gt;
security a lot of companies who rely on software, developed either &lt;br /&gt;
internally or externally, are wondering what they can do reduce the risk &lt;br /&gt;
of security flaws. &lt;br /&gt;
&lt;br /&gt;
Microsoft's Security Development Lifecycle (SDL) model can look &lt;br /&gt;
appealing, however without a clear understanding of what your software &lt;br /&gt;
security processes look like, it may be difficult to achieve any real &lt;br /&gt;
improvements. &lt;br /&gt;
&lt;br /&gt;
Implementing a holistic end-to-end software security process can often &lt;br /&gt;
look like an impossible task, and while the end picture resembles Eden, &lt;br /&gt;
it's often the first steps that everyone stumbles on. As the saying goes &lt;br /&gt;
&amp;quot;You can't manage what you can't measure&amp;quot;, and without a clear &lt;br /&gt;
understanding of what your software security processes look like now it's &lt;br /&gt;
unlikely that you can achieve any real improvements. &lt;br /&gt;
&lt;br /&gt;
OWASP's Open Software Assurance Maturity Model, or OpenSAMM, aims &lt;br /&gt;
to assist organisations, both big and small, in evaluating their existing &lt;br /&gt;
software security practices and constructing a measurable, balanced &lt;br /&gt;
program to increase their software security. &lt;br /&gt;
&lt;br /&gt;
Wondering how this can help your internal development processes? Want &lt;br /&gt;
to have a more rigid process to audit your externally developed software &lt;br /&gt;
processes? Then perhaps OWASP's OpenSAMM project can assist.&lt;br /&gt;
&lt;br /&gt;
This meeting will be co-hosted by both the local AISA chapter and the Perth OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
=== Perth OWASP - Perth AISA Technical Day (Dec 2009) ===&lt;br /&gt;
&lt;br /&gt;
==== [http://www.owasp.org/index.php/File:AISA_Perth_TSD_2009_Brochure_-Final.pdf Brochure] ====&lt;br /&gt;
&lt;br /&gt;
The local OWASP boys will be whipping out their flux capacitor to fit as much information as they possibly can into a 2 hour jam-packed session on web app security testing. By providing a flyby of the OWASP Testing Guide, David and Christian aim to demonstrate and explain how to detect security vulnerabilities in your own web applications, including: Cross Site Scripting; Injection Flaws; Cross Site Request Forgery and Session Management Flaws.&lt;br /&gt;
&lt;br /&gt;
Demonstrations will utilise a number of open source and freely available tools, including OWASP's own WebScarab. To provide a yoga-like flexibility to the session all materials and testing environments (an Ubuntu wrapped VMware virtual machine) will be provided to attendees, allowing you to either chase us rapidly down the rabbit hole of the OWASP Top 10, or to take your own time after the session...&lt;br /&gt;
&lt;br /&gt;
The perfect way to spend a lazy Sunday afternoon.&lt;br /&gt;
&lt;br /&gt;
=== Web-based Malware (Sep 2009) ===&lt;br /&gt;
&lt;br /&gt;
==== About the presenter ====&lt;br /&gt;
Shlomi Cohen joined IBM with the Watchfire acquisition at August 2007.&lt;br /&gt;
Over nine years of experience in web application security in both start-ups and established companies. Emphasis in strategic selling, sales consulting, technical sales and management.&lt;br /&gt;
* Leading the Security solution on the WW Rational Tiger sales team&lt;br /&gt;
* Work with the customers and the local sales team to form the right security solution&lt;br /&gt;
* Development of sale process for multiple products&lt;br /&gt;
* Working closely with customers and the product management team in driving the products roadmaps&lt;br /&gt;
* Assisting IBM’s growth in acquisition portfolio&lt;br /&gt;
&lt;br /&gt;
Previous to the WW Rational Security Solution leader:&lt;br /&gt;
* Managing the technical sales team for Watchfire in the Americas group of IBM&lt;br /&gt;
* Watchfire Security Research team manager - A team responsible for various web application security aspects including web application vulnerability research, security product rule updates, enhanced security feature definition, security audits, customer support, marketing and sales assistance&lt;br /&gt;
* AppShield Development Manager - Managed the development and QA teams for the AppShield product - a client Server Web Application Firewall&lt;br /&gt;
&lt;br /&gt;
=== Threat Modelling in the Software Development Lifecycle (Feb 2009) ===&lt;br /&gt;
&lt;br /&gt;
One of the most important concepts being promoted in the security industry is security in the software development lifecycle. This concept is important due to two primary factors:&lt;br /&gt;
* It is generally recognised that by shifting security activities closer towards the requirements gathering stage, or the design stage, that less vulnerabilities will make their way into the production systems.&lt;br /&gt;
* It is also recognised that the cost of mitigating vulnerabilities increases later in the lifecycle.&lt;br /&gt;
By walking through a case study I hope to demonstrate the effectiveness of addressing risk during the earlier stage of the software development lifecycle, and that these activities are not solely the responsibility of the &amp;quot;security guy&amp;quot;, but all participants in a software project including the project manager, business stakeholders and software designer.&lt;br /&gt;
==== About the presenter ====&lt;br /&gt;
Christian Frichot is currently employed by Bankwest working within the Security Consulting Services team. His core responsibilities include phishing and online fraud response, security assessments, information risk assessments and other ad-hoc information security consulting. Christian hopes to spend more time in '09 focusing on education and application security, where he feels more effort needs to be applied.&lt;br /&gt;
&lt;br /&gt;
-Updated 18/11/09 by [mailto:xntrik@gmail.com Christian Frichot]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:Australia]]&lt;/div&gt;</summary>
		<author><name>Joshuaq</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=50384</id>
		<title>Perth Australia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=50384"/>
				<updated>2009-01-08T15:00:18Z</updated>
		
		<summary type="html">&lt;p&gt;Joshuaq: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Perth, Western Australia|extra=The chapter leader is [mailto:joshua@qwek.com Joshua Qwek]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Perth|emailarchives=http://lists.owasp.org/pipermail/owasp-Perth}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Perth Australia&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to join us at our chapter meetings.&lt;br /&gt;
Our chapter's meetings are informal and encourage open discussion of all aspects of application security. Anyone in our area interested in web application security is welcome to attend. We encourage attendees to give short presentations about specific topics. If you would like to make a presentation, or have any questions, send an email to us.&lt;br /&gt;
&lt;br /&gt;
The location of the meeting is tentatively located at:&lt;br /&gt;
Grind Cafe, Trinity Arcade in the City.&lt;br /&gt;
&lt;br /&gt;
Joshua 11 Oct 2008&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Joshuaq</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=42933</id>
		<title>Perth Australia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=42933"/>
				<updated>2008-10-11T13:19:10Z</updated>
		
		<summary type="html">&lt;p&gt;Joshuaq: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Perth, Western Australia|extra=The chapter leader is [mailto:joshua.Qwek@stratsec.net Joshua Qwek]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Perth|emailarchives=http://lists.owasp.org/pipermail/owasp-Perth}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Perth Australia&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to join us at our chapter meetings.&lt;br /&gt;
Our chapter's meetings are informal and encourage open discussion of all aspects of application security. Anyone in our area interested in web application security is welcome to attend. We encourage attendees to give short presentations about specific topics. If you would like to make a presentation, or have any questions, send an email to us.&lt;br /&gt;
&lt;br /&gt;
The location of the meeting is tentatively located at:&lt;br /&gt;
Grind Cafe, Trinity Arcade in the City.&lt;br /&gt;
&lt;br /&gt;
Joshua 11 Oct 2008&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Joshuaq</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=42932</id>
		<title>Perth Australia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=42932"/>
				<updated>2008-10-11T12:53:17Z</updated>
		
		<summary type="html">&lt;p&gt;Joshuaq: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Perth, Western Australia|extra=The chapter leader is [mailto:joshua.Qwek@stratsec.net Joshua Qwek]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Perth|emailarchives=http://lists.owasp.org/pipermail/owasp-Perth}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Perth Australia&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to join us at our chapter meetings.&lt;br /&gt;
The location of the meeting is tentatively located at:&lt;br /&gt;
Grind Cafe, Trinity Arcade.&lt;br /&gt;
&lt;br /&gt;
Please let me know the preferred time/date.&lt;br /&gt;
&lt;br /&gt;
Joshua 11 Oct 2008&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Joshuaq</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=42931</id>
		<title>Perth Australia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Perth_Australia&amp;diff=42931"/>
				<updated>2008-10-11T12:47:06Z</updated>
		
		<summary type="html">&lt;p&gt;Joshuaq: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Perth, Western Australia|extra=The chapter leader is [mailto:joshua.Qwek@stratsec.net Joshua Qwek]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Perth|emailarchives=http://lists.owasp.org/pipermail/owasp-Perth}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Perth Australia&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to join us at our chapter meetings.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Joshuaq</name></author>	</entry>

	</feed>