<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Kathleen+Thaxton</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Kathleen+Thaxton"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Kathleen_Thaxton"/>
		<updated>2026-04-23T16:00:13Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Front_Range_OWASP_Conference_2012&amp;diff=125809</id>
		<title>Front Range OWASP Conference 2012</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Front_Range_OWASP_Conference_2012&amp;diff=125809"/>
				<updated>2012-03-09T00:25:32Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- [http://froc2011.eventbrite.com/ Registration is NOW OPEN] --&amp;gt;&lt;br /&gt;
&amp;lt;!-- FROC2010 was a major success!  The [http://www.surveymonkey.com/sr.aspx?sm=Fn2UBK3eyju0z2k3B8XpvHvs9s_2bdRO1BS428Of_2f9ZA0_3d survey results]are now posted.&lt;br /&gt;
&lt;br /&gt;
'''Looking for the presentations and videos?  They are [http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010#tab=Agenda here]'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&amp;lt;!-- Header --&amp;gt;&lt;br /&gt;
====Welcome====  &lt;br /&gt;
&amp;lt;!-- *** Update image [[Image:Froc2010_sm.png|200px]] &lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
'''Welcome to SnowFROC 2012, the fourth Front Range OWASP Application Security Conference!'''&lt;br /&gt;
&lt;br /&gt;
After successful FROC's in June of 2008, [http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2009 March of 2009], and [https://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010 2010] we are back in Denver, Colorado USA on '''Thursday the 22nd of March'''! &lt;br /&gt;
&lt;br /&gt;
This year we again present a full day, multi-track event, which will provide valuable information for managers and executives as well as developers and engineers.  '''ALSO''', on Friday March 23rd several instructors from OWASP will be conducting day-long deep-dives!&lt;br /&gt;
&lt;br /&gt;
In 2010, we attracted a packed venue with our great AppSec speakers, and we hope to achieve the same again in 2012.  &amp;lt;!-- This year we are organizing the conference with the support of our colleagues at the [http://www.cloudsecurityalliance.org/ Cloud Security Alliance], and will feature an AppSec track as well as a CloudSec/VirtSec track.&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Registration====&lt;br /&gt;
&lt;br /&gt;
[http://snowfroc2012.eventbrite.com Registration for SnowFROC is now open!]&lt;br /&gt;
&lt;br /&gt;
$20 covers breakfast, lunch, and a WORLD-CLASS AppSec conference!&lt;br /&gt;
&amp;lt;!-- Due to the hard work of our organizers and the gracious support of our sponsors, FROC was a free event in 2008 and 2009.  This year, thanks to the generosity of our [http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010#tab=Conference_Sponsors sponsors] we are offering tickets to the event on a DONATION basis.  Pay whatever you or your company can afford.&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Click [http://snowfroc2012.eventbrite.com HERE] to register now for SnowFROC!&lt;br /&gt;
&lt;br /&gt;
Click [[Denver,_Colorado|here]] to register for OWASP Deep Dives in Denver!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ====Agenda====&lt;br /&gt;
&lt;br /&gt;
'''CFP has closed; '''the agenda is being formed NOW and the draft agenda should be published SOON!&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 22 March 2012==&lt;br /&gt;
&lt;br /&gt;
The agenda follows the successful OWASP conference multi track format, with opening keynotes and presentations in the main room, split tracks in the middle of the day, and closing panel discussions back in the main room.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:86%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;4&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 22nd, 2012&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 07:45-08:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Continental Breakfast in the Adirondack Room&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-08:45 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Welcome to SnowFROC 2012 Conference&lt;br /&gt;
&lt;br /&gt;
''OWASP Denver and OWASP Boulder Chapter Leaders''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:45-09:10 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''State of OWASP''' &lt;br /&gt;
&lt;br /&gt;
''Matt Tesauro''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:10-10:10 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | '''Keynote:''' &lt;br /&gt;
&lt;br /&gt;
''John Pirc, Co-Author of [http://www.amazon.com/Cybercrime-Espionage-Analysis-Subversive-Multi-Vector/dp/1597496138/ref=sr_1_1?s=books&amp;amp;ie=UTF8&amp;amp;qid=1330542019&amp;amp;sr=1-1 &amp;quot;Cybercrime and Espionage: An Analysis of Subversive Multi-Vector Threats&amp;quot;]''&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:10-10:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | || colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:45%; background:#BC857A&amp;quot; | '''Tech Track - Zenith Room 640'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:45%; background:#BCA57A&amp;quot; | '''Management Track - Senate Chamber''' &lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; | '''Management / Exec Track: Room 3''' --&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:30-11:15 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | OWASP Passfault&lt;br /&gt;
''Cameron Morris''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Managing IT Risk in a Cloud Environment &lt;br /&gt;
''Karl Steinkamp''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--  | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD'' &lt;br /&gt;
--&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:15-12:00 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | State of Web Security: Monitored Attacks&lt;br /&gt;
 &lt;br /&gt;
''Robert Rowley''&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | PCI vs Risk Management  &lt;br /&gt;
''Doug Landoll''   &lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | Securing Data from the Web Tier ''Mike Fleck'' --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:00-13:00 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch - Expo&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 |  style:&amp;quot;width:10%; background: WebGoat.net&lt;br /&gt;
Jerry Hoff&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Securing Data from the Web Tier&lt;br /&gt;
''Mike Fleck''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD'' --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:50-14:40 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | Gray, the new black: Gray box vulnerability testing&lt;br /&gt;
''Adam Hills''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | What the Cyber Criminals are Doing on Your Website Right Now.&lt;br /&gt;
''LAZ''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD''&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:40-15:00 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | BREAK&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:00-15:50 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | &amp;quot;The Mobile Top 10&amp;quot;&lt;br /&gt;
''Mike Zussman''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | A Scalable Secure Development Program&lt;br /&gt;
''Rajiv Sharma''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD''&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:50-16:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | End of Conference Panel Discussion: &lt;br /&gt;
&lt;br /&gt;
Topic: ''The Crystal Ball and the 2-headed Calf - What's on the Horizon and Why Does It Seem So Unnatural?''  &lt;br /&gt;
&lt;br /&gt;
Moderator: Steve Kosten or Andy Lewis&lt;br /&gt;
Panelists: Laz, Matt Tesauro, John Pirc, Tanner Coltrin, Steve Kosten, others&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:30-17:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Wrap up, vendor raffles!&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Logistics====&lt;br /&gt;
[[Image:Denver_mountains.JPG]]&lt;br /&gt;
&lt;br /&gt;
This year, the conference will again be held at University of Colorado, Denver at the Tivoli Center.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--  *** need image, lat-long, directions [[File:Froc map.GIF|thumb|left]]&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=1200+Larimer+Street,+Denver,+CO&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=37.188995,62.226563&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=1200+Larimer+St,+Denver,+Colorado+80204&amp;amp;z=16&amp;amp;iwloc=A Google Map of the Venue: 1200 Larimer St., Denver CO 80204]&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Accomodation=====&lt;br /&gt;
OWASP is in the process of negotiating discounted rates with the uber-pimpin [http://www.hotelteatro.com/ Hotel Teatro].  Rooms under the FROC rate will be competitively priced and include courtesy Cadillac Escalade transportation to and from Auraria Campus. Currently a &amp;quot;petite queen&amp;quot; room will be reduced from $279/night to $149 by mentioning SnowFROC.&lt;br /&gt;
&lt;br /&gt;
To reserve a room, contact Hotel Teatro at +1.303.228.1100 and mention SnowFROC or use the [https://reservations.ihotelier.com/crs/g_reservation.cfm?groupID=464765&amp;amp;hotelID=14708 iHotelier.com link here].&lt;br /&gt;
&lt;br /&gt;
=====How to get to the venue?=====&lt;br /&gt;
&lt;br /&gt;
*By taxi: taxi from the airport to venue is about $50 USD&lt;br /&gt;
&lt;br /&gt;
*From hotel: transport from the conference hotel (Hotel Teatro) by limo is free&lt;br /&gt;
&lt;br /&gt;
*By car: there is plenty of parking at the Tivoli.  Attendees should park at the Tivoli lot (as in past years).  Parking validation will be provided for registered FROC participants.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Call for Presentations====&lt;br /&gt;
&amp;lt;!-- The [[Front_Range_OWASP_Conference_2012_CFP|call for presentations]] is open until February 23rd 2012. --&amp;gt;&lt;br /&gt;
The [[Front_Range_OWASP_Conference_2012_CFP|call for presentations]] closed February 23rd.  If you've got a compelling presentation involving bleeding-edge research please contact steve dot kosten /\+ owasp d0+ org for consideration.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ===[[SnowFROC Tentative Schedule]]=== --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Back to [https://www.owasp.org/index.php/Front_Range_OWASP_Conference_2009 SnowFROC Home] --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ====Capture the Flag (CTF)====&lt;br /&gt;
&lt;br /&gt;
A capture the flag contest may be held if we can find space and someone to set it up and lead it.&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Conference Committee====&lt;br /&gt;
&lt;br /&gt;
FROC 2012 Planning Committee Chair: Kathy Thaxton -  kthaxton at hosting dot com&lt;br /&gt;
&lt;br /&gt;
Presentation Selection Committee:&lt;br /&gt;
* Steve Kosten&lt;br /&gt;
* Denver OWASP Board&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Colorado Chapter Hosts:&lt;br /&gt;
* Andy Lewis - OWASP Denver - alewis at owasp dot org&lt;br /&gt;
* Mark Major - OWASP Boulder - mark dot major at owasp dot org&lt;br /&gt;
* Might have a CO Springs chapter in time for SnowFROC; stay tuned...&lt;br /&gt;
&lt;br /&gt;
Vendor Exhibition POC: Kathy Thaxton - kthaxton at hosting dot com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Capture the Flag POC: Eric Duprey - eduprey at owasp dot org&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Sponsors====&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring the Front Range OWASP Conference, please contact Kathy Thaxton at kthaxton at hosting dot com.&lt;br /&gt;
&amp;lt;!-- [[File:Sponsors.PNG]]&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We are proud to have the following sponsors for this year's conference:&lt;br /&gt;
&amp;lt;!-- &lt;br /&gt;
*Accuvant&lt;br /&gt;
*Breach&lt;br /&gt;
*Business Partner Solutions&lt;br /&gt;
*Denim Group&lt;br /&gt;
*Fishnet Security&lt;br /&gt;
*IBM&lt;br /&gt;
*Imperva&lt;br /&gt;
*Laz&lt;br /&gt;
*Lares&lt;br /&gt;
*Trustwave&lt;br /&gt;
*WhiteHat Security&lt;br /&gt;
*Hosting.com&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
&lt;br /&gt;
*[http://www.denimgroup.com/ Denim Group]&lt;br /&gt;
*[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.accuvant.com/ Accuvant]&lt;br /&gt;
*[http://www.hosting.com/ Hosting.com]&lt;br /&gt;
*[http://www.whitehatsec.com/home/index.html Whitehat Security]&lt;br /&gt;
*[http://www.hpenterprisesecurity.com/register/esp-grand-slam-camp-hpesp-homepage HP ESP]&lt;br /&gt;
*[http://www.coalfire.com/Home Coalfire Systems]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--  *** Logistics information for sponsors is available [[FROC2010 Sponsor Info|here]]&lt;br /&gt;
&lt;br /&gt;
More information about conference sponsorship is available [[OWASP AppSec Conference Sponsors | here]].&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP AppSec Conference]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- &lt;br /&gt;
====Twitter Feed====&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23FROC #FROC]''' hashtag for your tweets (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@OWASP303 Twitter Feed ([http://twitter.com/OWASP303 follow us on Twitter!])'''&lt;br /&gt;
&amp;lt;twitter&amp;gt;55021150&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|} &lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Speaker Bios ===&lt;br /&gt;
&lt;br /&gt;
==== '''Laz''' =====&lt;br /&gt;
&lt;br /&gt;
==== '''Mike Fleck''' ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- &amp;lt;hr&amp;gt;&lt;br /&gt;
&amp;lt;paypal&amp;gt;Denver&amp;lt;/paypal&amp;gt; --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Front_Range_OWASP_Conference_2012&amp;diff=125808</id>
		<title>Front Range OWASP Conference 2012</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Front_Range_OWASP_Conference_2012&amp;diff=125808"/>
				<updated>2012-03-09T00:24:07Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- [http://froc2011.eventbrite.com/ Registration is NOW OPEN] --&amp;gt;&lt;br /&gt;
&amp;lt;!-- FROC2010 was a major success!  The [http://www.surveymonkey.com/sr.aspx?sm=Fn2UBK3eyju0z2k3B8XpvHvs9s_2bdRO1BS428Of_2f9ZA0_3d survey results]are now posted.&lt;br /&gt;
&lt;br /&gt;
'''Looking for the presentations and videos?  They are [http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010#tab=Agenda here]'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&amp;lt;!-- Header --&amp;gt;&lt;br /&gt;
====Welcome====  &lt;br /&gt;
&amp;lt;!-- *** Update image [[Image:Froc2010_sm.png|200px]] &lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
'''Welcome to SnowFROC 2012, the fourth Front Range OWASP Application Security Conference!'''&lt;br /&gt;
&lt;br /&gt;
After successful FROC's in June of 2008, [http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2009 March of 2009], and [https://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010 2010] we are back in Denver, Colorado USA on '''Thursday the 22nd of March'''! &lt;br /&gt;
&lt;br /&gt;
This year we again present a full day, multi-track event, which will provide valuable information for managers and executives as well as developers and engineers.  '''ALSO''', on Friday March 23rd several instructors from OWASP will be conducting day-long deep-dives!&lt;br /&gt;
&lt;br /&gt;
In 2010, we attracted a packed venue with our great AppSec speakers, and we hope to achieve the same again in 2012.  &amp;lt;!-- This year we are organizing the conference with the support of our colleagues at the [http://www.cloudsecurityalliance.org/ Cloud Security Alliance], and will feature an AppSec track as well as a CloudSec/VirtSec track.&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Registration====&lt;br /&gt;
&lt;br /&gt;
[http://snowfroc2012.eventbrite.com Registration for SnowFROC is now open!]&lt;br /&gt;
&lt;br /&gt;
$20 covers breakfast, lunch, and a WORLD-CLASS AppSec conference!&lt;br /&gt;
&amp;lt;!-- Due to the hard work of our organizers and the gracious support of our sponsors, FROC was a free event in 2008 and 2009.  This year, thanks to the generosity of our [http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010#tab=Conference_Sponsors sponsors] we are offering tickets to the event on a DONATION basis.  Pay whatever you or your company can afford.&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Click [http://snowfroc2012.eventbrite.com HERE] to register now for SnowFROC!&lt;br /&gt;
&lt;br /&gt;
Click [[Denver,_Colorado|here]] to register for OWASP Deep Dives in Denver!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ====Agenda====&lt;br /&gt;
&lt;br /&gt;
'''CFP has closed; '''the agenda is being formed NOW and the draft agenda should be published SOON!&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 22 March 2012==&lt;br /&gt;
&lt;br /&gt;
The agenda follows the successful OWASP conference multi track format, with opening keynotes and presentations in the main room, split tracks in the middle of the day, and closing panel discussions back in the main room.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:86%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;4&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 22nd, 2012&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 07:45-08:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Continental Breakfast in the Adirondack Room&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-08:45 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Welcome to SnowFROC 2012 Conference&lt;br /&gt;
&lt;br /&gt;
''OWASP Denver and OWASP Boulder Chapter Leaders''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:45-09:10 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''State of OWASP''' &lt;br /&gt;
&lt;br /&gt;
''Matt Tesauro''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:10-10:10 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | '''Keynote:''' &lt;br /&gt;
&lt;br /&gt;
''John Pirc, Co-Author of [http://www.amazon.com/Cybercrime-Espionage-Analysis-Subversive-Multi-Vector/dp/1597496138/ref=sr_1_1?s=books&amp;amp;ie=UTF8&amp;amp;qid=1330542019&amp;amp;sr=1-1 &amp;quot;Cybercrime and Espionage: An Analysis of Subversive Multi-Vector Threats&amp;quot;]''&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:10-10:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | || colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:45%; background:#BC857A&amp;quot; | '''Tech Track - Zenith Room 640'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:45%; background:#BCA57A&amp;quot; | '''Management Track - Senate Chamber''' &lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; | '''Management / Exec Track: Room 3''' --&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:30-11:15 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | OWASP Passfault&lt;br /&gt;
''Cameron Morris''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Managing IT Risk in a Cloud Environment &lt;br /&gt;
''Karl Steinkamp''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--  | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD'' &lt;br /&gt;
--&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:15-12:00 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | State of Web Security: Monitored Attacks&lt;br /&gt;
 &lt;br /&gt;
''Robert Rowley''&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | PCI vs Risk Management  &lt;br /&gt;
''Doug Landoll''   &lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | Securing Data from the Web Tier ''Mike Fleck'' --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:00-13:00 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch - Expo&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 |  style:&amp;quot;width:10%; background: WebGoat.net&lt;br /&gt;
Jerry Hoff&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Securing Data from the Web Tier&lt;br /&gt;
''Mike Fleck''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD'' --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:50-14:40 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | Gray, the new black: Gray box vulnerability testing&lt;br /&gt;
''Adam Hills''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | What the Cyber Criminals are Doing on Your Website Right Now.&lt;br /&gt;
                - My experience as the Director of Information Security for a Fortune 50 Organization&lt;br /&gt;
''LAZ''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD''&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:40-15:00 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | BREAK&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:00-15:50 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | &amp;quot;The Mobile Top 10&amp;quot;&lt;br /&gt;
''Mike Zussman''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | A Scalable Secure Development Program&lt;br /&gt;
''Rajiv Sharma''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD''&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:50-16:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | End of Conference Panel Discussion: &lt;br /&gt;
&lt;br /&gt;
Topic: ''The Crystal Ball and the 2-headed Calf - What's on the Horizon and Why Does It Seem So Unnatural?''  &lt;br /&gt;
&lt;br /&gt;
Moderator: Steve Kosten or Andy Lewis&lt;br /&gt;
Panelists: Laz, Matt Tesauro, John Pirc, Tanner Coltrin, Steve Kosten, others&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:30-17:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Wrap up, vendor raffles!&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Logistics====&lt;br /&gt;
[[Image:Denver_mountains.JPG]]&lt;br /&gt;
&lt;br /&gt;
This year, the conference will again be held at University of Colorado, Denver at the Tivoli Center.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--  *** need image, lat-long, directions [[File:Froc map.GIF|thumb|left]]&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=1200+Larimer+Street,+Denver,+CO&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=37.188995,62.226563&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=1200+Larimer+St,+Denver,+Colorado+80204&amp;amp;z=16&amp;amp;iwloc=A Google Map of the Venue: 1200 Larimer St., Denver CO 80204]&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Accomodation=====&lt;br /&gt;
OWASP is in the process of negotiating discounted rates with the uber-pimpin [http://www.hotelteatro.com/ Hotel Teatro].  Rooms under the FROC rate will be competitively priced and include courtesy Cadillac Escalade transportation to and from Auraria Campus. Currently a &amp;quot;petite queen&amp;quot; room will be reduced from $279/night to $149 by mentioning SnowFROC.&lt;br /&gt;
&lt;br /&gt;
To reserve a room, contact Hotel Teatro at +1.303.228.1100 and mention SnowFROC or use the [https://reservations.ihotelier.com/crs/g_reservation.cfm?groupID=464765&amp;amp;hotelID=14708 iHotelier.com link here].&lt;br /&gt;
&lt;br /&gt;
=====How to get to the venue?=====&lt;br /&gt;
&lt;br /&gt;
*By taxi: taxi from the airport to venue is about $50 USD&lt;br /&gt;
&lt;br /&gt;
*From hotel: transport from the conference hotel (Hotel Teatro) by limo is free&lt;br /&gt;
&lt;br /&gt;
*By car: there is plenty of parking at the Tivoli.  Attendees should park at the Tivoli lot (as in past years).  Parking validation will be provided for registered FROC participants.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Call for Presentations====&lt;br /&gt;
&amp;lt;!-- The [[Front_Range_OWASP_Conference_2012_CFP|call for presentations]] is open until February 23rd 2012. --&amp;gt;&lt;br /&gt;
The [[Front_Range_OWASP_Conference_2012_CFP|call for presentations]] closed February 23rd.  If you've got a compelling presentation involving bleeding-edge research please contact steve dot kosten /\+ owasp d0+ org for consideration.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ===[[SnowFROC Tentative Schedule]]=== --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Back to [https://www.owasp.org/index.php/Front_Range_OWASP_Conference_2009 SnowFROC Home] --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ====Capture the Flag (CTF)====&lt;br /&gt;
&lt;br /&gt;
A capture the flag contest may be held if we can find space and someone to set it up and lead it.&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Conference Committee====&lt;br /&gt;
&lt;br /&gt;
FROC 2012 Planning Committee Chair: Kathy Thaxton -  kthaxton at hosting dot com&lt;br /&gt;
&lt;br /&gt;
Presentation Selection Committee:&lt;br /&gt;
* Steve Kosten&lt;br /&gt;
* Denver OWASP Board&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Colorado Chapter Hosts:&lt;br /&gt;
* Andy Lewis - OWASP Denver - alewis at owasp dot org&lt;br /&gt;
* Mark Major - OWASP Boulder - mark dot major at owasp dot org&lt;br /&gt;
* Might have a CO Springs chapter in time for SnowFROC; stay tuned...&lt;br /&gt;
&lt;br /&gt;
Vendor Exhibition POC: Kathy Thaxton - kthaxton at hosting dot com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Capture the Flag POC: Eric Duprey - eduprey at owasp dot org&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Sponsors====&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring the Front Range OWASP Conference, please contact Kathy Thaxton at kthaxton at hosting dot com.&lt;br /&gt;
&amp;lt;!-- [[File:Sponsors.PNG]]&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We are proud to have the following sponsors for this year's conference:&lt;br /&gt;
&amp;lt;!-- &lt;br /&gt;
*Accuvant&lt;br /&gt;
*Breach&lt;br /&gt;
*Business Partner Solutions&lt;br /&gt;
*Denim Group&lt;br /&gt;
*Fishnet Security&lt;br /&gt;
*IBM&lt;br /&gt;
*Imperva&lt;br /&gt;
*Laz&lt;br /&gt;
*Lares&lt;br /&gt;
*Trustwave&lt;br /&gt;
*WhiteHat Security&lt;br /&gt;
*Hosting.com&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
&lt;br /&gt;
*[http://www.denimgroup.com/ Denim Group]&lt;br /&gt;
*[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.accuvant.com/ Accuvant]&lt;br /&gt;
*[http://www.hosting.com/ Hosting.com]&lt;br /&gt;
*[http://www.whitehatsec.com/home/index.html Whitehat Security]&lt;br /&gt;
*[http://www.hpenterprisesecurity.com/register/esp-grand-slam-camp-hpesp-homepage HP ESP]&lt;br /&gt;
*[http://www.coalfire.com/Home Coalfire Systems]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--  *** Logistics information for sponsors is available [[FROC2010 Sponsor Info|here]]&lt;br /&gt;
&lt;br /&gt;
More information about conference sponsorship is available [[OWASP AppSec Conference Sponsors | here]].&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP AppSec Conference]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- &lt;br /&gt;
====Twitter Feed====&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23FROC #FROC]''' hashtag for your tweets (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@OWASP303 Twitter Feed ([http://twitter.com/OWASP303 follow us on Twitter!])'''&lt;br /&gt;
&amp;lt;twitter&amp;gt;55021150&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|} &lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Speaker Bios ===&lt;br /&gt;
&lt;br /&gt;
==== '''Laz''' =====&lt;br /&gt;
&lt;br /&gt;
==== '''Mike Fleck''' ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- &amp;lt;hr&amp;gt;&lt;br /&gt;
&amp;lt;paypal&amp;gt;Denver&amp;lt;/paypal&amp;gt; --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Front_Range_OWASP_Conference_2012&amp;diff=125807</id>
		<title>Front Range OWASP Conference 2012</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Front_Range_OWASP_Conference_2012&amp;diff=125807"/>
				<updated>2012-03-09T00:20:00Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- [http://froc2011.eventbrite.com/ Registration is NOW OPEN] --&amp;gt;&lt;br /&gt;
&amp;lt;!-- FROC2010 was a major success!  The [http://www.surveymonkey.com/sr.aspx?sm=Fn2UBK3eyju0z2k3B8XpvHvs9s_2bdRO1BS428Of_2f9ZA0_3d survey results]are now posted.&lt;br /&gt;
&lt;br /&gt;
'''Looking for the presentations and videos?  They are [http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010#tab=Agenda here]'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&amp;lt;!-- Header --&amp;gt;&lt;br /&gt;
====Welcome====  &lt;br /&gt;
&amp;lt;!-- *** Update image [[Image:Froc2010_sm.png|200px]] &lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
'''Welcome to SnowFROC 2012, the fourth Front Range OWASP Application Security Conference!'''&lt;br /&gt;
&lt;br /&gt;
After successful FROC's in June of 2008, [http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2009 March of 2009], and [https://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010 2010] we are back in Denver, Colorado USA on '''Thursday the 22nd of March'''! &lt;br /&gt;
&lt;br /&gt;
This year we again present a full day, multi-track event, which will provide valuable information for managers and executives as well as developers and engineers.  '''ALSO''', on Friday March 23rd several instructors from OWASP will be conducting day-long deep-dives!&lt;br /&gt;
&lt;br /&gt;
In 2010, we attracted a packed venue with our great AppSec speakers, and we hope to achieve the same again in 2012.  &amp;lt;!-- This year we are organizing the conference with the support of our colleagues at the [http://www.cloudsecurityalliance.org/ Cloud Security Alliance], and will feature an AppSec track as well as a CloudSec/VirtSec track.&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Registration====&lt;br /&gt;
&lt;br /&gt;
[http://snowfroc2012.eventbrite.com Registration for SnowFROC is now open!]&lt;br /&gt;
&lt;br /&gt;
$20 covers breakfast, lunch, and a WORLD-CLASS AppSec conference!&lt;br /&gt;
&amp;lt;!-- Due to the hard work of our organizers and the gracious support of our sponsors, FROC was a free event in 2008 and 2009.  This year, thanks to the generosity of our [http://www.owasp.org/index.php/Front_Range_OWASP_Conference_2010#tab=Conference_Sponsors sponsors] we are offering tickets to the event on a DONATION basis.  Pay whatever you or your company can afford.&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Click [http://snowfroc2012.eventbrite.com HERE] to register now for SnowFROC!&lt;br /&gt;
&lt;br /&gt;
Click [[Denver,_Colorado|here]] to register for OWASP Deep Dives in Denver!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ====Agenda====&lt;br /&gt;
&lt;br /&gt;
'''CFP has closed; '''the agenda is being formed NOW and the draft agenda should be published SOON!&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 22 March 2012==&lt;br /&gt;
&lt;br /&gt;
The agenda follows the successful OWASP conference multi track format, with opening keynotes and presentations in the main room, split tracks in the middle of the day, and closing panel discussions back in the main room.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:86%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;4&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 22nd, 2012&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 07:45-08:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Continental Breakfast in the Adirondack Room&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-08:45 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Welcome to SnowFROC 2012 Conference&lt;br /&gt;
&lt;br /&gt;
''OWASP Denver and OWASP Boulder Chapter Leaders''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:45-09:10 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
'''State of OWASP''' &lt;br /&gt;
&lt;br /&gt;
''Matt Tesauro''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:10-10:10 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | '''Keynote:''' &lt;br /&gt;
&lt;br /&gt;
''John Pirc, Co-Author of [http://www.amazon.com/Cybercrime-Espionage-Analysis-Subversive-Multi-Vector/dp/1597496138/ref=sr_1_1?s=books&amp;amp;ie=UTF8&amp;amp;qid=1330542019&amp;amp;sr=1-1 &amp;quot;Cybercrime and Espionage: An Analysis of Subversive Multi-Vector Threats&amp;quot;]''&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:10-10:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | || colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:45%; background:#BC857A&amp;quot; | '''Tech Track - Zenith Room 640'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:45%; background:#BCA57A&amp;quot; | '''Management Track - Senate Chamber''' &lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; | '''Management / Exec Track: Room 3''' --&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:30-11:15 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | OWASP Passfault&lt;br /&gt;
''Cameron Morris''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Managing IT Risk in a Cloud Environment &lt;br /&gt;
''Karl Steinkamp''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--  | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD'' &lt;br /&gt;
--&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:15-12:00 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | State of Web Security: Monitored Attacks&lt;br /&gt;
 &lt;br /&gt;
''Robert Rowley''&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | PCI vs Risk Management  &lt;br /&gt;
''Doug Landoll''   &lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | Securing Data from the Web Tier ''Mike Fleck'' --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:00-13:00 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch - Expo&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 |  WebGoat.net&lt;br /&gt;
Jerry Hoff&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Securing Data from the Web Tier&lt;br /&gt;
''Mike Fleck''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD'' --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:50-14:40 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | Gray, the new black: Gray box vulnerability testing&lt;br /&gt;
''Adam Hills''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Web Session Intelligence&lt;br /&gt;
&lt;br /&gt;
''LAZ''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD''&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:40-15:00 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | BREAK&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:00-15:50 || style=&amp;quot;width:45%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | &amp;quot;The Mobile Top 10&amp;quot;&lt;br /&gt;
''Mike Zussman''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:45%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | A Scalable Secure Development Program&lt;br /&gt;
''Rajiv Sharma''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C6E2FF&amp;quot; align=&amp;quot;left&amp;quot; | TBD&lt;br /&gt;
''TBD''&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:50-16:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | End of Conference Panel Discussion: &lt;br /&gt;
&lt;br /&gt;
Topic: ''The Crystal Ball and the 2-headed Calf - What's on the Horizon and Why Does It Seem So Unnatural?''  &lt;br /&gt;
&lt;br /&gt;
Moderator: Steve Kosten or Andy Lewis&lt;br /&gt;
Panelists: Laz, Matt Tesauro, John Pirc, Tanner Coltrin, Steve Kosten, others&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:30-17:30 || colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Wrap up, vendor raffles!&lt;br /&gt;
 |-&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Logistics====&lt;br /&gt;
[[Image:Denver_mountains.JPG]]&lt;br /&gt;
&lt;br /&gt;
This year, the conference will again be held at University of Colorado, Denver at the Tivoli Center.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--  *** need image, lat-long, directions [[File:Froc map.GIF|thumb|left]]&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=1200+Larimer+Street,+Denver,+CO&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=37.188995,62.226563&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=1200+Larimer+St,+Denver,+Colorado+80204&amp;amp;z=16&amp;amp;iwloc=A Google Map of the Venue: 1200 Larimer St., Denver CO 80204]&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Accomodation=====&lt;br /&gt;
OWASP is in the process of negotiating discounted rates with the uber-pimpin [http://www.hotelteatro.com/ Hotel Teatro].  Rooms under the FROC rate will be competitively priced and include courtesy Cadillac Escalade transportation to and from Auraria Campus. Currently a &amp;quot;petite queen&amp;quot; room will be reduced from $279/night to $149 by mentioning SnowFROC.&lt;br /&gt;
&lt;br /&gt;
To reserve a room, contact Hotel Teatro at +1.303.228.1100 and mention SnowFROC or use the [https://reservations.ihotelier.com/crs/g_reservation.cfm?groupID=464765&amp;amp;hotelID=14708 iHotelier.com link here].&lt;br /&gt;
&lt;br /&gt;
=====How to get to the venue?=====&lt;br /&gt;
&lt;br /&gt;
*By taxi: taxi from the airport to venue is about $50 USD&lt;br /&gt;
&lt;br /&gt;
*From hotel: transport from the conference hotel (Hotel Teatro) by limo is free&lt;br /&gt;
&lt;br /&gt;
*By car: there is plenty of parking at the Tivoli.  Attendees should park at the Tivoli lot (as in past years).  Parking validation will be provided for registered FROC participants.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Call for Presentations====&lt;br /&gt;
&amp;lt;!-- The [[Front_Range_OWASP_Conference_2012_CFP|call for presentations]] is open until February 23rd 2012. --&amp;gt;&lt;br /&gt;
The [[Front_Range_OWASP_Conference_2012_CFP|call for presentations]] closed February 23rd.  If you've got a compelling presentation involving bleeding-edge research please contact steve dot kosten /\+ owasp d0+ org for consideration.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ===[[SnowFROC Tentative Schedule]]=== --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Back to [https://www.owasp.org/index.php/Front_Range_OWASP_Conference_2009 SnowFROC Home] --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ====Capture the Flag (CTF)====&lt;br /&gt;
&lt;br /&gt;
A capture the flag contest may be held if we can find space and someone to set it up and lead it.&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Conference Committee====&lt;br /&gt;
&lt;br /&gt;
FROC 2012 Planning Committee Chair: Kathy Thaxton -  kthaxton at hosting dot com&lt;br /&gt;
&lt;br /&gt;
Presentation Selection Committee:&lt;br /&gt;
* Steve Kosten&lt;br /&gt;
* Denver OWASP Board&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Colorado Chapter Hosts:&lt;br /&gt;
* Andy Lewis - OWASP Denver - alewis at owasp dot org&lt;br /&gt;
* Mark Major - OWASP Boulder - mark dot major at owasp dot org&lt;br /&gt;
* Might have a CO Springs chapter in time for SnowFROC; stay tuned...&lt;br /&gt;
&lt;br /&gt;
Vendor Exhibition POC: Kathy Thaxton - kthaxton at hosting dot com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Capture the Flag POC: Eric Duprey - eduprey at owasp dot org&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Sponsors====&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring the Front Range OWASP Conference, please contact Kathy Thaxton at kthaxton at hosting dot com.&lt;br /&gt;
&amp;lt;!-- [[File:Sponsors.PNG]]&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We are proud to have the following sponsors for this year's conference:&lt;br /&gt;
&amp;lt;!-- &lt;br /&gt;
*Accuvant&lt;br /&gt;
*Breach&lt;br /&gt;
*Business Partner Solutions&lt;br /&gt;
*Denim Group&lt;br /&gt;
*Fishnet Security&lt;br /&gt;
*IBM&lt;br /&gt;
*Imperva&lt;br /&gt;
*Laz&lt;br /&gt;
*Lares&lt;br /&gt;
*Trustwave&lt;br /&gt;
*WhiteHat Security&lt;br /&gt;
*Hosting.com&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
&lt;br /&gt;
*[http://www.denimgroup.com/ Denim Group]&lt;br /&gt;
*[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.accuvant.com/ Accuvant]&lt;br /&gt;
*[http://www.hosting.com/ Hosting.com]&lt;br /&gt;
*[http://www.whitehatsec.com/home/index.html Whitehat Security]&lt;br /&gt;
*[http://www.hpenterprisesecurity.com/register/esp-grand-slam-camp-hpesp-homepage HP ESP]&lt;br /&gt;
*[http://www.coalfire.com/Home Coalfire Systems]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--  *** Logistics information for sponsors is available [[FROC2010 Sponsor Info|here]]&lt;br /&gt;
&lt;br /&gt;
More information about conference sponsorship is available [[OWASP AppSec Conference Sponsors | here]].&lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP AppSec Conference]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- &lt;br /&gt;
====Twitter Feed====&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23FROC #FROC]''' hashtag for your tweets (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@OWASP303 Twitter Feed ([http://twitter.com/OWASP303 follow us on Twitter!])'''&lt;br /&gt;
&amp;lt;twitter&amp;gt;55021150&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|} &lt;br /&gt;
 --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Speaker Bios ===&lt;br /&gt;
&lt;br /&gt;
==== '''Laz''' =====&lt;br /&gt;
&lt;br /&gt;
==== '''Mike Fleck''' ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- &amp;lt;hr&amp;gt;&lt;br /&gt;
&amp;lt;paypal&amp;gt;Denver&amp;lt;/paypal&amp;gt; --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72718</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72718"/>
				<updated>2009-11-05T19:54:01Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''November Meeting combined with the Denver Chapter meeting:'''&lt;br /&gt;
&lt;br /&gt;
Wednesday 18 November 2009, 6pm @ Raytheon Polar Services &lt;br /&gt;
&lt;br /&gt;
Anton Rager: &amp;quot;The Evils of XSS: Its not just for cookies anymore&amp;quot; &lt;br /&gt;
&lt;br /&gt;
Many security professionals, security administrators and developers are aware of Cross-Site Scripting (XSS) vulnerabilities, but disregard them as a significant risk to an organization. Traditionally XSS attacks have either involved nuisance re-direction of a client or leakage of client cookies/state information to an attacker. They are almost always a one-shot XSS exploit against a vulnerable server and dont have the ability to execute multiple transactions against an XSS vulnerable site. &lt;br /&gt;
&lt;br /&gt;
This presentation briefly outlines current XSS attacks, then discusses and demonstrates methods to create multi-transaction XSS attacks or persistent XSS based browser hi-jacking. Browser hi-jacking uses the victim browser to leverage existing trust that a browser may have with an XSS vulnerable site, and performs an arbitrary number of transactions from the victim browser against the vulnerable site. This means that the attacker can use the victims browser to attack a site that is behind a firewall, requires client-side certificates, filters IP addresses, or has a cached authentication with the victim browser this is way beyond cookie theft as an attacker is actually using the victims browser to access the site. Attack modes can include transparent site traversal thru victim browser (read and/or write to server with access of victim from remote attack console), passive monitoring of victim interaction with target site, or active MITM content modification of information to/from victim browser. &lt;br /&gt;
&lt;br /&gt;
A custom tool (XSS-Proxy) will be demonstrated that demonstrates the ability for a remote attacker to perform these XSS based attacks. XSS persistence and commands are controlled from a Perl based HTTP attack server with victim/XSS target content forwarded to the same server. This does not rely on any new vulnerability in browsers and currently works in modern JavaScript enabled IE and Mozilla/Firefox based browsers. &lt;br /&gt;
&lt;br /&gt;
Presenter: Anton Rager &lt;br /&gt;
&lt;br /&gt;
Anton Rager is an independent security researcher focused on vulnerability exploitation, VPN security and wireless security. He is currently a programmer with an undisclosed network storage startup where he focuses on application development, Linux network magic, and Linux kernel/driver hacking. &lt;br /&gt;
He is best known for his work with 802.11 wireless WEP security and associated testing/analysis tools. In 2001 he released WEPCrack, the first open-source, public domain utility to validate the WEP/RC4 attack discovered by Fluhrer, Mantin and Shamir. Anton was also a Contributing Technical Editor to the book Maximum Wireless Security. In 2003 he continued researching 802.11/WEP and developed an injection attack and open-source tool (WEPWedgie) that allows network scanning attacks of WEP encrypted networks without knowledge of WEP keys. This tool/attack is mentioned in the book WI-FOO: The Secrets of Wireless Hacking as well as multiple online articles. &lt;br /&gt;
&lt;br /&gt;
Anton has also focused heavily on IPSec VPN security issues and in 2001 implemented the first open-source utility to allow password attacks against IKE based IPSec VPN connections (IKECrack). Follow-on IPSec research resulted in an IKE protocol testing tool (IKEProber) that highlighted multiple vulnerabilities in common IPSec client/gateway implementations. &lt;br /&gt;
&lt;br /&gt;
More recently he has been working with web application security issues and in 2005 devised a novel Cross-Site-Scripting (XSS) attack method and open-source tool (XSS-Proxy) to allow browser hijacking with XSS vulnerable sites. This tool/attack is also highlighted in Phishing Exposed book and as well as the book XSS-Attacks that he co-authored with other leading XSS researchers. &lt;br /&gt;
Anton has presented at well-known security conferences and has conducted many security training and security awareness primers with industry and government sectors. He currently resides and works near Denver, Colorado. In addition to an addictive computer security hobby, Anton is also an extreme mountain biker, snowboarder, naturalist, guitarist and philosopher hack. &lt;br /&gt;
&lt;br /&gt;
Agenda &lt;br /&gt;
&lt;br /&gt;
•	6pm: Pizza &amp;amp; pop @ Raytheon Polar Services, courtesy of Accuvant &lt;br /&gt;
&lt;br /&gt;
•	6:30pm: Introduction and Chapter business &lt;br /&gt;
&lt;br /&gt;
•	6:45pm --&amp;gt; 8pm: Presentation&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72717</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72717"/>
				<updated>2009-11-05T19:53:44Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
'''November Meeting combined with the Denver Chapter meeting:'''&lt;br /&gt;
&lt;br /&gt;
Wednesday 18 November 2009, 6pm @ Raytheon Polar Services &lt;br /&gt;
&lt;br /&gt;
Anton Rager: &amp;quot;The Evils of XSS: Its not just for cookies anymore&amp;quot; &lt;br /&gt;
&lt;br /&gt;
Many security professionals, security administrators and developers are aware of Cross-Site Scripting (XSS) vulnerabilities, but disregard them as a significant risk to an organization. Traditionally XSS attacks have either involved nuisance re-direction of a client or leakage of client cookies/state information to an attacker. They are almost always a one-shot XSS exploit against a vulnerable server and dont have the ability to execute multiple transactions against an XSS vulnerable site. &lt;br /&gt;
&lt;br /&gt;
This presentation briefly outlines current XSS attacks, then discusses and demonstrates methods to create multi-transaction XSS attacks or persistent XSS based browser hi-jacking. Browser hi-jacking uses the victim browser to leverage existing trust that a browser may have with an XSS vulnerable site, and performs an arbitrary number of transactions from the victim browser against the vulnerable site. This means that the attacker can use the victims browser to attack a site that is behind a firewall, requires client-side certificates, filters IP addresses, or has a cached authentication with the victim browser this is way beyond cookie theft as an attacker is actually using the victims browser to access the site. Attack modes can include transparent site traversal thru victim browser (read and/or write to server with access of victim from remote attack console), passive monitoring of victim interaction with target site, or active MITM content modification of information to/from victim browser. &lt;br /&gt;
&lt;br /&gt;
A custom tool (XSS-Proxy) will be demonstrated that demonstrates the ability for a remote attacker to perform these XSS based attacks. XSS persistence and commands are controlled from a Perl based HTTP attack server with victim/XSS target content forwarded to the same server. This does not rely on any new vulnerability in browsers and currently works in modern JavaScript enabled IE and Mozilla/Firefox based browsers. &lt;br /&gt;
&lt;br /&gt;
Presenter: Anton Rager &lt;br /&gt;
&lt;br /&gt;
Anton Rager is an independent security researcher focused on vulnerability exploitation, VPN security and wireless security. He is currently a programmer with an undisclosed network storage startup where he focuses on application development, Linux network magic, and Linux kernel/driver hacking. &lt;br /&gt;
He is best known for his work with 802.11 wireless WEP security and associated testing/analysis tools. In 2001 he released WEPCrack, the first open-source, public domain utility to validate the WEP/RC4 attack discovered by Fluhrer, Mantin and Shamir. Anton was also a Contributing Technical Editor to the book Maximum Wireless Security. In 2003 he continued researching 802.11/WEP and developed an injection attack and open-source tool (WEPWedgie) that allows network scanning attacks of WEP encrypted networks without knowledge of WEP keys. This tool/attack is mentioned in the book WI-FOO: The Secrets of Wireless Hacking as well as multiple online articles. &lt;br /&gt;
&lt;br /&gt;
Anton has also focused heavily on IPSec VPN security issues and in 2001 implemented the first open-source utility to allow password attacks against IKE based IPSec VPN connections (IKECrack). Follow-on IPSec research resulted in an IKE protocol testing tool (IKEProber) that highlighted multiple vulnerabilities in common IPSec client/gateway implementations. &lt;br /&gt;
&lt;br /&gt;
More recently he has been working with web application security issues and in 2005 devised a novel Cross-Site-Scripting (XSS) attack method and open-source tool (XSS-Proxy) to allow browser hijacking with XSS vulnerable sites. This tool/attack is also highlighted in Phishing Exposed book and as well as the book XSS-Attacks that he co-authored with other leading XSS researchers. &lt;br /&gt;
Anton has presented at well-known security conferences and has conducted many security training and security awareness primers with industry and government sectors. He currently resides and works near Denver, Colorado. In addition to an addictive computer security hobby, Anton is also an extreme mountain biker, snowboarder, naturalist, guitarist and philosopher hack. &lt;br /&gt;
&lt;br /&gt;
Agenda &lt;br /&gt;
&lt;br /&gt;
•	6pm: Pizza &amp;amp; pop @ Raytheon Polar Services, courtesy of Accuvant &lt;br /&gt;
&lt;br /&gt;
•	6:30pm: Introduction and Chapter business &lt;br /&gt;
&lt;br /&gt;
•	6:45pm --&amp;gt; 8pm: Presentation&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72716</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72716"/>
				<updated>2009-11-05T19:53:22Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
'''November Meeting combined with the Denver Chapter meeting:'''&lt;br /&gt;
&lt;br /&gt;
Wednesday 18 November 2009, 6pm @ Raytheon Polar Services &lt;br /&gt;
&lt;br /&gt;
Anton Rager: &amp;quot;The Evils of XSS: Its not just for cookies anymore&amp;quot; &lt;br /&gt;
&lt;br /&gt;
Many security professionals, security administrators and developers are aware of Cross-Site Scripting (XSS) vulnerabilities, but disregard them as a significant risk to an organization. Traditionally XSS attacks have either involved nuisance re-direction of a client or leakage of client cookies/state information to an attacker. They are almost always a one-shot XSS exploit against a vulnerable server and dont have the ability to execute multiple transactions against an XSS vulnerable site. &lt;br /&gt;
&lt;br /&gt;
This presentation briefly outlines current XSS attacks, then discusses and demonstrates methods to create multi-transaction XSS attacks or persistent XSS based browser hi-jacking. Browser hi-jacking uses the victim browser to leverage existing trust that a browser may have with an XSS vulnerable site, and performs an arbitrary number of transactions from the victim browser against the vulnerable site. This means that the attacker can use the victims browser to attack a site that is behind a firewall, requires client-side certificates, filters IP addresses, or has a cached authentication with the victim browser this is way beyond cookie theft as an attacker is actually using the victims browser to access the site. Attack modes can include transparent site traversal thru victim browser (read and/or write to server with access of victim from remote attack console), passive monitoring of victim interaction with target site, or active MITM content modification of information to/from victim browser. &lt;br /&gt;
&lt;br /&gt;
A custom tool (XSS-Proxy) will be demonstrated that demonstrates the ability for a remote attacker to perform these XSS based attacks. XSS persistence and commands are controlled from a Perl based HTTP attack server with victim/XSS target content forwarded to the same server. This does not rely on any new vulnerability in browsers and currently works in modern JavaScript enabled IE and Mozilla/Firefox based browsers. &lt;br /&gt;
&lt;br /&gt;
Presenter: Anton Rager &lt;br /&gt;
&lt;br /&gt;
Anton Rager is an independent security researcher focused on vulnerability exploitation, VPN security and wireless security. He is currently a programmer with an undisclosed network storage startup where he focuses on application development, Linux network magic, and Linux kernel/driver hacking. &lt;br /&gt;
He is best known for his work with 802.11 wireless WEP security and associated testing/analysis tools. In 2001 he released WEPCrack, the first open-source, public domain utility to validate the WEP/RC4 attack discovered by Fluhrer, Mantin and Shamir. Anton was also a Contributing Technical Editor to the book Maximum Wireless Security. In 2003 he continued researching 802.11/WEP and developed an injection attack and open-source tool (WEPWedgie) that allows network scanning attacks of WEP encrypted networks without knowledge of WEP keys. This tool/attack is mentioned in the book WI-FOO: The Secrets of Wireless Hacking as well as multiple online articles. &lt;br /&gt;
&lt;br /&gt;
Anton has also focused heavily on IPSec VPN security issues and in 2001 implemented the first open-source utility to allow password attacks against IKE based IPSec VPN connections (IKECrack). Follow-on IPSec research resulted in an IKE protocol testing tool (IKEProber) that highlighted multiple vulnerabilities in common IPSec client/gateway implementations. &lt;br /&gt;
&lt;br /&gt;
More recently he has been working with web application security issues and in 2005 devised a novel Cross-Site-Scripting (XSS) attack method and open-source tool (XSS-Proxy) to allow browser hijacking with XSS vulnerable sites. This tool/attack is also highlighted in Phishing Exposed book and as well as the book XSS-Attacks that he co-authored with other leading XSS researchers. &lt;br /&gt;
Anton has presented at well-known security conferences and has conducted many security training and security awareness primers with industry and government sectors. He currently resides and works near Denver, Colorado. In addition to an addictive computer security hobby, Anton is also an extreme mountain biker, snowboarder, naturalist, guitarist and philosopher hack. &lt;br /&gt;
&lt;br /&gt;
Agenda &lt;br /&gt;
•	6pm: Pizza &amp;amp; pop @ Raytheon Polar Services, courtesy of Accuvant &lt;br /&gt;
•	6:30pm: Introduction and Chapter business &lt;br /&gt;
•	6:45pm --&amp;gt; 8pm: Presentation&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72714</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72714"/>
				<updated>2009-11-05T19:51:43Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* December  - Date TBA  “Capture the Holiday flag” */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NEXT MEETING SEPTEMBER 24TH.  SEE AGENDA BELOW&lt;br /&gt;
&lt;br /&gt;
November Meeting combined with the Denver Chapter meeting:&lt;br /&gt;
&lt;br /&gt;
Wednesday 18 November 2009, 6pm @ Raytheon Polar Services &lt;br /&gt;
Anton Rager: &amp;quot;The Evils of XSS: Its not just for cookies anymore&amp;quot; &lt;br /&gt;
Many security professionals, security administrators and developers are aware of Cross-Site Scripting (XSS) vulnerabilities, but disregard them as a significant risk to an organization. Traditionally XSS attacks have either involved nuisance re-direction of a client or leakage of client cookies/state information to an attacker. They are almost always a one-shot XSS exploit against a vulnerable server and dont have the ability to execute multiple transactions against an XSS vulnerable site. &lt;br /&gt;
This presentation briefly outlines current XSS attacks, then discusses and demonstrates methods to create multi-transaction XSS attacks or persistent XSS based browser hi-jacking. Browser hi-jacking uses the victim browser to leverage existing trust that a browser may have with an XSS vulnerable site, and performs an arbitrary number of transactions from the victim browser against the vulnerable site. This means that the attacker can use the victims browser to attack a site that is behind a firewall, requires client-side certificates, filters IP addresses, or has a cached authentication with the victim browser this is way beyond cookie theft as an attacker is actually using the victims browser to access the site. Attack modes can include transparent site traversal thru victim browser (read and/or write to server with access of victim from remote attack console), passive monitoring of victim interaction with target site, or active MITM content modification of information to/from victim browser. &lt;br /&gt;
A custom tool (XSS-Proxy) will be demonstrated that demonstrates the ability for a remote attacker to perform these XSS based attacks. XSS persistence and commands are controlled from a Perl based HTTP attack server with victim/XSS target content forwarded to the same server. This does not rely on any new vulnerability in browsers and currently works in modern JavaScript enabled IE and Mozilla/Firefox based browsers. &lt;br /&gt;
&lt;br /&gt;
Presenter: Anton Rager &lt;br /&gt;
Anton Rager is an independent security researcher focused on vulnerability exploitation, VPN security and wireless security. He is currently a programmer with an undisclosed network storage startup where he focuses on application development, Linux network magic, and Linux kernel/driver hacking. &lt;br /&gt;
He is best known for his work with 802.11 wireless WEP security and associated testing/analysis tools. In 2001 he released WEPCrack, the first open-source, public domain utility to validate the WEP/RC4 attack discovered by Fluhrer, Mantin and Shamir. Anton was also a Contributing Technical Editor to the book Maximum Wireless Security. In 2003 he continued researching 802.11/WEP and developed an injection attack and open-source tool (WEPWedgie) that allows network scanning attacks of WEP encrypted networks without knowledge of WEP keys. This tool/attack is mentioned in the book WI-FOO: The Secrets of Wireless Hacking as well as multiple online articles. &lt;br /&gt;
Anton has also focused heavily on IPSec VPN security issues and in 2001 implemented the first open-source utility to allow password attacks against IKE based IPSec VPN connections (IKECrack). Follow-on IPSec research resulted in an IKE protocol testing tool (IKEProber) that highlighted multiple vulnerabilities in common IPSec client/gateway implementations. &lt;br /&gt;
More recently he has been working with web application security issues and in 2005 devised a novel Cross-Site-Scripting (XSS) attack method and open-source tool (XSS-Proxy) to allow browser hijacking with XSS vulnerable sites. This tool/attack is also highlighted in Phishing Exposed book and as well as the book XSS-Attacks that he co-authored with other leading XSS researchers. &lt;br /&gt;
Anton has presented at well-known security conferences and has conducted many security training and security awareness primers with industry and government sectors. He currently resides and works near Denver, Colorado. In addition to an addictive computer security hobby, Anton is also an extreme mountain biker, snowboarder, naturalist, guitarist and philosopher hack. &lt;br /&gt;
&lt;br /&gt;
Agenda &lt;br /&gt;
•	6pm: Pizza &amp;amp; pop @ Raytheon Polar Services, courtesy of Accuvant &lt;br /&gt;
•	6:30pm: Introduction and Chapter business &lt;br /&gt;
•	6:45pm --&amp;gt; 8pm: Presentation&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72713</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72713"/>
				<updated>2009-11-05T19:50:35Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* October and November 2009 Meetings will be joint with the Denver OWASP at a downtown location TBA */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NEXT MEETING SEPTEMBER 24TH.  SEE AGENDA BELOW&lt;br /&gt;
&lt;br /&gt;
November Meeting combined with the Denver Chapter meeting:&lt;br /&gt;
&lt;br /&gt;
Wednesday 18 November 2009, 6pm @ Raytheon Polar Services &lt;br /&gt;
Anton Rager: &amp;quot;The Evils of XSS: Its not just for cookies anymore&amp;quot; &lt;br /&gt;
Many security professionals, security administrators and developers are aware of Cross-Site Scripting (XSS) vulnerabilities, but disregard them as a significant risk to an organization. Traditionally XSS attacks have either involved nuisance re-direction of a client or leakage of client cookies/state information to an attacker. They are almost always a one-shot XSS exploit against a vulnerable server and dont have the ability to execute multiple transactions against an XSS vulnerable site. &lt;br /&gt;
This presentation briefly outlines current XSS attacks, then discusses and demonstrates methods to create multi-transaction XSS attacks or persistent XSS based browser hi-jacking. Browser hi-jacking uses the victim browser to leverage existing trust that a browser may have with an XSS vulnerable site, and performs an arbitrary number of transactions from the victim browser against the vulnerable site. This means that the attacker can use the victims browser to attack a site that is behind a firewall, requires client-side certificates, filters IP addresses, or has a cached authentication with the victim browser this is way beyond cookie theft as an attacker is actually using the victims browser to access the site. Attack modes can include transparent site traversal thru victim browser (read and/or write to server with access of victim from remote attack console), passive monitoring of victim interaction with target site, or active MITM content modification of information to/from victim browser. &lt;br /&gt;
A custom tool (XSS-Proxy) will be demonstrated that demonstrates the ability for a remote attacker to perform these XSS based attacks. XSS persistence and commands are controlled from a Perl based HTTP attack server with victim/XSS target content forwarded to the same server. This does not rely on any new vulnerability in browsers and currently works in modern JavaScript enabled IE and Mozilla/Firefox based browsers. &lt;br /&gt;
&lt;br /&gt;
Presenter: Anton Rager &lt;br /&gt;
Anton Rager is an independent security researcher focused on vulnerability exploitation, VPN security and wireless security. He is currently a programmer with an undisclosed network storage startup where he focuses on application development, Linux network magic, and Linux kernel/driver hacking. &lt;br /&gt;
He is best known for his work with 802.11 wireless WEP security and associated testing/analysis tools. In 2001 he released WEPCrack, the first open-source, public domain utility to validate the WEP/RC4 attack discovered by Fluhrer, Mantin and Shamir. Anton was also a Contributing Technical Editor to the book Maximum Wireless Security. In 2003 he continued researching 802.11/WEP and developed an injection attack and open-source tool (WEPWedgie) that allows network scanning attacks of WEP encrypted networks without knowledge of WEP keys. This tool/attack is mentioned in the book WI-FOO: The Secrets of Wireless Hacking as well as multiple online articles. &lt;br /&gt;
Anton has also focused heavily on IPSec VPN security issues and in 2001 implemented the first open-source utility to allow password attacks against IKE based IPSec VPN connections (IKECrack). Follow-on IPSec research resulted in an IKE protocol testing tool (IKEProber) that highlighted multiple vulnerabilities in common IPSec client/gateway implementations. &lt;br /&gt;
More recently he has been working with web application security issues and in 2005 devised a novel Cross-Site-Scripting (XSS) attack method and open-source tool (XSS-Proxy) to allow browser hijacking with XSS vulnerable sites. This tool/attack is also highlighted in Phishing Exposed book and as well as the book XSS-Attacks that he co-authored with other leading XSS researchers. &lt;br /&gt;
Anton has presented at well-known security conferences and has conducted many security training and security awareness primers with industry and government sectors. He currently resides and works near Denver, Colorado. In addition to an addictive computer security hobby, Anton is also an extreme mountain biker, snowboarder, naturalist, guitarist and philosopher hack. &lt;br /&gt;
&lt;br /&gt;
Agenda &lt;br /&gt;
•	6pm: Pizza &amp;amp; pop @ Raytheon Polar Services, courtesy of Accuvant &lt;br /&gt;
•	6:30pm: Introduction and Chapter business &lt;br /&gt;
•	6:45pm --&amp;gt; 8pm: Presentation&lt;br /&gt;
&lt;br /&gt;
== December  - Date TBA  “Capture the Holiday flag” ==&lt;br /&gt;
&lt;br /&gt;
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72712</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72712"/>
				<updated>2009-11-05T19:49:44Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* Logistics */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NEXT MEETING SEPTEMBER 24TH.  SEE AGENDA BELOW&lt;br /&gt;
&lt;br /&gt;
== October and November 2009 Meetings will be joint with the Denver OWASP at a downtown location TBA ==&lt;br /&gt;
==Unfortunately we are going to have to cancel this months (September 2009) meeting.  Our sponsor presenter was unable to make it out here at the last minute due to some budgeting constraints.&lt;br /&gt;
&lt;br /&gt;
David Campbell (Denver OWASP) and I will be holding joint meetings for October and November at a downtown location in order to make it convenient for all of our members.  We will be focusing on Cloud Security for the rest of the year as this has become a hot topic and pertinent to 2010 planning for many.==&lt;br /&gt;
&lt;br /&gt;
== December  - Date TBA  “Capture the Holiday flag” ==&lt;br /&gt;
&lt;br /&gt;
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72711</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72711"/>
				<updated>2009-11-05T19:49:02Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* Agenda */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NEXT MEETING SEPTEMBER 24TH.  SEE AGENDA BELOW&lt;br /&gt;
&lt;br /&gt;
=== Logistics ===&lt;br /&gt;
Please bring a wifi equipped laptop.  We recommend the [http://www.owasp.org/index.php/Category:OWASP_Live_CD_2008_Project OWASP LiveCD].  Go ahead and download it and familiarize yourself with it ahead of time, if you're so inclined.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following the meeting we will have informal discussions over beverages at the [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Gordon+Biersch+Brewery+Broomfield+colorado&amp;amp;ie=UTF8&amp;amp;ll=39.935803,-105.13092&amp;amp;spn=0.077395,0.144711&amp;amp;z=13&amp;amp;iwloc=A Gordon Biersch Brewery and Restaurant].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
== October and November 2009 Meetings will be joint with the Denver OWASP at a downtown location TBA ==&lt;br /&gt;
==Unfortunately we are going to have to cancel this months (September 2009) meeting.  Our sponsor presenter was unable to make it out here at the last minute due to some budgeting constraints.&lt;br /&gt;
&lt;br /&gt;
David Campbell (Denver OWASP) and I will be holding joint meetings for October and November at a downtown location in order to make it convenient for all of our members.  We will be focusing on Cloud Security for the rest of the year as this has become a hot topic and pertinent to 2010 planning for many.==&lt;br /&gt;
&lt;br /&gt;
== December  - Date TBA  “Capture the Holiday flag” ==&lt;br /&gt;
&lt;br /&gt;
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72710</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=72710"/>
				<updated>2009-11-05T19:48:17Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* Directions to Staples: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NEXT MEETING SEPTEMBER 24TH.  SEE AGENDA BELOW&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
* 6 to 7:00 Dinner @ [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Corporate+Express+1+Environmental+Way,+Broomfield+colorado&amp;amp;sll=39.935803,-105.13092&amp;amp;sspn=0.077395,0.144711&amp;amp;ie=UTF8&amp;amp;ll=39.926934,-105.126565&amp;amp;spn=0.009676,0.018089&amp;amp;z=16&amp;amp;iwloc=A Staples CE - Broomfield] &lt;br /&gt;
&lt;br /&gt;
* 7pm to 8:30 pm Cross-site scripting lab&lt;br /&gt;
Sponsor:  '''Nope, no sponsor.  It'a your chapter, BYO dinner and/or order pizza at 6'ish'''&lt;br /&gt;
&lt;br /&gt;
Speaker:  tbd&lt;br /&gt;
&lt;br /&gt;
=== Logistics ===&lt;br /&gt;
Please bring a wifi equipped laptop.  We recommend the [http://www.owasp.org/index.php/Category:OWASP_Live_CD_2008_Project OWASP LiveCD].  Go ahead and download it and familiarize yourself with it ahead of time, if you're so inclined.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following the meeting we will have informal discussions over beverages at the [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Gordon+Biersch+Brewery+Broomfield+colorado&amp;amp;ie=UTF8&amp;amp;ll=39.935803,-105.13092&amp;amp;spn=0.077395,0.144711&amp;amp;z=13&amp;amp;iwloc=A Gordon Biersch Brewery and Restaurant].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
== October and November 2009 Meetings will be joint with the Denver OWASP at a downtown location TBA ==&lt;br /&gt;
==Unfortunately we are going to have to cancel this months (September 2009) meeting.  Our sponsor presenter was unable to make it out here at the last minute due to some budgeting constraints.&lt;br /&gt;
&lt;br /&gt;
David Campbell (Denver OWASP) and I will be holding joint meetings for October and November at a downtown location in order to make it convenient for all of our members.  We will be focusing on Cloud Security for the rest of the year as this has become a hot topic and pertinent to 2010 planning for many.==&lt;br /&gt;
&lt;br /&gt;
== December  - Date TBA  “Capture the Holiday flag” ==&lt;br /&gt;
&lt;br /&gt;
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=69649</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=69649"/>
				<updated>2009-09-22T22:12:03Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* October and November 2009 Meetings will be joint with the Denver OWASP at a downtown location TBA */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NEXT MEETING SEPTEMBER 24TH.  SEE AGENDA BELOW&lt;br /&gt;
&lt;br /&gt;
=== Directions to Staples: ===&lt;br /&gt;
&lt;br /&gt;
'''Staples:  [http://maps.google.com/maps?q=1+Environmental+Way,+Broomfield,+CO+80021,+USA&amp;amp;sa=X&amp;amp;oi=map&amp;amp;ct=title One Environmental Way, Broomfield, Co. 80021]'''&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
* 6 to 7:00 Dinner @ [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Corporate+Express+1+Environmental+Way,+Broomfield+colorado&amp;amp;sll=39.935803,-105.13092&amp;amp;sspn=0.077395,0.144711&amp;amp;ie=UTF8&amp;amp;ll=39.926934,-105.126565&amp;amp;spn=0.009676,0.018089&amp;amp;z=16&amp;amp;iwloc=A Staples CE - Broomfield] &lt;br /&gt;
&lt;br /&gt;
* 7pm to 8:30 pm Cross-site scripting lab&lt;br /&gt;
Sponsor:  '''Nope, no sponsor.  It'a your chapter, BYO dinner and/or order pizza at 6'ish'''&lt;br /&gt;
&lt;br /&gt;
Speaker:  tbd&lt;br /&gt;
&lt;br /&gt;
=== Logistics ===&lt;br /&gt;
Please bring a wifi equipped laptop.  We recommend the [http://www.owasp.org/index.php/Category:OWASP_Live_CD_2008_Project OWASP LiveCD].  Go ahead and download it and familiarize yourself with it ahead of time, if you're so inclined.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following the meeting we will have informal discussions over beverages at the [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Gordon+Biersch+Brewery+Broomfield+colorado&amp;amp;ie=UTF8&amp;amp;ll=39.935803,-105.13092&amp;amp;spn=0.077395,0.144711&amp;amp;z=13&amp;amp;iwloc=A Gordon Biersch Brewery and Restaurant].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
== October and November 2009 Meetings will be joint with the Denver OWASP at a downtown location TBA ==&lt;br /&gt;
==Unfortunately we are going to have to cancel this months (September 2009) meeting.  Our sponsor presenter was unable to make it out here at the last minute due to some budgeting constraints.&lt;br /&gt;
&lt;br /&gt;
David Campbell (Denver OWASP) and I will be holding joint meetings for October and November at a downtown location in order to make it convenient for all of our members.  We will be focusing on Cloud Security for the rest of the year as this has become a hot topic and pertinent to 2010 planning for many.==&lt;br /&gt;
&lt;br /&gt;
== December  - Date TBA  “Capture the Holiday flag” ==&lt;br /&gt;
&lt;br /&gt;
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=69648</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=69648"/>
				<updated>2009-09-22T22:11:49Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* December  - Date TBA  “Capture the Holiday flag” */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NEXT MEETING SEPTEMBER 24TH.  SEE AGENDA BELOW&lt;br /&gt;
&lt;br /&gt;
=== Directions to Staples: ===&lt;br /&gt;
&lt;br /&gt;
'''Staples:  [http://maps.google.com/maps?q=1+Environmental+Way,+Broomfield,+CO+80021,+USA&amp;amp;sa=X&amp;amp;oi=map&amp;amp;ct=title One Environmental Way, Broomfield, Co. 80021]'''&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
* 6 to 7:00 Dinner @ [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Corporate+Express+1+Environmental+Way,+Broomfield+colorado&amp;amp;sll=39.935803,-105.13092&amp;amp;sspn=0.077395,0.144711&amp;amp;ie=UTF8&amp;amp;ll=39.926934,-105.126565&amp;amp;spn=0.009676,0.018089&amp;amp;z=16&amp;amp;iwloc=A Staples CE - Broomfield] &lt;br /&gt;
&lt;br /&gt;
* 7pm to 8:30 pm Cross-site scripting lab&lt;br /&gt;
Sponsor:  '''Nope, no sponsor.  It'a your chapter, BYO dinner and/or order pizza at 6'ish'''&lt;br /&gt;
&lt;br /&gt;
Speaker:  tbd&lt;br /&gt;
&lt;br /&gt;
=== Logistics ===&lt;br /&gt;
Please bring a wifi equipped laptop.  We recommend the [http://www.owasp.org/index.php/Category:OWASP_Live_CD_2008_Project OWASP LiveCD].  Go ahead and download it and familiarize yourself with it ahead of time, if you're so inclined.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following the meeting we will have informal discussions over beverages at the [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Gordon+Biersch+Brewery+Broomfield+colorado&amp;amp;ie=UTF8&amp;amp;ll=39.935803,-105.13092&amp;amp;spn=0.077395,0.144711&amp;amp;z=13&amp;amp;iwloc=A Gordon Biersch Brewery and Restaurant].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
== October and November 2009 Meetings will be joint with the Denver OWASP at a downtown location TBA ==&lt;br /&gt;
===Unfortunately we are going to have to cancel this months (September 2009) meeting.  Our sponsor presenter was unable to make it out here at the last minute due to some budgeting constraints.&lt;br /&gt;
&lt;br /&gt;
David Campbell (Denver OWASP) and I will be holding joint meetings for October and November at a downtown location in order to make it convenient for all of our members.  We will be focusing on Cloud Security for the rest of the year as this has become a hot topic and pertinent to 2010 planning for many.===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== December  - Date TBA  “Capture the Holiday flag” ==&lt;br /&gt;
&lt;br /&gt;
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=69647</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=69647"/>
				<updated>2009-09-22T22:09:19Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* Boulder OWASP 2009 AGENDA */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NEXT MEETING SEPTEMBER 24TH.  SEE AGENDA BELOW&lt;br /&gt;
&lt;br /&gt;
=== Directions to Staples: ===&lt;br /&gt;
&lt;br /&gt;
'''Staples:  [http://maps.google.com/maps?q=1+Environmental+Way,+Broomfield,+CO+80021,+USA&amp;amp;sa=X&amp;amp;oi=map&amp;amp;ct=title One Environmental Way, Broomfield, Co. 80021]'''&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
* 6 to 7:00 Dinner @ [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Corporate+Express+1+Environmental+Way,+Broomfield+colorado&amp;amp;sll=39.935803,-105.13092&amp;amp;sspn=0.077395,0.144711&amp;amp;ie=UTF8&amp;amp;ll=39.926934,-105.126565&amp;amp;spn=0.009676,0.018089&amp;amp;z=16&amp;amp;iwloc=A Staples CE - Broomfield] &lt;br /&gt;
&lt;br /&gt;
* 7pm to 8:30 pm Cross-site scripting lab&lt;br /&gt;
Sponsor:  '''Nope, no sponsor.  It'a your chapter, BYO dinner and/or order pizza at 6'ish'''&lt;br /&gt;
&lt;br /&gt;
Speaker:  tbd&lt;br /&gt;
&lt;br /&gt;
=== Logistics ===&lt;br /&gt;
Please bring a wifi equipped laptop.  We recommend the [http://www.owasp.org/index.php/Category:OWASP_Live_CD_2008_Project OWASP LiveCD].  Go ahead and download it and familiarize yourself with it ahead of time, if you're so inclined.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following the meeting we will have informal discussions over beverages at the [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Gordon+Biersch+Brewery+Broomfield+colorado&amp;amp;ie=UTF8&amp;amp;ll=39.935803,-105.13092&amp;amp;spn=0.077395,0.144711&amp;amp;z=13&amp;amp;iwloc=A Gordon Biersch Brewery and Restaurant].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
== October and November 2009 Meetings will be joint with the Denver OWASP at a downtown location TBA ==&lt;br /&gt;
===Unfortunately we are going to have to cancel this months (September 2009) meeting.  Our sponsor presenter was unable to make it out here at the last minute due to some budgeting constraints.&lt;br /&gt;
&lt;br /&gt;
David Campbell (Denver OWASP) and I will be holding joint meetings for October and November at a downtown location in order to make it convenient for all of our members.  We will be focusing on Cloud Security for the rest of the year as this has become a hot topic and pertinent to 2010 planning for many.===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== December  - Date TBA  “Capture the Holiday flag” ===&lt;br /&gt;
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=67762</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=67762"/>
				<updated>2009-08-20T16:40:20Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* Directions to Staples: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
NEXT MEETING SEPTEMBER 24TH.  SEE AGENDA BELOW&lt;br /&gt;
&lt;br /&gt;
=== Directions to Staples: ===&lt;br /&gt;
&lt;br /&gt;
'''Staples:  [http://maps.google.com/maps?q=1+Environmental+Way,+Broomfield,+CO+80021,+USA&amp;amp;sa=X&amp;amp;oi=map&amp;amp;ct=title One Environmental Way, Broomfield, Co. 80021]'''&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
* 6 to 7:00 Dinner @ [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Corporate+Express+1+Environmental+Way,+Broomfield+colorado&amp;amp;sll=39.935803,-105.13092&amp;amp;sspn=0.077395,0.144711&amp;amp;ie=UTF8&amp;amp;ll=39.926934,-105.126565&amp;amp;spn=0.009676,0.018089&amp;amp;z=16&amp;amp;iwloc=A Staples CE - Broomfield] &lt;br /&gt;
&lt;br /&gt;
* 7pm to 8:30 pm Cross-site scripting lab&lt;br /&gt;
Sponsor:  '''Nope, no sponsor.  It'a your chapter, BYO dinner and/or order pizza at 6'ish'''&lt;br /&gt;
&lt;br /&gt;
Speaker:  tbd&lt;br /&gt;
&lt;br /&gt;
=== Logistics ===&lt;br /&gt;
Please bring a wifi equipped laptop.  We recommend the [http://www.owasp.org/index.php/Category:OWASP_Live_CD_2008_Project OWASP LiveCD].  Go ahead and download it and familiarize yourself with it ahead of time, if you're so inclined.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following the meeting we will have informal discussions over beverages at the [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Gordon+Biersch+Brewery+Broomfield+colorado&amp;amp;ie=UTF8&amp;amp;ll=39.935803,-105.13092&amp;amp;spn=0.077395,0.144711&amp;amp;z=13&amp;amp;iwloc=A Gordon Biersch Brewery and Restaurant].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
== Boulder OWASP 2009 AGENDA ==&lt;br /&gt;
=== May 21, 2009 Cross site scripting Lab ===&lt;br /&gt;
Lab to explain how to attack vulnerable sites –we will use three different examples and &lt;br /&gt;
Spend  one half hour on each:  Basic attacks, intermediate and advanced.&lt;br /&gt;
Teacher TBA.&lt;br /&gt;
&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (we’ll choose one):&lt;br /&gt;
&lt;br /&gt;
Black Hat DC researchers demonstrate new cross-site scripting browser hack that lets attackers retrieve data without a trace&lt;br /&gt;
&lt;br /&gt;
[http://developers.slashdot.org/article.pl?sid=09/05/09/1339213 Should Developers Be Liable For Their Code?]&lt;br /&gt;
&lt;br /&gt;
=== June 18, 2009 Part 2 Cross Site Scripting Lab – put it into practice – how to defend against Cross site scripting ===&lt;br /&gt;
We will defend against a basic attack, an intermediate and advanced.&lt;br /&gt;
Teacher TBA&lt;br /&gt;
Remember to bring your OWASP Live CD and your laptop with CD player.&lt;br /&gt;
Location will be at CSU in Fort Collins.  Directions will be forthcoming.&lt;br /&gt;
6:30 to 7pm Dinner (Brown Bag or we will all order pizza) Lab from 7pm to 9pm.&lt;br /&gt;
&lt;br /&gt;
=== No meetings July or August 2009 ===  &lt;br /&gt;
We will try to put up the sites that we are defending against in the June Lab so that you can have a go at them over the break.&lt;br /&gt;
&lt;br /&gt;
=== September 24, 2009 Sql injection ===&lt;br /&gt;
We will be using SQL injection to attack using  authentication bypass, database enumeration, adding users through sql injection, Data mining, writing code &lt;br /&gt;
Teacher TBA&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (TBA).&lt;br /&gt;
&lt;br /&gt;
=== October, 22, 2009 Defense against sql injection – how to sanitize user input ===&lt;br /&gt;
Teacher TBA&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (TBA).&lt;br /&gt;
&lt;br /&gt;
=== November, 19, 2009 This Lab will put into action the SQL injection attack and the defense.  ===&lt;br /&gt;
We will be using the attacks from the September meeting and then defending against them.&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (TBA).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== December  - Date TBA  “Capture the Holiday flag” ===&lt;br /&gt;
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=67761</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=67761"/>
				<updated>2009-08-20T16:34:05Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* September 17, 2009 Sql injection */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Directions to Staples: ===&lt;br /&gt;
&lt;br /&gt;
'''Staples:  [http://maps.google.com/maps?q=1+Environmental+Way,+Broomfield,+CO+80021,+USA&amp;amp;sa=X&amp;amp;oi=map&amp;amp;ct=title One Environmental Way, Broomfield, Co. 80021]'''&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
* 6 to 7:00 Dinner @ [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Corporate+Express+1+Environmental+Way,+Broomfield+colorado&amp;amp;sll=39.935803,-105.13092&amp;amp;sspn=0.077395,0.144711&amp;amp;ie=UTF8&amp;amp;ll=39.926934,-105.126565&amp;amp;spn=0.009676,0.018089&amp;amp;z=16&amp;amp;iwloc=A Staples CE - Broomfield] &lt;br /&gt;
&lt;br /&gt;
* 7pm to 8:30 pm Cross-site scripting lab&lt;br /&gt;
Sponsor:  '''Nope, no sponsor.  It'a your chapter, BYO dinner and/or order pizza at 6'ish'''&lt;br /&gt;
&lt;br /&gt;
Speaker:  tbd&lt;br /&gt;
&lt;br /&gt;
=== Logistics ===&lt;br /&gt;
Please bring a wifi equipped laptop.  We recommend the [http://www.owasp.org/index.php/Category:OWASP_Live_CD_2008_Project OWASP LiveCD].  Go ahead and download it and familiarize yourself with it ahead of time, if you're so inclined.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following the meeting we will have informal discussions over beverages at the [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Gordon+Biersch+Brewery+Broomfield+colorado&amp;amp;ie=UTF8&amp;amp;ll=39.935803,-105.13092&amp;amp;spn=0.077395,0.144711&amp;amp;z=13&amp;amp;iwloc=A Gordon Biersch Brewery and Restaurant].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
== Boulder OWASP 2009 AGENDA ==&lt;br /&gt;
=== May 21, 2009 Cross site scripting Lab ===&lt;br /&gt;
Lab to explain how to attack vulnerable sites –we will use three different examples and &lt;br /&gt;
Spend  one half hour on each:  Basic attacks, intermediate and advanced.&lt;br /&gt;
Teacher TBA.&lt;br /&gt;
&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (we’ll choose one):&lt;br /&gt;
&lt;br /&gt;
Black Hat DC researchers demonstrate new cross-site scripting browser hack that lets attackers retrieve data without a trace&lt;br /&gt;
&lt;br /&gt;
[http://developers.slashdot.org/article.pl?sid=09/05/09/1339213 Should Developers Be Liable For Their Code?]&lt;br /&gt;
&lt;br /&gt;
=== June 18, 2009 Part 2 Cross Site Scripting Lab – put it into practice – how to defend against Cross site scripting ===&lt;br /&gt;
We will defend against a basic attack, an intermediate and advanced.&lt;br /&gt;
Teacher TBA&lt;br /&gt;
Remember to bring your OWASP Live CD and your laptop with CD player.&lt;br /&gt;
Location will be at CSU in Fort Collins.  Directions will be forthcoming.&lt;br /&gt;
6:30 to 7pm Dinner (Brown Bag or we will all order pizza) Lab from 7pm to 9pm.&lt;br /&gt;
&lt;br /&gt;
=== No meetings July or August 2009 ===  &lt;br /&gt;
We will try to put up the sites that we are defending against in the June Lab so that you can have a go at them over the break.&lt;br /&gt;
&lt;br /&gt;
=== September 24, 2009 Sql injection ===&lt;br /&gt;
We will be using SQL injection to attack using  authentication bypass, database enumeration, adding users through sql injection, Data mining, writing code &lt;br /&gt;
Teacher TBA&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (TBA).&lt;br /&gt;
&lt;br /&gt;
=== October, 22, 2009 Defense against sql injection – how to sanitize user input ===&lt;br /&gt;
Teacher TBA&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (TBA).&lt;br /&gt;
&lt;br /&gt;
=== November, 19, 2009 This Lab will put into action the SQL injection attack and the defense.  ===&lt;br /&gt;
We will be using the attacks from the September meeting and then defending against them.&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (TBA).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== December  - Date TBA  “Capture the Holiday flag” ===&lt;br /&gt;
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Boulder&amp;diff=67760</id>
		<title>Boulder</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Boulder&amp;diff=67760"/>
				<updated>2009-08-20T16:33:24Z</updated>
		
		<summary type="html">&lt;p&gt;Kathleen Thaxton: /* Next Meeting - XSS Lab - Postponed until August 20th, 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Boulder&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Directions to Staples: ===&lt;br /&gt;
&lt;br /&gt;
'''Staples:  [http://maps.google.com/maps?q=1+Environmental+Way,+Broomfield,+CO+80021,+USA&amp;amp;sa=X&amp;amp;oi=map&amp;amp;ct=title One Environmental Way, Broomfield, Co. 80021]'''&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
* 6 to 7:00 Dinner @ [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Corporate+Express+1+Environmental+Way,+Broomfield+colorado&amp;amp;sll=39.935803,-105.13092&amp;amp;sspn=0.077395,0.144711&amp;amp;ie=UTF8&amp;amp;ll=39.926934,-105.126565&amp;amp;spn=0.009676,0.018089&amp;amp;z=16&amp;amp;iwloc=A Staples CE - Broomfield] &lt;br /&gt;
&lt;br /&gt;
* 7pm to 8:30 pm Cross-site scripting lab&lt;br /&gt;
Sponsor:  '''Nope, no sponsor.  It'a your chapter, BYO dinner and/or order pizza at 6'ish'''&lt;br /&gt;
&lt;br /&gt;
Speaker:  tbd&lt;br /&gt;
&lt;br /&gt;
=== Logistics ===&lt;br /&gt;
Please bring a wifi equipped laptop.  We recommend the [http://www.owasp.org/index.php/Category:OWASP_Live_CD_2008_Project OWASP LiveCD].  Go ahead and download it and familiarize yourself with it ahead of time, if you're so inclined.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following the meeting we will have informal discussions over beverages at the [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Gordon+Biersch+Brewery+Broomfield+colorado&amp;amp;ie=UTF8&amp;amp;ll=39.935803,-105.13092&amp;amp;spn=0.077395,0.144711&amp;amp;z=13&amp;amp;iwloc=A Gordon Biersch Brewery and Restaurant].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
== Boulder OWASP 2009 AGENDA ==&lt;br /&gt;
=== May 21, 2009 Cross site scripting Lab ===&lt;br /&gt;
Lab to explain how to attack vulnerable sites –we will use three different examples and &lt;br /&gt;
Spend  one half hour on each:  Basic attacks, intermediate and advanced.&lt;br /&gt;
Teacher TBA.&lt;br /&gt;
&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (we’ll choose one):&lt;br /&gt;
&lt;br /&gt;
Black Hat DC researchers demonstrate new cross-site scripting browser hack that lets attackers retrieve data without a trace&lt;br /&gt;
&lt;br /&gt;
[http://developers.slashdot.org/article.pl?sid=09/05/09/1339213 Should Developers Be Liable For Their Code?]&lt;br /&gt;
&lt;br /&gt;
=== June 18, 2009 Part 2 Cross Site Scripting Lab – put it into practice – how to defend against Cross site scripting ===&lt;br /&gt;
We will defend against a basic attack, an intermediate and advanced.&lt;br /&gt;
Teacher TBA&lt;br /&gt;
Remember to bring your OWASP Live CD and your laptop with CD player.&lt;br /&gt;
Location will be at CSU in Fort Collins.  Directions will be forthcoming.&lt;br /&gt;
6:30 to 7pm Dinner (Brown Bag or we will all order pizza) Lab from 7pm to 9pm.&lt;br /&gt;
&lt;br /&gt;
=== No meetings July or August 2009 ===  &lt;br /&gt;
We will try to put up the sites that we are defending against in the June Lab so that you can have a go at them over the break.&lt;br /&gt;
&lt;br /&gt;
=== September 17, 2009 Sql injection ===&lt;br /&gt;
We will be using SQL injection to attack using  authentication bypass, database enumeration, adding users through sql injection, Data mining, writing code &lt;br /&gt;
Teacher TBA&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (TBA).&lt;br /&gt;
&lt;br /&gt;
=== October, 22, 2009 Defense against sql injection – how to sanitize user input ===&lt;br /&gt;
Teacher TBA&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (TBA).&lt;br /&gt;
&lt;br /&gt;
=== November, 19, 2009 This Lab will put into action the SQL injection attack and the defense.  ===&lt;br /&gt;
We will be using the attacks from the September meeting and then defending against them.&lt;br /&gt;
We will be using the OWASP Live CD and will have them available.&lt;br /&gt;
Must have laptop with CD player.  &lt;br /&gt;
Meeting will be at Staples:  One Environmental Way, Broomfield, Co. 80021&lt;br /&gt;
Brown bag or we can order pizza when everyone gets there.&lt;br /&gt;
6pm to 7pm dinner and Lab from 7pm to 8:30 &lt;br /&gt;
Drinks at Gordon Biersch after the lab.  Topics up for discussion (TBA).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== December  - Date TBA  “Capture the Holiday flag” ===&lt;br /&gt;
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?&lt;/div&gt;</summary>
		<author><name>Kathleen Thaxton</name></author>	</entry>

	</feed>