<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mallory</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mallory"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Mallory"/>
		<updated>2026-04-28T10:07:38Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Chapters_Assigned&amp;diff=15528</id>
		<title>Chapters Assigned</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Chapters_Assigned&amp;diff=15528"/>
				<updated>2007-01-18T02:55:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mallory: /* Design review */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Methodology==&lt;br /&gt;
&lt;br /&gt;
#Code Review Introduction&lt;br /&gt;
#Steps and Roles&lt;br /&gt;
#Code Review Processes&lt;br /&gt;
&lt;br /&gt;
== Design review ==&lt;br /&gt;
#Designing for security &lt;br /&gt;
## - M Roxberry(.NET)&lt;br /&gt;
## - Paolo Perego (Java)&lt;br /&gt;
## - Andrew van der Stock (PHP) &lt;br /&gt;
## - Paolo Perego (C)&lt;br /&gt;
## - C++&lt;br /&gt;
## - Andrew van der Stock (MySQL)&lt;br /&gt;
## - Mallory (AJAX)&lt;br /&gt;
&lt;br /&gt;
==Examples by Vulnerability==&lt;br /&gt;
#Reviewing Code for Buffer Overruns and Overflows - 70%&lt;br /&gt;
#Reviewing Code for OS Injection - 70%&lt;br /&gt;
#Reviewing Code for SQL Injection - 70%&lt;br /&gt;
#Reviewing Code for Data Validation - Jenelle Chapman / E Keary&lt;br /&gt;
#Reviewing Code for Error Handling - Jenelle Chapman&lt;br /&gt;
#Reviewing Code for Logging Issues - 70%&lt;br /&gt;
#Reviewing The Secure Code Environment - E Keary&lt;br /&gt;
#Transaction Analysis - E Keary&lt;br /&gt;
#Authorization (Currently linked to &amp;quot;The Development Guide&amp;quot;)&lt;br /&gt;
#Authentication (Code review)&lt;br /&gt;
#Session Integrity&lt;br /&gt;
#Cross Site Request Forgery&lt;br /&gt;
#Cryptography (Currently linked to &amp;quot;The Development Guide&amp;quot;)&lt;br /&gt;
#Dangerous HTTP Methods ( Secure deployment)&lt;br /&gt;
#Race Conditions&lt;br /&gt;
&lt;br /&gt;
== Language specific best practice ==&lt;br /&gt;
&lt;br /&gt;
===Java=== &lt;br /&gt;
#Inner classes (Paolo Perego)&lt;br /&gt;
#Class comparison (Paolo Perego)&lt;br /&gt;
#Cloneable classes (Paolo Perego)&lt;br /&gt;
#Serializable classes (Paolo Perego)&lt;br /&gt;
#Package scope and encapsulation (Paolo Perego)&lt;br /&gt;
#Mutable objects (Paolo Perego)&lt;br /&gt;
#Private methods &amp;amp; circumvention (Paolo Perego)&lt;br /&gt;
&lt;br /&gt;
===.NET===&lt;br /&gt;
&lt;br /&gt;
===PHP===&lt;br /&gt;
&lt;br /&gt;
Assigned to Andrew van der Stock&lt;br /&gt;
&lt;br /&gt;
===MySQL===&lt;br /&gt;
&lt;br /&gt;
Assigned to Andrew van der Stock&lt;br /&gt;
&lt;br /&gt;
===Stored Procs===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===C/C++===&lt;br /&gt;
&lt;br /&gt;
# Memory management (Paolo Perego)&lt;br /&gt;
# String management (Paolo Perego)&lt;br /&gt;
# Secure access to file system items (Paolo Perego)&lt;br /&gt;
&lt;br /&gt;
==Automating Code Reviews==&lt;br /&gt;
#Preface&lt;br /&gt;
#Reasons for using automated tools&lt;br /&gt;
#Education and cultural change&lt;br /&gt;
#Tool Deployment Model&lt;br /&gt;
&lt;br /&gt;
==References==&lt;/div&gt;</summary>
		<author><name>Mallory</name></author>	</entry>

	</feed>