<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mike</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mike"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Mike"/>
		<updated>2026-04-10T20:18:01Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=117780</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=117780"/>
				<updated>2011-09-21T19:24:45Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:michael.weber35@gmail.com Michael Weber] &amp;amp; [mailto:sheadington@gmail.com Scott Headington].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Next Meeting September 29th, 2011: Basic Cryptography, Scott Headington, Foundstone Security Consultant ==&lt;br /&gt;
&lt;br /&gt;
In this presentation you will learn the basic principles of cryptography and how use of different cryptographic technologies (symmetric, asymmetric encryption and hashing).  Also during this presentation is a discussion of applying these cryptographic technologies using SSL as a case study.&lt;br /&gt;
&lt;br /&gt;
'''Speaker Bio:'''&lt;br /&gt;
&lt;br /&gt;
Scott Headington is a security consultant at McAfee's Foundstone. At Foundstone Scott focuses on providing web application penetration testing, code review, threat modeling and teaches several classes.  Scott has many years experience working with application security, prior to joining Foundstone Scott was a software engineer for over 14 years. &lt;br /&gt;
&lt;br /&gt;
'''RSVP:'''&lt;br /&gt;
&lt;br /&gt;
Please sign up at http://www.eventbrite.com/event/2224082290&lt;br /&gt;
&lt;br /&gt;
== Future meetings ==&lt;br /&gt;
We always want ideas!  Send your request for a meeting topic to a chapter leader or the [http://lists.owasp.org/mailman/listinfo/owasp-sacramento chapter mailing list].  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2011-04-28: Michael Weber, Aspect Security, Cross-Site Request Forgery: Attack and Defense&lt;br /&gt;
&lt;br /&gt;
2011-03-24: HTML 5:  Scott Headington, Foundstone, Presented on &amp;quot;New and exciting… for attackers too&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-09-30: Roman Hustad conducted a &amp;quot;Threat Modeling Workshop&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-06-24: [mailto:michael.weber35@gmail.com Michael Weber] conducted a &amp;quot;SQL Injection Lab&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-05-27: Erik Peterson of [http://www.veracode.com Veracode] presented &amp;quot;Automated Web Application Testing - Why we're Doing It Wrong&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=117779</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=117779"/>
				<updated>2011-09-21T19:24:15Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:michael.weber35@gmail.com Michael Weber] &amp;amp; [mailto:sheadington@gmail.com Scott Headington].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Next meeting September 29th, 2011: Basic Cryptography, Scott Headington, Foundstone Security Consultant ==&lt;br /&gt;
&lt;br /&gt;
In this presentation you will learn the basic principles of cryptography and how use of different cryptographic technologies (symmetric, asymmetric encryption and hashing).  Also during this presentation is a discussion of applying these cryptographic technologies using SSL as a case study.&lt;br /&gt;
&lt;br /&gt;
'''Speaker Bio:'''&lt;br /&gt;
&lt;br /&gt;
Scott Headington is a security consultant at McAfee's Foundstone. At Foundstone Scott focuses on providing web application penetration testing, code review, threat modeling and teaches several classes.  Scott has many years experience working with application security, prior to joining Foundstone Scott was a software engineer for over 14 years. &lt;br /&gt;
&lt;br /&gt;
'''RSVP:'''&lt;br /&gt;
&lt;br /&gt;
Please sign up at http://www.eventbrite.com/event/2224082290&lt;br /&gt;
&lt;br /&gt;
== Future meetings ==&lt;br /&gt;
We always want ideas!  Send your request for a meeting topic to a chapter leader or the [http://lists.owasp.org/mailman/listinfo/owasp-sacramento chapter mailing list].  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2011-04-28: Michael Weber, Aspect Security, Cross-Site Request Forgery: Attack and Defense&lt;br /&gt;
&lt;br /&gt;
2011-03-24: HTML 5:  Scott Headington, Foundstone, Presented on &amp;quot;New and exciting… for attackers too&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-09-30: Roman Hustad conducted a &amp;quot;Threat Modeling Workshop&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-06-24: [mailto:michael.weber35@gmail.com Michael Weber] conducted a &amp;quot;SQL Injection Lab&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-05-27: Erik Peterson of [http://www.veracode.com Veracode] presented &amp;quot;Automated Web Application Testing - Why we're Doing It Wrong&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=117767</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=117767"/>
				<updated>2011-09-21T18:45:51Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:michael.weber35@gmail.com Michael Weber] &amp;amp; [mailto:sheadington@gmail.com Scott Headington].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Next meeting September 29th, 2011: Basic Cryptography, Scott Headington, Foundstone Security Consultant ==&lt;br /&gt;
&lt;br /&gt;
In this presentation you will learn the basic principles of cryptography and how use of different cryptographic technologies (symmetric, asymmetric encryption and hashing).  Also during this presentation is a discussion of applying these cryptographic technologies using SSL as a case study.&lt;br /&gt;
&lt;br /&gt;
'''Speaker Bio:'''&lt;br /&gt;
&lt;br /&gt;
Scott Headington is a security consultant at McAfee's Foundstone. At Foundstone Scott focuses on providing web application penetration testing, code review, threat modeling and teaches several classes.  Scott has many years experience working with application security, prior to joining Foundstone Scott was a software engineer for over 14 years. &lt;br /&gt;
&lt;br /&gt;
'''RSVP:'''&lt;br /&gt;
&lt;br /&gt;
Please sign up at http://www.eventbrite.com/event/2224082290&lt;br /&gt;
&lt;br /&gt;
== Future meetings ==&lt;br /&gt;
We always want ideas!  Send your request for a meeting topic to a chapter leader or the [http://lists.owasp.org/mailman/listinfo/owasp-sacramento chapter mailing list].  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2011-04-28: HTML 5: Michael Weber, Aspect Security, Cross-Site Request Forgery: Attack and Defense&lt;br /&gt;
&lt;br /&gt;
2011-03-24: HTML 5:  Scott Headington, Foundstone, Presented on &amp;quot;New and exciting… for attackers too&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-09-30: Roman Hustad conducted a &amp;quot;Threat Modeling Workshop&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-06-24: [mailto:michael.weber35@gmail.com Michael Weber] conducted a &amp;quot;SQL Injection Lab&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-05-27: Erik Peterson of [http://www.veracode.com Veracode] presented &amp;quot;Automated Web Application Testing - Why we're Doing It Wrong&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=109529</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=109529"/>
				<updated>2011-04-26T23:51:00Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:michael.weber35@gmail.com Michael Weber] &amp;amp; [mailto:sheadington@gmail.com Scott Headington].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Next meeting April 28th, 2011: Cross-Site Request Forgery:  Attack and Defense, Michael Weber, Aspect Security ==&lt;br /&gt;
&lt;br /&gt;
Cross-Site Request Forgery is a deceptively simple attack that has been slowly climbing up the OWASP Top 10 the last few years.  During this presentation we will learn how a CSRF attack works, why it is so dangerous and how to prevent CSRF attacks.  We will also examine tools for testing for CSRF attacks as well as the OWASP CSRF Guard project. &lt;br /&gt;
&lt;br /&gt;
'''Speaker Bio:'''&lt;br /&gt;
&lt;br /&gt;
Michael Weber is an Application Security Engineer of Aspect Security, a consulting services company specializing in application security, with a focus in web application security and software development.  Drawing upon extensive web application development expertise, Mike provides expert guidance to clients in the financial, medical and retail sectors.  Michael has performed many security architecture reviews, application code reviews and penetration testing of mission critical applications.  &lt;br /&gt;
&lt;br /&gt;
'''RSVP:'''&lt;br /&gt;
&lt;br /&gt;
Please sign up at http://www.eventbrite.com/event/1595487145&lt;br /&gt;
&lt;br /&gt;
== Future meetings ==&lt;br /&gt;
We always want ideas!  Send your request for a meeting topic to a chapter leader or the [http://lists.owasp.org/mailman/listinfo/owasp-sacramento chapter mailing list].  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2011-03-24: HTML 5:  Scott Headington, Foundstone, Presented on &amp;quot;New and exciting… for attackers too&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-09-30: Roman Hustad conducted a &amp;quot;Threat Modeling Workshop&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-06-24: [mailto:michael.weber35@gmail.com Michael Weber] conducted a &amp;quot;SQL Injection Lab&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-05-27: Erik Peterson of [http://www.veracode.com Veracode] presented &amp;quot;Automated Web Application Testing - Why we're Doing It Wrong&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=106633</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=106633"/>
				<updated>2011-03-10T23:27:04Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:michael.weber35@gmail.com Michael Weber] &amp;amp; [mailto:sheadington@gmail.com Scott Headington].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Next meeting March 24th, 2011: HTML 5:  New and exciting… for attackers too, Scott Headington, Foundstone ==&lt;br /&gt;
&lt;br /&gt;
HTML 5 is the next revision of the HTML specification.  It promises to integrate audio and video without the need for additional plug-ins, a new and improved tag library and the ability for web applications to work offline by using client side storage.  All these exciting new features that have developers ready to move but, HTML 5 also brings along a series of new security concerns at a time when security flaws in web applications are at an all time high.  This presentation will cover a brief discussion of the new features of HTML 5 and an overview of the security risks associated with them.&lt;br /&gt;
&lt;br /&gt;
'''Speaker Bio:'''&lt;br /&gt;
&lt;br /&gt;
Scott is a Security Consultant at Foundstone, working out of the Sacramento, CA area.  He specializes in performing web application penetration testing, threat modeling and code reviews.  Scott also provides client education services for Foundstone class lead and instructor of Writing Secure Code: Java and Building Secure Code courses.  He is also an instructor for the Ultimate Hacking: Web course. &lt;br /&gt;
&lt;br /&gt;
Prior to joining Foundstone, Scott worked as a software engineer with over 14 years experience with several years experience on security projects.  In his years as a software engineer he has filled the roles of architect and lead developer and has worked for companies ranging from Fortune 500 companies to small successful start-ups.  His core development competencies are in Java and related technologies for creation of web and server side applications and is also proficient with .NET technologies.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Future meetings ==&lt;br /&gt;
We always want ideas!  Send your request for a meeting topic to a chapter leader or the [http://lists.owasp.org/mailman/listinfo/owasp-sacramento chapter mailing list].  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2010-09-30: Roman Hustad conducted a &amp;quot;Threat Modeling Workshop&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-06-24: [mailto:michael.weber35@gmail.com Michael Weber] conducted a &amp;quot;SQL Injection Lab&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-05-27: Erik Peterson of [http://www.veracode.com Veracode] presented &amp;quot;Automated Web Application Testing - Why we're Doing It Wrong&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=104780</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=104780"/>
				<updated>2011-02-10T02:12:45Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:michael.weber35@gmail.com Michael Weber] &amp;amp; [mailto:sheadington@gmail.com Scott Headington].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Next meeting: TBD ==&lt;br /&gt;
&lt;br /&gt;
We are currently recruiting a speaker for our January/February meeting.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Future meetings ==&lt;br /&gt;
We always want ideas!  Send your request for a meeting topic to a chapter leader or the [http://lists.owasp.org/mailman/listinfo/owasp-sacramento chapter mailing list].  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2010-09-30: Roman Hustad conducted a &amp;quot;Threat Modeling Workshop&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-06-24: [mailto:michael.weber35@gmail.com Michael Weber] conducted a &amp;quot;SQL Injection Lab&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-05-27: Erik Peterson of [http://www.veracode.com Veracode] presented &amp;quot;Automated Web Application Testing - Why we're Doing It Wrong&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Enterprise_Security_API_.NET_Version&amp;diff=95438</id>
		<title>GPC Project Details/OWASP Enterprise Security API .NET Version</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Enterprise_Security_API_.NET_Version&amp;diff=95438"/>
				<updated>2010-12-04T19:38:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Project Identification Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP ESAPI for .NET&lt;br /&gt;
| project_description = This is the .NET language version of OWASP ESAPI. &lt;br /&gt;
* [http://ankhsvn.open.collab.net/ AnkhSVN] is a free SVN tool that integrates with Visual Studio. Point your SVN tool at http://owasp-esapi-dotnet.googlecode.com/svn/trunk. Anonymous checkout is supported. You can also [http://code.google.com/p/owasp-esapi-dotnet/source/browse browse the source].  &lt;br /&gt;
| project_license = [http://en.wikipedia.org/wiki/BSD_license BSD license]&lt;br /&gt;
| leader_name = Alex Smolen &lt;br /&gt;
| leader_email = me@alexsmolen.com&lt;br /&gt;
| leader_username = &lt;br /&gt;
| past_leaders_special_contributions = &lt;br /&gt;
| maintainer_name = Michael Weber&lt;br /&gt;
| maintainer_email = michael.weber35@gmail.com&lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = Paul Apostolescu&lt;br /&gt;
| contributor_email1 = apbogdan@gmail.com&lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link = &lt;br /&gt;
| mailing_list_name = esapi-dev-dotnet&lt;br /&gt;
| links_url1 = http://code.google.com/p/owasp-esapi-dotnet/&lt;br /&gt;
| links_name1 = ESAPI for .NET Google Code repository&lt;br /&gt;
| links_url2 = http://owasp-esapi-dotnet.googlecode.com/files/Esapi.zip&lt;br /&gt;
| links_name2 = Download the latest .NET ESAPI library binary from Google Code here. &lt;br /&gt;
| links_url3 = http://owasp-esapi-dotnet.googlecode.com/files/Esapi_Documentation.zip&lt;br /&gt;
| links_name3 = Download the latest .NET ESAPI documentation from Google Code here. It is a zipped .chm (help) file. &lt;br /&gt;
| links_url4 = http://alexsmolen.com/dotnetesapidoc/index.html&lt;br /&gt;
| links_name4 = You can also browse the .NET ESAPI documentation here&lt;br /&gt;
| links_url5 = http://www.owasp.org/index.php/ESAPI_DotNET_Readme&lt;br /&gt;
| links_name5 = ESAPI .NET readme and release notes&lt;br /&gt;
| links_url6 = http://keepitlocked.net/archive/2009/07/29/owasp-net-esapi-0-2-released.aspx&lt;br /&gt;
| links_name6 = ESAPI for .NET design notes (Blog) &lt;br /&gt;
| links_url7 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Downloads&lt;br /&gt;
| links_name7 = General ESAPI information&lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = &lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username =&lt;br /&gt;
| current_release_details =  &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
| last_GPC_update = 4/10/2009&lt;br /&gt;
| GPC_Notes = Empty template (.NET_Version)&lt;br /&gt;
| project_home_page = :Category:OWASP_Enterprise_Security_API&lt;br /&gt;
| project_details_wiki_page = GPC_Project_Details/OWASP_Enterprise_Security_API_.NET_Version&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=92795</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=92795"/>
				<updated>2010-11-12T00:58:02Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leader is [mailto:michael.weber35@gmail.com Michael Weber].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Next meeting: TBD ==&lt;br /&gt;
&lt;br /&gt;
We are currently recruiting a speaker for our January/February meeting.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Future meetings ==&lt;br /&gt;
We always want ideas!  Send your request for a meeting topic to a chapter leader or the [http://lists.owasp.org/mailman/listinfo/owasp-sacramento chapter mailing list].  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2010-09-30: Roman Hustad conducted a &amp;quot;Threat Modeling Workshop&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-06-24: [mailto:michael.weber35@gmail.com Michael Weber] conducted a &amp;quot;SQL Injection Lab&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-05-27: Erik Peterson of [http://www.veracode.com Veracode] presented &amp;quot;Automated Web Application Testing - Why we're Doing It Wrong&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=83538</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=83538"/>
				<updated>2010-05-14T19:26:35Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: /* MEETING: May 27, 2010, 6-8 pm: Automated Web Application Testing - Why we're Doing It Wrong */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:roman.hustad@yahoo.com Roman Hustad], [mailto:mpetteys@caiso.com Matt Petteys], and [mailto:michael.weber35@gmail.com Michael Weber].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
== MEETING: May 27, 2010, 6-8 pm: Automated Web Application Testing - Why we're Doing It Wrong ==&lt;br /&gt;
&lt;br /&gt;
'''TOPIC:  Automated Web Application Testing - Why we're Doing It Wrong'''. &lt;br /&gt;
&lt;br /&gt;
AUDIENCE PRE-REQUISITIES:&lt;br /&gt;
&lt;br /&gt;
A general understanding of web application technology as well as a general understanding of web application security testing tools and methods will be useful but not absolutely required. Even those new to web application testing, managers and executives concerned about web security will find this talk useful.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Attendees to this session will walk away with a good understanding of the following: &lt;br /&gt;
&lt;br /&gt;
1. A brief understanding of the history of automated dynamic or black box testing for web applications&lt;br /&gt;
&lt;br /&gt;
2. How modern web application technology is impacting the security teams ability to test for security defects and ensure the business is effectively managing application risk&lt;br /&gt;
&lt;br /&gt;
3. The way many organizations are using web application testing tools today and how these approaches can lead to a false sense of security&lt;br /&gt;
&lt;br /&gt;
4. How changing how we think about web applications and combining new testing techniques can deliver more accurate results and better test coverage&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ABSTRACT:&lt;br /&gt;
&lt;br /&gt;
It's been over 10 years since the first automated web scanning products were introduced so why are so many of the dynamic or black box testing tools still challenging to use and often ineffective? With the average organization having dozens or in some cases hundreds of web applications, testing them all manually is an expensive and time consuming task.  As a result organizations have turned to automated solutions to assess their online risks, but are automated dynamic scanning solutions really effective or are they only offering us a false sense of security? &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This talk covers the history of web application scanning, how web applications and therefore the methods of assessing web application risk have and must change and how cloud computing is enabling new approaches to managing and assessing risk that bring scalability and cost inline with business expectations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
SPEAKER BIO:&lt;br /&gt;
&lt;br /&gt;
Erik Peterson is a Senior Solutions Architect for Veracode and an application and information security veteran with over 15 years of industry experience. Prior to Veracode, Erik Peterson was with Hewlett-Packard where he was Senior Director of Products for the HP Application Security Center, previously known as S.P.I. Dynamics which was acquired by HP in 2007. Erik was a member of the S.P.I. Dynamics executive team and led the product management team which defined the company's product and technology strategy.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''RSVP &amp;amp; LOCATION:''' &lt;br /&gt;
&lt;br /&gt;
Please [http://www.eventbrite.com/event/694041898 RSVP] for this event. Upon arriving at the main entrance, please ask for Robert Grill, office: 916-636-4392, cell: 916-997-9892. Any problems, please contact Roman Hustad, 916-402-0620&lt;br /&gt;
*: HP Medi-Cal [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=%3D3215+Prospect+Park+Drive,Rancho+Cordova,+CA+95670&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=51.443116,107.753906&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=38.58885,-121.275437&amp;amp;spn=0.01117,0.019956&amp;amp;t=k&amp;amp;z=16&amp;amp;iwloc=addr (map)]   &lt;br /&gt;
*: 3215 Prospect Park Drive   &lt;br /&gt;
*: Rancho Cordova , CA   &lt;br /&gt;
*: 95670&lt;br /&gt;
&lt;br /&gt;
== FUTURE Meetings ==&lt;br /&gt;
2010-06-24: Michael Weber be presenting &amp;quot;SQL Injection Lab - Attacks &amp;amp; Defense&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=83537</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=83537"/>
				<updated>2010-05-14T19:21:05Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: /* MEETING: April 29, 2010, 6-8 pm: The Secure Software Development Lifecycle */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:roman.hustad@yahoo.com Roman Hustad], [mailto:mpetteys@caiso.com Matt Petteys], and [mailto:michael.weber35@gmail.com Michael Weber].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
== MEETING: May 27, 2010, 6-8 pm: Automated Web Application Testing - Why we're Doing It Wrong ==&lt;br /&gt;
&lt;br /&gt;
'''TOPIC:  Automated Web Application Testing - Why we're Doing It Wrong'''. &lt;br /&gt;
&lt;br /&gt;
AUDIENCE PRE-REQUISITIES:&lt;br /&gt;
&lt;br /&gt;
A general understanding of web application technology as well as a general understanding of web application security testing tools and methods will be useful but not absolutely required. Even those new to web application testing, managers and executives concerned about web security will find this talk useful.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Attendees to this session will walk away with a good understanding of the following: &lt;br /&gt;
&lt;br /&gt;
   1. A brief understanding of the history of automated dynamic or black box testing for web applications&lt;br /&gt;
   2. How modern web application technology is impacting the security teams ability to test for security defects and ensure the business is effectively managing application risk&lt;br /&gt;
   3. The way many organizations are using web application testing tools today and how these approaches can lead to a false sense of security&lt;br /&gt;
   4. How changing how we think about web applications and combining new testing techniques can deliver more accurate results and better test coverage&lt;br /&gt;
&lt;br /&gt;
ABSTRACT:&lt;br /&gt;
&lt;br /&gt;
It's been over 10 years since the first automated web scanning products were introduced so why are so many of the dynamic or black box testing tools still challenging to use and often ineffective? With the average organization having dozens or in some cases hundreds of web applications, testing them all manually is an expensive and time consuming task.  As a result organizations have turned to automated solutions to assess their online risks, but are automated dynamic scanning solutions really effective or are they only offering us a false sense of security? &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This talk covers the history of web application scanning, how web applications and therefore the methods of assessing web application risk have and must change and how cloud computing is enabling new approaches to managing and assessing risk that bring scalability and cost inline with business expectations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
SPEAKER BIO:&lt;br /&gt;
&lt;br /&gt;
Erik Peterson is a Senior Solutions Architect for Veracode and an application and information security veteran with over 15 years of industry experience. Prior to Veracode, Erik Peterson was with Hewlett-Packard where he was Senior Director of Products for the HP Application Security Center, previously known as S.P.I. Dynamics which was acquired by HP in 2007. Erik was a member of the S.P.I. Dynamics executive team and led the product management team which defined the company's product and technology strategy.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''RSVP &amp;amp; LOCATION:''' &lt;br /&gt;
&lt;br /&gt;
Please [http://www.eventbrite.com/event/694041898 RSVP] for this event. Upon arriving at the main entrance, please ask for Robert Grill, office: 916-636-4392, cell: 916-997-9892. Any problems, please contact Roman Hustad, 916-402-0620&lt;br /&gt;
*: HP Medi-Cal [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=%3D3215+Prospect+Park+Drive,Rancho+Cordova,+CA+95670&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=51.443116,107.753906&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=38.58885,-121.275437&amp;amp;spn=0.01117,0.019956&amp;amp;t=k&amp;amp;z=16&amp;amp;iwloc=addr (map)]   &lt;br /&gt;
*: 3215 Prospect Park Drive   &lt;br /&gt;
*: Rancho Cordova , CA   &lt;br /&gt;
*: 95670&lt;br /&gt;
&lt;br /&gt;
== FUTURE Meetings ==&lt;br /&gt;
2010-06-24: Michael Weber be presenting &amp;quot;SQL Injection Lab - Attacks &amp;amp; Defense&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=83534</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=83534"/>
				<updated>2010-05-14T18:54:47Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: /* FUTURE Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:roman.hustad@yahoo.com Roman Hustad], [mailto:mpetteys@caiso.com Matt Petteys], and [mailto:michael.weber35@gmail.com Michael Weber].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
== MEETING: April 29, 2010, 6-8 pm: The Secure Software Development Lifecycle ==&lt;br /&gt;
&lt;br /&gt;
'''TOPIC:  The Secure Software Development Lifecycle'''. &lt;br /&gt;
Come to this meeting if you want to learn (and discuss) how to bake security into your applications as they are created.  We will examine the current maturity models and methodologies (CLASP, SDL, 7 Touchpoints, OpenSAMM, BSI-MM) and talk about how these work out in the real world.  The focus will be on high-value, low drag activities that are practical for most development teams.  Peripheral issues will also be considered, such as how to get management on board; how traditional information security professionals can work with development teams; dealing with legacy applications; and how to separate the real threats from the security busywork.  &lt;br /&gt;
&lt;br /&gt;
SPEAKER BIO&lt;br /&gt;
Roman Hustad has been an enterprise software developer in Sacramento for most of the past ten years. Most recently he was a Principal Consultant at Foundstone where he specialized in application security by performing code reviews, threat models, and teaching secure programming. Roman is a regular presenter at local chapters of OWASP, ISSA, ISACA, and Java User Groups. He is currently a local Java development lead in the financial services industry. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''RSVP &amp;amp; LOCATION:''' &lt;br /&gt;
&lt;br /&gt;
Please [http://owaspsacramento.eventbrite.com/ RSVP] for this event. Upon arriving at the main entrance, please ask for Robert Grill, office: 916-636-4392, cell: 916-997-9892. Any problems, please contact Roman Hustad, 916-402-0620&lt;br /&gt;
*: HP Medi-Cal [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=%3D3215+Prospect+Park+Drive,Rancho+Cordova,+CA+95670&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=51.443116,107.753906&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=38.58885,-121.275437&amp;amp;spn=0.01117,0.019956&amp;amp;t=k&amp;amp;z=16&amp;amp;iwloc=addr (map)]   &lt;br /&gt;
*: 3215 Prospect Park Drive   &lt;br /&gt;
*: Rancho Cordova , CA   &lt;br /&gt;
*: 95670&lt;br /&gt;
&lt;br /&gt;
== FUTURE Meetings ==&lt;br /&gt;
2010-06-24: Michael Weber be presenting &amp;quot;SQL Injection Lab - Attacks &amp;amp; Defense&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=83533</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=83533"/>
				<updated>2010-05-14T18:54:21Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: /* FUTURE Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:roman.hustad@yahoo.com Roman Hustad], [mailto:mpetteys@caiso.com Matt Petteys], and [mailto:michael.weber35@gmail.com Michael Weber].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
== MEETING: April 29, 2010, 6-8 pm: The Secure Software Development Lifecycle ==&lt;br /&gt;
&lt;br /&gt;
'''TOPIC:  The Secure Software Development Lifecycle'''. &lt;br /&gt;
Come to this meeting if you want to learn (and discuss) how to bake security into your applications as they are created.  We will examine the current maturity models and methodologies (CLASP, SDL, 7 Touchpoints, OpenSAMM, BSI-MM) and talk about how these work out in the real world.  The focus will be on high-value, low drag activities that are practical for most development teams.  Peripheral issues will also be considered, such as how to get management on board; how traditional information security professionals can work with development teams; dealing with legacy applications; and how to separate the real threats from the security busywork.  &lt;br /&gt;
&lt;br /&gt;
SPEAKER BIO&lt;br /&gt;
Roman Hustad has been an enterprise software developer in Sacramento for most of the past ten years. Most recently he was a Principal Consultant at Foundstone where he specialized in application security by performing code reviews, threat models, and teaching secure programming. Roman is a regular presenter at local chapters of OWASP, ISSA, ISACA, and Java User Groups. He is currently a local Java development lead in the financial services industry. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''RSVP &amp;amp; LOCATION:''' &lt;br /&gt;
&lt;br /&gt;
Please [http://owaspsacramento.eventbrite.com/ RSVP] for this event. Upon arriving at the main entrance, please ask for Robert Grill, office: 916-636-4392, cell: 916-997-9892. Any problems, please contact Roman Hustad, 916-402-0620&lt;br /&gt;
*: HP Medi-Cal [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=%3D3215+Prospect+Park+Drive,Rancho+Cordova,+CA+95670&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=51.443116,107.753906&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=38.58885,-121.275437&amp;amp;spn=0.01117,0.019956&amp;amp;t=k&amp;amp;z=16&amp;amp;iwloc=addr (map)]   &lt;br /&gt;
*: 3215 Prospect Park Drive   &lt;br /&gt;
*: Rancho Cordova , CA   &lt;br /&gt;
*: 95670&lt;br /&gt;
&lt;br /&gt;
== FUTURE Meetings ==&lt;br /&gt;
2010-06-24: Michael Weber be presenting/teaching &amp;quot;SQL Injection Lab - Attacks &amp;amp; Defense&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=83532</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=83532"/>
				<updated>2010-05-14T18:51:41Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: /* Past Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:roman.hustad@yahoo.com Roman Hustad], [mailto:mpetteys@caiso.com Matt Petteys], and [mailto:michael.weber35@gmail.com Michael Weber].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
== MEETING: April 29, 2010, 6-8 pm: The Secure Software Development Lifecycle ==&lt;br /&gt;
&lt;br /&gt;
'''TOPIC:  The Secure Software Development Lifecycle'''. &lt;br /&gt;
Come to this meeting if you want to learn (and discuss) how to bake security into your applications as they are created.  We will examine the current maturity models and methodologies (CLASP, SDL, 7 Touchpoints, OpenSAMM, BSI-MM) and talk about how these work out in the real world.  The focus will be on high-value, low drag activities that are practical for most development teams.  Peripheral issues will also be considered, such as how to get management on board; how traditional information security professionals can work with development teams; dealing with legacy applications; and how to separate the real threats from the security busywork.  &lt;br /&gt;
&lt;br /&gt;
SPEAKER BIO&lt;br /&gt;
Roman Hustad has been an enterprise software developer in Sacramento for most of the past ten years. Most recently he was a Principal Consultant at Foundstone where he specialized in application security by performing code reviews, threat models, and teaching secure programming. Roman is a regular presenter at local chapters of OWASP, ISSA, ISACA, and Java User Groups. He is currently a local Java development lead in the financial services industry. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''RSVP &amp;amp; LOCATION:''' &lt;br /&gt;
&lt;br /&gt;
Please [http://owaspsacramento.eventbrite.com/ RSVP] for this event. Upon arriving at the main entrance, please ask for Robert Grill, office: 916-636-4392, cell: 916-997-9892. Any problems, please contact Roman Hustad, 916-402-0620&lt;br /&gt;
*: HP Medi-Cal [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=%3D3215+Prospect+Park+Drive,Rancho+Cordova,+CA+95670&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=51.443116,107.753906&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=38.58885,-121.275437&amp;amp;spn=0.01117,0.019956&amp;amp;t=k&amp;amp;z=16&amp;amp;iwloc=addr (map)]   &lt;br /&gt;
*: 3215 Prospect Park Drive   &lt;br /&gt;
*: Rancho Cordova , CA   &lt;br /&gt;
*: 95670&lt;br /&gt;
&lt;br /&gt;
== FUTURE Meetings ==&lt;br /&gt;
2010-05-27: [http://www.veracode.com Veracode] will be talking about &amp;quot;Automated Web Application Scanning&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2010-04-29: Roman Hustad presented &amp;quot;The Secure Software Development Lifecycle&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-03-25: Mike Fauzy of [http://www.aspectsecurity.com Aspect Security] presented &amp;quot;Tool Assisted Manual Code Review - Manual Precision with Automated Performance&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2010-02-25: Arshad Noor of [http://www.strongauth.com/ StrongAuth, Inc.] presented &amp;quot;Key Management &amp;amp; Encryption&amp;quot;  [http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf Download presentation]&lt;br /&gt;
&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=79129</id>
		<title>Sacramento</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sacramento&amp;diff=79129"/>
				<updated>2010-03-03T18:00:07Z</updated>
		
		<summary type="html">&lt;p&gt;Mike: /* MEETING: February 25, 2010, 6-8 pm: Key Management &amp;amp; Encryption */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sacramento|extra=The chapter leaders are [mailto:roman.hustad@yahoo.com Roman Hustad], [mailto:mpetteys@caiso.com Matt Petteys], and [mailto:michael.weber35@gmail.com Michael Weber].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sacramento|emailarchives=http://lists.owasp.org/pipermail/owasp-sacramento}}&lt;br /&gt;
&lt;br /&gt;
== Charter ==&lt;br /&gt;
The Sacramento OWASP Chapter promotes the [[About_The_Open_Web_Application_Security_Project|principles of OWASP]] in our local community with an emphasis on education, local networking opportunities, and fun.  Meetings are typically on the last Thursday evening of the month. &lt;br /&gt;
&lt;br /&gt;
== MEETING: February 25, 2010, 6-8 pm: Key Management &amp;amp; Encryption ==&lt;br /&gt;
&lt;br /&gt;
Refreshments will be provided by the speaker.&lt;br /&gt;
&lt;br /&gt;
'''TOPIC:  Key Management &amp;amp; Encryption'''. The presentation will explore the technical details of this discipline to explain some basics, pitfalls, best practices and the current state-of-the-art of encryption and key-management.  Using this information, attendees will be able to make more informed choices when using cryptography to protect sensitive data.&lt;br /&gt;
&lt;br /&gt;
* Encryption and Key Management techniques&lt;br /&gt;
* Tokenization vs. Encryption - pros and cons&lt;br /&gt;
* What are software developers doing wrong today&lt;br /&gt;
* Why sites like Heartland get hacked despite being PCI-certified&lt;br /&gt;
* What are the best practices for encryption and Key Management&lt;br /&gt;
* How do software developers get from here to the best practices&lt;br /&gt;
* Key Management standards confusion and how to navigate it&lt;br /&gt;
** http://xml.coverpages.org/keyManagement.html&lt;br /&gt;
&lt;br /&gt;
'''SPEAKER:  Arshad Noor''', is the CTO of StrongAuth, Inc, a Cupertino CA-based company that specializes in enterprise key management.  He is the designer and lead-developer of StrongKey, the industry's first open-source Symmetric Key Management System, and the StrongKey Lite Encryption System - the industry's first appliance combining encryption, tokenization, key-management and a cryptographic hardware module.  He has written many papers and spoken at many forums on the subject of encryption and key-management over the years.&lt;br /&gt;
&lt;br /&gt;
'''RSVP &amp;amp; LOCATION:''' &lt;br /&gt;
&lt;br /&gt;
Please [http://fs17.formsite.com/rhustad/form306287621/ RSVP] for this event. Upon arriving at the main entrance, please ask for Robert Grill, office: 916-636-4392, cell: 916-997-9892. Any problems, please contact Roman Hustad, 916-402-0620&lt;br /&gt;
*: EDS Medi-Cal [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=%3D3215+Prospect+Park+Drive,Rancho+Cordova,+CA+95670&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=51.443116,107.753906&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=38.58885,-121.275437&amp;amp;spn=0.01117,0.019956&amp;amp;t=k&amp;amp;z=16&amp;amp;iwloc=addr (map)]   &lt;br /&gt;
*: 3215 Prospect Park Drive   &lt;br /&gt;
*: Rancho Cordova , CA   &lt;br /&gt;
*: 95670&lt;br /&gt;
&lt;br /&gt;
'''Presentation Download:'''&lt;br /&gt;
http://www.mediafire.com/file/jz5dyu1wiyk/EKM-1.0.pdf&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
2009-12-09: Alex Smolen presented &amp;quot;The OWASP .NET ESAPI&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-10-08: Ned Allison chaired a roundtable on &amp;quot;Database Security&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-07-30: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on Cross-Site Scripting&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2009-05-12: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;Hands-on SQL Injection&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-10-30: Joy Forsythe from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Voting Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-07-31: [mailto:roman.hustad@yahoo.com Roman Hustad] presented &amp;quot;How to Test the Security of Web Applications.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-06-26: Shan Zhou from [http://www.imperva.com/ Imperva] presented &amp;quot;Database Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
2008-04-03: Ryan C. Barnett from [http://www.breach.com/ Breach Security] presented &amp;quot;Passive Web Application Defect Identification.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
2007-11-29: [mailto:roman.hustad@yahoo.com Roman Hustad] from [http://www.foundstone.com Foundstone] presented &amp;quot;Web Application Hacking&amp;quot; to over 40 attendees.&lt;br /&gt;
&lt;br /&gt;
2007-08-30: Barmak Meftah from [http://www.fortifysoftware.com Fortify Software] presented &amp;quot;Hack proof your Service-Oriented Architecture&amp;quot; to 15 attendees.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>Mike</name></author>	</entry>

	</feed>