<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mmeucci</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mmeucci"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Mmeucci"/>
		<updated>2026-05-02T18:46:17Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256584</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256584"/>
				<updated>2020-01-08T09:05:32Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modeling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Presentations =&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Morana2020.jpg|Marco Morana: [https://drive.google.com/open?id=1Ak8lne8_Fzw9NozjS0GKF2WIhMU5pBhm &amp;quot;Introduction to Threat Modeling and the Process for Attack Simulation and Threat Analysis&amp;quot;]&lt;br /&gt;
Calligaris2020.jpg|David Calligaris: [https://drive.google.com/open?id=1-s81HxzTSjTh8IPZvyexMsfEFH2LCy1C &amp;quot;SSRF present and future&amp;quot;]&lt;br /&gt;
Calzavara2020.jpg|Stefano Calzavara: [https://drive.google.com/open?id=1-skFH-BeyMiMOF-7ZxR1LJ3nDL5CFVIH &amp;quot;Testing for integrity flaws in web sessions&amp;quot;]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Agenda =&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256579</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256579"/>
				<updated>2020-01-07T18:08:10Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modeling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Presentations =&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Morana2020.jpg|Marco Morana: [https://drive.google.com/open?id=1aqxMwHjjCQgHPsUWdCQ9omiT45QjJlDR &amp;quot;Introduction to Threat Modeling and the Process for Attack Simulation and Threat Analysis&amp;quot;]&lt;br /&gt;
Calligaris2020.jpg|David Calligaris: [https://drive.google.com/open?id=1-s81HxzTSjTh8IPZvyexMsfEFH2LCy1C &amp;quot;SSRF present and future&amp;quot;]&lt;br /&gt;
Calzavara2020.jpg|Stefano Calzavara: [https://drive.google.com/open?id=1-skFH-BeyMiMOF-7ZxR1LJ3nDL5CFVIH &amp;quot;Testing for integrity flaws in web sessions&amp;quot;]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Agenda =&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256578</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256578"/>
				<updated>2020-01-07T18:07:42Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modeling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Presentations =&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Morana2020.jpg|Marco Morana: [https://drive.google.com/open?id=1aqxMwHjjCQgHPsUWdCQ9omiT45QjJlDR &amp;quot;Introduction to Threat Modeling and the Process for Attack Simulation and Threat Analysis&amp;quot;]&lt;br /&gt;
Calligaris2020.jpg|David Calligaris: [https://drive.google.com/open?id=1-s81HxzTSjTh8IPZvyexMsfEFH2LCy1C &amp;quot;SSRF present and future&amp;quot;]&lt;br /&gt;
Calzavara2020.jpg|Stefano Calzavara: [https://drive.google.com/open?id=1-skFH-BeyMiMOF-7ZxR1LJ3nDL5CFVIH &amp;quot;Testing for integrity flaws in web sessions&amp;quot;]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Agenda =&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256577</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256577"/>
				<updated>2020-01-07T18:02:49Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modeling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Presentations =&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Morana2020.jpg|Marco Morana: [https://drive.google.com/open?id=17ZejrxgwR6kK_isy83324UyIJbywMRhT &amp;quot;Introduction to Threat Modeling and the Process for Attack Simulation and Threat Analysis&amp;quot;]&lt;br /&gt;
Calligaris2020.jpg|David Calligaris: [https://drive.google.com/open?id=1-s81HxzTSjTh8IPZvyexMsfEFH2LCy1C &amp;quot;SSRF present and future&amp;quot;]&lt;br /&gt;
Calzavara2020.jpg|Stefano Calzavara: [https://drive.google.com/open?id=1-skFH-BeyMiMOF-7ZxR1LJ3nDL5CFVIH &amp;quot;Testing for integrity flaws in web sessions&amp;quot;]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Agenda =&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256576</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256576"/>
				<updated>2020-01-07T18:02:15Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modeling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Presentations =&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Morana2020.jpg|Marco Morana: [https://drive.google.com/open?id=17ZejrxgwR6kK_isy83324UyIJbywMRhT &amp;quot;Introduction to Threat Modeling and the Process for Attack Simulation and Threat Analysis&amp;quot;]&lt;br /&gt;
Calligaris2020.jpg|David Calligaris: [https://drive.google.com/open?id=1-s81HxzTSjTh8IPZvyexMsfEFH2LCy1C &amp;quot;SSRF present and future&amp;quot;]&lt;br /&gt;
Calzavara2020.jpg|Stefano Calzavara: [https://drive.google.com/open?id=1-skFH-BeyMiMOF-7ZxR1LJ3nDL5CFVIH &amp;quot;Testing for integrity flaws in web sessions&amp;quot;]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Agenda =&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256575</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256575"/>
				<updated>2020-01-07T18:01:46Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modeling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Presentations =&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Morana2020.jpg|Marco Morana: [https://drive.google.com/open?id=17ZejrxgwR6kK_isy83324UyIJbywMRhT &amp;quot;Introduction to Threat Modeling and the Process for Attack Simulation and Threat Analysis&amp;quot;]&lt;br /&gt;
Calligaris2020.jpg|David Calligaris: [https://drive.google.com/open?id=1-s81HxzTSjTh8IPZvyexMsfEFH2LCy1C &amp;quot;SSRF present and future&amp;quot;]&lt;br /&gt;
Calzavara2020.jpg|Stefano Calzavara: [https://drive.google.com/open?id=1-skFH-BeyMiMOF-7ZxR1LJ3nDL5CFVIH &amp;quot;Testing for integrity flaws in web sessions&amp;quot;]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Agenda =&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256574</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256574"/>
				<updated>2020-01-07T18:00:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modeling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Agenda and presentations =&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Morana2020.jpg|Marco Morana: [https://drive.google.com/open?id=17ZejrxgwR6kK_isy83324UyIJbywMRhT &amp;quot;Introduction to Threat Modeling and the Process for Attack Simulation and Threat Analysis&amp;quot;]&lt;br /&gt;
Calligaris2020.jpg|David Calligaris: [https://drive.google.com/open?id=1-s81HxzTSjTh8IPZvyexMsfEFH2LCy1C &amp;quot;SSRF present and future&amp;quot;]&lt;br /&gt;
Calzavara2020.jpg|Stefano Calzavara: [https://drive.google.com/open?id=1-skFH-BeyMiMOF-7ZxR1LJ3nDL5CFVIH &amp;quot;Testing for integrity flaws in web sessions&amp;quot;]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256573</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256573"/>
				<updated>2020-01-07T17:58:29Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modeling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Agenda and presentations =&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Morana2020.jpg|Marco Morana: [https://drive.google.com/open?id=17ZejrxgwR6kK_isy83324UyIJbywMRhT &amp;quot;Introduction to Threat Modeling and the Process for Attack Simulation and Threat Analysis&amp;quot;]&lt;br /&gt;
Calligaris2020.jpg|David Calligaris: &amp;quot;SSRF present and future&amp;quot;&lt;br /&gt;
Calzavara2020.jpg|Stefano Calzavara: &amp;quot;Testing for integrity flaws in web sessions&amp;quot;&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256572</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256572"/>
				<updated>2020-01-07T17:57:06Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modeling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Agenda and presentations =&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Morana2020.jpg|Marco Morana: &amp;quot;Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&lt;br /&gt;
Calligaris2020.jpg|David Calligaris: &amp;quot;SSRF present and future&amp;quot;&lt;br /&gt;
Calzavara2020.jpg|Stefano Calzavara: &amp;quot;Testing for integrity flaws in web sessions&amp;quot;&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256571</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256571"/>
				<updated>2020-01-07T17:53:34Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modelling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Agenda and presentations =&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Morana2020.jpg|Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&lt;br /&gt;
Calligaris2020.jpg|Caption2&lt;br /&gt;
Calzavara2020.jpg|Caption3&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256570</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256570"/>
				<updated>2020-01-07T17:36:19Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modelling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Agenda and presentations =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
[[File:Morana2020.jpg|thumb|left]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
[[File:Calligaris2020.jpg|thumb|left]]&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
[[File:Calzavara2020.jpg|thumb|left]]&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Calzavara2020.jpg&amp;diff=256569</id>
		<title>File:Calzavara2020.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Calzavara2020.jpg&amp;diff=256569"/>
				<updated>2020-01-07T17:36:02Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Calligaris2020.jpg&amp;diff=256568</id>
		<title>File:Calligaris2020.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Calligaris2020.jpg&amp;diff=256568"/>
				<updated>2020-01-07T17:35:22Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Morana2020.jpg&amp;diff=256567</id>
		<title>File:Morana2020.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Morana2020.jpg&amp;diff=256567"/>
				<updated>2020-01-07T17:30:25Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256566</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256566"/>
				<updated>2020-01-07T17:29:59Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modelling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Agenda and presentations =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
[[File:Morana2020.jpg]]&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy&amp;diff=256565</id>
		<title>Italy</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy&amp;diff=256565"/>
				<updated>2020-01-07T15:01:23Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[Image:OWASP-Italy.PNG]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== WELCOME  ====&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Italy|extra=The chapter leader is [mailto:matteo.meucci@owasp.org Matteo Meucci]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-italy|emailarchives=http://lists.owasp.org/pipermail/owasp-italy}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Italy&amp;lt;/paypal&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''LAST EVENT: OWASP Day in Udine - 27th September 2019''' ==&lt;br /&gt;
&lt;br /&gt;
More information here:&lt;br /&gt;
&lt;br /&gt;
[[Italy OWASP Day Udine 2019|https://www.owasp.org/index.php/Italy_OWASP_Day_Udine_2019]]&lt;br /&gt;
&lt;br /&gt;
== '''OWASP/WIA initiatives - 26th March 2019''' ==&lt;br /&gt;
Thanks to Loredana Mancini and Zoe Braiterman we will have an OWASP-Italy /WIA initiatives at the Link Campus in Rome next 26th March.&amp;lt;br&amp;gt;&lt;br /&gt;
Venue: Link Campus University Via del Casale di San Pio V, 44 - 00165 Roma (RM)&lt;br /&gt;
&lt;br /&gt;
Speakers: Prof.ssa Paola Giannetakis (Link Campus University), Zoe Braiterman (OWASP/WIA Chair), Luciana Scognamiglio (Senior security expert /HPE), Matteo Meucci (OWASP-Italy Chair).&lt;br /&gt;
&lt;br /&gt;
http://it.expandi-web.com/aruba/2019/aruba_oswap/form.html&lt;br /&gt;
== '''OWASP-Italy@Security Summit 2019''' ==&lt;br /&gt;
Thanks to CLUSIT, Giuseppe Trotta and Lorenzo De Meo had a talk at the OWASP-Italy corner during the Security Summit in Milan &amp;lt;br&amp;gt;&lt;br /&gt;
When: 14th March 2019 at 16:10-16:50&amp;lt;br&amp;gt;&lt;br /&gt;
Where: UNAHOTELS EXPO FIERA, via Keplero 12, Pero &amp;lt;br&amp;gt;&lt;br /&gt;
Please see the presentations here:&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/a/aa/OWASPCloudTestingMar19.pdf Federico De Meo: &amp;quot;Cloud Security Testing&amp;quot;]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[https://drive.google.com/file/d/1AU2zQXcy2Lnc1jI9UxYnkw1rKrDwPcYW/view Giuseppe Trotta: &amp;quot;New generation of phishing attacks&amp;quot;]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''OWASP-Italy Cagliari Day 2018 - 19th October 2018''' ==&lt;br /&gt;
Università di Cagliari.&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day Cagliari 2018|Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
=='''OWASP-Italy Day 2018 @ Milano 16th June 2018''' ==&lt;br /&gt;
Politecnico of Milano&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2018 ==&lt;br /&gt;
OWASP Italy did participate to the Security Summit 2018 in Milan with 2 talks.&amp;lt;br&amp;gt;More information here: [https://www.securitysummit.it/agenda-details/333 https://www.securitysummit.it/agenda-details/93]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day 2017 @ Cagliari 20th October 2017 ==&lt;br /&gt;
Cagliari , 6th October 2017, Università di Cagliari&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2017]]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 6th October 2017 ==&lt;br /&gt;
'''V Conference on Application Security and Modern Technologies'''&lt;br /&gt;
&lt;br /&gt;
Mestre, 6th October 2017, Università Ca' Foscari&lt;br /&gt;
&lt;br /&gt;
http://www.isaca.org/chapters5/Venice/Pages/default.aspx&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2017 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2017 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
Antonio Parata will give a talk on EyePyramid malware and Fabrizio Bugli will talk about (3rd) Party like nobody's watching&lt;br /&gt;
&lt;br /&gt;
https://www.securitysummit.it/agenda-details/93&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP AppSec Europe 2016 in Rome! ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASPAppSecEU2016.jpg]]&lt;br /&gt;
&lt;br /&gt;
OWASP is organizing the next OWASP AppSecEU in Rome.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;See the agenda and buy your ticket here:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
http://2016.appsec.eu/&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2016 ==&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2016 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2016/seminari-associazioni/talk-257/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Adopt OSS. First Edition ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy is pleased to announce a new initiative: '''Adopt''' '''O'''pen'''S'''ource'''S'''oftware&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Given OWASP’s mission to help organizations with application security, we have established a new initiative to provide free, voluntary-based support to open source software projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Thanks to Adopt OSS, security enthusiasts are paired with participating open source projects, thus gaining exposure to real-life security engineering challenges and the opportunity for career growth. In turn, the participating projects are able to obtain free professional expertise to better improve their security posture, and ultimately build secure software. Over a six months period, OWASP Italy will facilitate the effort by coordinating the initiative and providing support when needed.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The first edition of this initiative will take place between ''May and November 2015'', and will see the participation of '''7 OWASP Italy members''' and '''3 major OpenSource projects'''. At the end of the six months period, OWASP Italy will publish results and feedback from both volunteers and OSS maintainers.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The official flyer can be [https://www.owasp.org/images/0/07/AdoptOSSManifest-OWASPItaly.pdf downloaded from here].&lt;br /&gt;
&lt;br /&gt;
===Ntopng===&lt;br /&gt;
''Alessio Petracca, Mattia Folador, Giuseppe Longo''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.ntop.org/products/traffic-analysis/ntop/ Ntop] is the de-facto standard for real-time network traffic monitoring. OWASP Italy wants to help the project by increasing the security level of ntopng, performing security testing activities and supporting the remediation process.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will act in two steps:&lt;br /&gt;
* First, a penetration test targeting the web interface of ntopng will be performed, following the [https://www.owasp.org/index.php/OWASP_Testing_Guide_v3_Table_of_Contents OWASP Testing Methodology]&lt;br /&gt;
* Secondly, source code review of ntopng main components (such as the C++ core engine) will be statically reviewed. The objective is to address all relevant checks contained within the [https://www.owasp.org/index.php/OWASP_Code_review_V2_Table_of_Contents OWASP Code Review Guide]&lt;br /&gt;
&lt;br /&gt;
In case the activities above are completed before the end of the six-months period, additional activities (such as the development of security plugins) will be discussed.&lt;br /&gt;
Luca Deri and Arianna Avanzini will support Alessio Petracca and Mattia Folador in these activities, by providing guidance and insights.&lt;br /&gt;
&lt;br /&gt;
===WordPress===&lt;br /&gt;
''Paolo Perego, Sandro Zaccarini''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://wordpress.org/ WordPress] is the facto standard for web publishing. If you need a blog, if you need a new showcase website for your portfolio or a tiny e-commerce web site for your small company you will look at WordPress to start.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Paying the cost to be the boss, WordPress during the years suffered tons of security issues, 3 major issues only in the beginning of May 2015. Either the core, plugins and themes are developed with easy to use in mind and they need to be hardened.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Italy wants to support WordPress adopting it with the &amp;quot;Stand by WordPress&amp;quot; initiative. We will deploy the software in three different standard configurations: blog, company's portfolio and e-commerce.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will do continuous appsec during development of 4.3 version in order to quickly spot security issues before the August release. In addition, we will take care of hardening guidelines and both plugins and themes subsystems in order to improve the overall architecture.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You can follow the progress of the &amp;quot;Stand by WordPress&amp;quot; initiative here: https://standbywordpress.wordpress.com&lt;br /&gt;
&lt;br /&gt;
===GlobaLeaks===&lt;br /&gt;
''Luca Carettoni, Giovanni Cerrato, Marco Lancini''&lt;br /&gt;
&lt;br /&gt;
[https://www.globaleaks.org/ GlobaLeaks] is the first open-source whistleblowing framework. It empowers anyone to easily set up and maintain an anonymous whistleblowing platform.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Considering the potential hostile environments in which the application may be hosted, security vulnerabilities and abuses are primary concerns for GlobaLeaks’ maintainers.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We want to help the team in their excellent application security practices, by performing vulnerability research activities in order to discover unknown bugs within the boundaries of their specific [https://docs.google.com/document/d/1niYFyEar1FUmStC03OidYAIfVJf18ErUFwSWCmWBhcA/pub threat model]. In particular, we will be focusing on two main software components (GLBackend and GLClient) and new security-relevant changes (upcoming authentication re-factoring and end-to-end encryption).&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information on '''Adopt OSS''', please send an email to [mailto:owasp-italy@lists.owasp.org owasp-italy@lists.owasp.org]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2015 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2015 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2015/seminari-associazioni/talk-140/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Rome 11-12th December 2014 ==&lt;br /&gt;
The agenda is online! &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
http://www.isacaroma.it/images/owasp_agenda_11-12-12-2014.JPG&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 3rd October 2014 ==&lt;br /&gt;
The agenda: &amp;lt;br&amp;gt;&lt;br /&gt;
[[File:Venice2014.jpg]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Here is the [https://www.owasp.org/images/d/d3/OWASPVenice2014.pdf flyer]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day @ the University of Genova (14th May 2014) ==&lt;br /&gt;
Thank to the collaboration with [http://www.ai-lab.it/armando Prof. Alessandro Armando] and to the availability of Gary McGraw, Ph.D. CTO, Cigital we are planning an incredible [https://www.owasp.org/index.php/Italy_OWASP_Day_2014_Genova OWASP Day next 14th May].&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2014 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2014 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2014/seminari-associazioni/talk-34/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP EU Tour 2013 - 27th June - Rome==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;{{:EUTour2013 header}}&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with Università Degli Studi Roma Tre, next 27th June we will have the OWASP EU Tour Rome Conference.&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Europe TOUR, is an event across the European region that promotes awareness about application security, so that people and organizations can make informed decisions about true application security risks. &amp;lt;br&amp;gt;Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.&lt;br /&gt;
&lt;br /&gt;
The conference will be held at Università Degli Studi Roma Tre. Address: Via Vito Volterra, 62, Rome.&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/EUTour2013_Rome_Agenda Here you can find the agenda and all the information to participate]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2013 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy participated to the Security Summit 2013 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[http://milano2013.securitysummit.it/eventi/view/35 See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy Day 2012: &amp;quot;Web Security in a Mobile World&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;center&amp;gt;[[File:OWASPITDay2012.jpg]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Italy OWASP Italy chapter] will host the OWASP Italy Day 2012 conference in Rome, Italy at the University of Rome La Sapienza next 23rd November 2012.&lt;br /&gt;
&lt;br /&gt;
More information [https://www.owasp.org/index.php?title=Italy_OWASP_Day_2012 here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Board  ==&lt;br /&gt;
&lt;br /&gt;
*This is the '''OWASP-Italy Board''':&lt;br /&gt;
Founder and Chair: Matteo Meucci (Jan 2005)&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Italy Board: Paolo Perego, Luca Carettoni, Antonio Parata, Giorgio Fedon, Stefano Di Paola, Mauro Bregolin, Claudio Merloni, Raoul Chiesa.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Partnerships  ====&lt;br /&gt;
&lt;br /&gt;
*ISC2-Italian Chapter: Thanks to Marco Misitano, Paolo Ottolino and Claudio Sasso, OWASP Italy collaborates with the ISC2-Italian Chapter for new initiatives regarding Security Conferences, articles and contentes regarding SDLC.&lt;br /&gt;
&lt;br /&gt;
[http://www.isc2chapter-italy.it https://www.owasp.org/images/a/a3/ISC2Italy.jpg]&lt;br /&gt;
&lt;br /&gt;
*CSA Italy Partnership&lt;br /&gt;
&lt;br /&gt;
[http://chapters.cloudsecurityalliance.org/italy/ https://www.owasp.org/images/6/6a/CSAItalylogo.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Alberto Manfredi (CSA Italy President) we are starting a collaboration with the Italian Chapter of the Cloud Security Alliance.&lt;br /&gt;
&lt;br /&gt;
*IsecLab Partnership&lt;br /&gt;
&lt;br /&gt;
[http://www.iseclab.org http://www.owasp.org/images/4/4b/LogoIsecLab.png]&lt;br /&gt;
&lt;br /&gt;
We are beginning a collaboration with David Balzarotti and Marco Balduzzi of International Secure Systems Lab(IsecLab) with the goal of sharing and improving new WebAppSec projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*CLUSIT Member&lt;br /&gt;
&lt;br /&gt;
http://www.clusit.it/logo_clusit/clusit_logo_b130.gif &lt;br /&gt;
&lt;br /&gt;
Thanks to CLUSIT and OWASP Foundation we have established a cross-membership between the two organizations. So OWASP-Italy is now a [http://www.clusit.it/soci.htm CLUSIT member] and CLUSIT is an OWASP Educational Member.&lt;br /&gt;
&lt;br /&gt;
*ISACA Rome&lt;br /&gt;
&lt;br /&gt;
[http://www.isacaroma.it http://www.owasp.org/images/9/98/Isacaroma.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Ugo Spaziani, we are developing seminars and new ideas with ISACA Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2012 ==&lt;br /&gt;
- 21st March 2012, OWASP Italy will present 3 talks:&lt;br /&gt;
&lt;br /&gt;
- Antonio Parata e Paolo Perego:&amp;quot;Security Testing for developers&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;Banking Malware evolution in Italy: defense approach&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Stefano Di Paola:&amp;quot;DOM Xss: la nuova generazione di vulnerabilità applicative&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
Please subscribe for free here: https://www.securitysummit.it/eventi/view/21&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2011 ==&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''OWASP Books are out!'''&lt;br /&gt;
&lt;br /&gt;
Now you can download or buy a book on the OWASP Projects. Check it here: http://stores.lulu.com/owasp &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Activities  ====&lt;br /&gt;
&lt;br /&gt;
*(Jun 10): OWASP Testing Guide presentation at FBK (Fondazione Bruno Kessler). &lt;br /&gt;
&lt;br /&gt;
*(May 10): OWASP Training at London: last 28th May in London, OWASP leaders deliver a course focused on the main OWASP Projects. This course aims to change that by providing a selection of mature and enterprise ready projects together with practical examples of how to use them. &lt;br /&gt;
This Course was FREE for OWASP Members. &lt;br /&gt;
http://www.owasp.org/index.php/London/Training/OWASP_projects_and_resources_you_can_use_TODAY&lt;br /&gt;
&lt;br /&gt;
*(Jan 09) OWASP Testing Guide v3 is finished! You can download or browse it [http://www.owasp.org/index.php/Category:OWASP_Testing_Project here]&lt;br /&gt;
&lt;br /&gt;
*(Mar 07) Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) )&lt;br /&gt;
&lt;br /&gt;
[http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
*(Oct 06) ISACA Roma has published several interview with OWASP-Italy members:&lt;br /&gt;
&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli]] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/328 Carlo Pelliccioni]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Paolo Perego has created the new '''OWASP Orizon Project'''. Go to [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Matteo Meucci has been selected as the new editor of the '''OWASP Testing Guide v2'''. See OWASP [http://www.owasp.org/index.php/OWASP_Autumn_Of_Code_2006_:_Selected_Projects_Press_Release press release] and go to [http://www.owasp.org/index.php/OWASP_Autumn_of_Code_2006_-_Projects:_Testing_Guide OWASP Testing Project v2]&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Carlo Pelliccioni is writing an article about the [http://www.owasp.org/index.php/Analysis_about_error_codes analysis of error codes] received by web servers.&lt;br /&gt;
&lt;br /&gt;
*Top10 Vulnerabilities - OWASP-Italy survey:&lt;br /&gt;
&lt;br /&gt;
[[Image:Top 10 vulnerabilities-mini.GIF]] &lt;br /&gt;
&lt;br /&gt;
*(21 Jun 06) '''Infosecurity 2006''': the event is organized and managed by the CLUSIT.&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. [http://www.infosecurity.it/Roma/programma.php More info here] &lt;br /&gt;
&lt;br /&gt;
*(1 Jun 06) '''&amp;quot;Quaderno CLUSIT&amp;quot;'''&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but will be made public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
*(31 May 06) Luca Carettoni has published the article '''&amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;.''' [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article.&lt;br /&gt;
&lt;br /&gt;
*(1 Mar 06) '''OWASP-Boston, Microsoft'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler, Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting. [http://www.owasp.org/local/boston.html More info here] &lt;br /&gt;
&lt;br /&gt;
*(18 Nov 05) '''IDC - European Banking Forum'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we will have a great speech at the [http://www.idc.com/italy/events/banking05/banking05_agenda.jsp IDC European IT Banking Forum 2005]. Agenda: - New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair - Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy &lt;br /&gt;
&lt;br /&gt;
*(Oct 05) '''SMAU 2005''' is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy.&lt;br /&gt;
&lt;br /&gt;
SMAU has accepted our submission! [http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili More info here] &lt;br /&gt;
&lt;br /&gt;
*(Giu 05) Thanks to Massimiliano Graziani we have translated in italian the '''&amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;'''. You can download it [http://www.owasp.org/documentation/testing.html here.]&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
*(May 05) '''ISACA Roma Newsletter''' has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005.&lt;br /&gt;
&lt;br /&gt;
*The presentation of the seminar we have done in '''ISACA Rome''' (31th March 2005) is now available [http://www.isacaroma.it/pdf/050331/meucci.zip here.]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)].&lt;br /&gt;
&lt;br /&gt;
*(Mar 05) Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here].&lt;br /&gt;
&lt;br /&gt;
*[http://www.isacaroma.it/html/newsletter/?q=node/78 Here] you can read an interview talking about OWASP. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Events  ====&lt;br /&gt;
&lt;br /&gt;
=== 15th March, 2011 - OWASP-Italy@Security Summit ===&lt;br /&gt;
&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
=== November, 2010 - OWASP-Italy Day V  ===&lt;br /&gt;
&lt;br /&gt;
- OWASP Day for E-Gov 2010: 9th November 2010 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
An event organized by Consip. More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_10 here]&lt;br /&gt;
&lt;br /&gt;
=== November, 2009 - OWASP-Italy Day IV  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Following on from the great success of last OWASP Days the forth conference has taken place in November 2009 in Milan. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_4 here]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Day for E-Gov 2009: 5th November 2009 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_09 here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2009 - OWASP-Italy @ PCI Milan  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Testing Guide and PCI-DSS Standard at the [http://www.pci-portal.com/lang-en/events/event-info/pcimilan PCI Milan event] last 31st March. &lt;br /&gt;
&lt;br /&gt;
The presentation is published [http://www.owasp.org/images/3/38/MeucciPciMilan09.pdf here] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 23rd February, 2009 - OWASP Day III  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_3 &amp;quot;Web Application Security: research meets industry&amp;quot;] &amp;lt;br&amp;gt; Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== 10th October, 2008 - Isaca Roma PCM 2008 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci presented the new OWASP Projects and the Application Security in the Italian Companies. More information [http://www.isacaroma.it/html/ArchivioEventi-081010.html here] &lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2008 - OWASP Day II  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_2 &amp;quot;The State of the Art of the Web Application Security and the OWASP guidelines in the Companies&amp;quot;] Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== February 2008 - OWASP Italy at InfoSecurity 2008  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
5th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - The Owasp Orizon project: internals and hands on&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_94.aspx Paolo Perego] &lt;br /&gt;
&lt;br /&gt;
6th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - Costruire Software Sicuro dalle Fondamenta&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_128.aspx Antonio Parata] &lt;br /&gt;
&lt;br /&gt;
7th February: &lt;br /&gt;
&lt;br /&gt;
*10:30 - Tu programmi. Io buco.&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_137.aspx Luca Carettoni] &lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it Here] you can read more information about it. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== November 30th, 2007 - OWASP-Italy @ Elsag Datamat Security Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Guidelines and SDLC Security at the Elsag Datamat Security Forum 2007 &amp;lt;br&amp;gt;Where: Pescara &amp;lt;br&amp;gt;When: 30th November 2007, h.12.30 &lt;br /&gt;
&lt;br /&gt;
=== October 20th, 2007 - OWASP Italy at SMAU E-Academy 2007  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Last 20th October 2007 we had 5 speeches at SMAU E-Academy 2007, here you can download our presentations: &lt;br /&gt;
&lt;br /&gt;
*Giorgio Fedon, COO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/.pdf &amp;quot;Dove sono finiti i miei soldi? Internet Banking e Cross Site Scripting&amp;quot;] (coming soon) [[Image:FedonSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Paolo Perego, Senior Security Consultant at Spike Reply:&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/7/79/PeregoSMAU07.ppt &amp;quot;The Owasp Orizon project - bring security at the source&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Antonio Parata, Security Consultant at eMaze:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Valutazione del rischio tramite la logica fuzzy&amp;quot; (coming soon) [[Image:ParataSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Alberto Revelli, Senior Security Consultant at Portcullis Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/9/9f/RevelliSMAU07.pdf &amp;quot;Anti-Anti-XSS: bypass delle difese del browser&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, CTO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Cros-site Flashing! Gli attacchi Web di ultima generazione parlano multipiattaforma&amp;quot; (coming soon) [[Image:DiPaolaSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== September 10th, 2007 - OWASP Day WorldWide: &amp;quot;Privacy in the 21st Century&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Italy_OWASP_Day_1 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 29th, 2007 - Seminar: &amp;quot;Software Security&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, Paolo Perego and Matteo Meucci will talk at the Seminar: [http://www.sicurinfo.it/informazioni/visinf.asp?IDInfo=246&amp;amp;CAT=53 &amp;quot;Which approaches to Software Security&amp;quot;] organized by Firenze Tecnologia.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 15th-17th, 2007 - 6th OWASP AppSec Conference in Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We are in the initial planning stages for the next OWASP Europe conference, which we plan to hold in Italy in May 2007.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/6th_OWASP_AppSec_Conference_-_Italy_2007 Here] you can find all the details about the conference, cfp and sponsorship. &lt;br /&gt;
&lt;br /&gt;
=== April 14th, 2007 - Master on Information Security, University of Rome &amp;quot;La Sapienza&amp;quot; ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We have done a 4h seminar for the students of [http://mastersicurezza.uniroma1.it/ Master on Information Security at &amp;quot;La Sapienza&amp;quot;] for the [http://icsecurity.di.uniroma1.it/dokuwiki/doku.php?id=projects:asp Application Security Project of &amp;quot;La Sapienza&amp;quot; University.]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 30th, 2007 - University of Rome &amp;quot;La Sapienza&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Thanks to Prof. Mancini and Roberto D'Addario, we will talk about OWASP at the convention &amp;quot;Institutions, Companies and Information Security: comparing the problems&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[http://w3.uniroma1.it/security/Eventi/eventi.html Here] you can find more details. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2007 - EuSecWest 07  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci presented the new OWASP Testing Guide at [http://www.eusecwest.com/agenda.html EUSecWest]. [http://www.owasp.org/images/e/e9/OWASP_Testing_Guide_Presentation_EUSecWest07.zip Here] you take a look at the presentation. &lt;br /&gt;
&lt;br /&gt;
=== February 6th-8th, 2007 - InfoSecurity  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*February 6th:15.30&lt;br /&gt;
&lt;br /&gt;
After the great success obtained form CCC at Berlin, Stefano Di Paola and Giorgio Fedon will talk about:&amp;quot; Web Security Client Side: attacks at Web 2.0&amp;quot; More information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=aqfi82GOKd6I748s1evI8Q%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 6th:16.30&lt;br /&gt;
&lt;br /&gt;
After the great effort on the Testing Guide Project, Matteo Meucci and Alberto Revelli will present: &amp;quot;The new OWASP Testing Guide&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=nq6tSIuRoPVJBanBSsRiSQ%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 7th:12.30&lt;br /&gt;
&lt;br /&gt;
Authors of innovative SQL injection tools, Alberto Revelli and Antonio Parata will show: &amp;quot;Advanced SQL Injection: testing tools and defensive strategies.&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=3z04F5BgZRgfU0YX8JRYtA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here] &lt;br /&gt;
&lt;br /&gt;
*February 7th:13.30&lt;br /&gt;
&lt;br /&gt;
Author of the new OWASP Orizon project, Paolo Perergo will present:&amp;quot;Secure programming: from theory to practice&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=9HePIzyo5p29ylpGBl6CiA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
=== January 25th, 2007 - Isaca Rome  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci will discuss the new [http://www.owasp.org/index.php/Category:OWASP_Testing_Project OWASP Testing Guide v2]&amp;lt;br&amp;gt; For more information:&amp;lt;br&amp;gt; http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
=== October 7th, 2006 - SMAU 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''The quest for secure code: code review and fundamental of secure coding.''&amp;quot; Matteo Meucci will present an introduction to the new OWASP Projects and OWASP-Italy activities. Paolo Perego (sp0nge) will speak about safe coding and the importance of code periodic review as natural software life cycle. Paolo will give a vision on code review and its phases http://www.webb.it/event/eventview/5772 &lt;br /&gt;
&lt;br /&gt;
Here are the presentations: &amp;lt;br&amp;gt; [[Image:Meucci SMAU06.pdf|Meucci_SMAU06]] &amp;lt;br&amp;gt; [[Image:Perego SMAU06.pdf|Perego_SMAU 06]] &lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''Advanced SQL Injection.''&amp;quot; Antonio Parata (S4tan) will explain SQL Injection, and how SQL Inference works on PHP/MySql platform. He will present an open source tool to support the testing. Alberto Revelli (icesurfer) will focus on Microsoft SQL Server: he will perform a live demo of sqlninja (http://sqlninja.sf.net), explaining how to obtain a pseudo-shell over SQL, how to escalate privileges, and how to play with the exotic equation: &amp;quot;SQL Injection + debug.exe + DNS = DOS prompt&amp;quot;&amp;amp;nbsp;! http://www.webb.it/event/eventview/5774 &lt;br /&gt;
&lt;br /&gt;
[[Image:Revelli SMAU06.pdf|Revelli_SMAU06]] &amp;lt;br&amp;gt; [[Image:Parata SMAU06.pdf|Parate_SMAU06]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP-Italy at SMAU06 2.JPG]] Luca, Carlo, Alberto, Antonio, Stefano &amp;lt;br&amp;gt; Matteo, Paolo, Giorgio &lt;br /&gt;
&lt;br /&gt;
=== September 29th, 2006 - OpenExp 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
September 30th, at 10:45 Antonio Parata (S4tan) will speak about SQL Injection: techniques, tools and practical examples. &lt;br /&gt;
&lt;br /&gt;
Abstract: Antonio will introduce some basic concepts about software security. It will be shown how SQL Inference works on PHP/MySql platform and presented an open source tool to support the testing. Finally will be listed some advises to avoid common bugs. http://www.openexp.it/ &lt;br /&gt;
&lt;br /&gt;
OWASP-Italy will have a stand from September 29th to October 1st. &lt;br /&gt;
&lt;br /&gt;
[[Image:Antonio Matteo Carlo.JPG]] [[Image:Antonio speech.JPG]] [[Image:Carlo.JPG]] [[Image:Claudio Luca.JPG]] [[Image:Mayhem Matteo.JPG]] [[Image:OWASP Banner2.JPG]] [[Image:OWASP Banner.JPG]] &lt;br /&gt;
&lt;br /&gt;
=== June 21th, 2006 - InfoSecurity 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. The event is organized and managed by the CLUSIT. &lt;br /&gt;
&lt;br /&gt;
Where: Sheraton Roma Hotel - Viale Del Pattinaggio, 100 When: 10,30 - 17,00 Who: Matteo Meucci and Alberto Revelli Link: http://www.infosecurity.it/Roma/programma.php &lt;br /&gt;
&lt;br /&gt;
Agenda: -- I Session -- Introduction to Web Application Security • Which are the risks? • Risk assessment of a web application • Core pillars of web security How to develop secure web applications: • Guidelines and case-studies &lt;br /&gt;
&lt;br /&gt;
-- II Session -- How to realize a security audit of a web application • The methodology OWASP Penetration Testing • The tools: OWASP WebScarab • Hands-on web application vulnerabilities: OWASP WebGoat • Advanced SQL Injection. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2006 - OWASP-Boston, Microsoft  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler (OWASP-Boston Chair), Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting of march. [http://www.owasp.org/index.php/Boston More info here] &lt;br /&gt;
&lt;br /&gt;
=== November 5th, 2005 - IDC - European Banking Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we have had a great speech at the IDC European IT Banking Forum 2005 (18 Nov 2005). http://www.idc.com/italy/events/banking05/banking05_agenda.jsp Agenda: &lt;br /&gt;
&lt;br /&gt;
*New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair &lt;br /&gt;
*Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy.&lt;br /&gt;
&lt;br /&gt;
You can download the report [http://cdn.idc.com/italy/downloads/report_banking05_eng.pdf here]. &lt;br /&gt;
&lt;br /&gt;
You can download the Case-Study of a vulnerable Home Banking Web Application [http://www.owasp.org/docroot/owasp/misc/IDC_BankingForum05v1.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== October 5th, 2005 - OWASP-Italy@SMAU2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
SMAU is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy. Alberto Revelli (our Technical Director) and Matteo Meucci have conducted a seminar talking about Web Application Security. Alberto has presented his new project: [http://sqlninja.sourceforge.net sqlninja]. Very cool!! &lt;br /&gt;
&lt;br /&gt;
http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili &lt;br /&gt;
&lt;br /&gt;
=== May 25th, 2005 - ISACA Rome 2nd meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
May 25th we'll be in ISACA Rome to present OWASP WebGoat and a real case of a Web Application Vulnerability. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.30 Registration 14.45 Matteo Meucci - Web Application Security Phase II - OWASP WebScarab and PenTest Checklist &lt;br /&gt;
&lt;br /&gt;
*A case-study of a Web Application Vulnerability: MMS Spoofing&lt;br /&gt;
&lt;br /&gt;
--- Web Application analysis --- Authentication and Billing of the MMS service --- Vulnerabilities --- Attack Analysis &lt;br /&gt;
&lt;br /&gt;
*Learning the most common web application vulnerabilities: OWASP WebGoat&lt;br /&gt;
&lt;br /&gt;
--- Http Basics --- HTML Clues --- Hidden Field Tampering --- How to spoof a Session Cookie --- Stored Cross Site Scripting --- Command Injection --- SQL Injection --- Fail Open Authentication &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050525/OWASP.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== May 18th, 2005 - Workshop on Computer Crime 2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; May 18th, 2005 OWASP-Italy is invited to present OWASP Top 10 to the &amp;quot;Workshop on Computer Crime 2005&amp;quot; titled: &amp;quot;EVOLUZIONI NORMATIVE E RECENTI PROBLEMATICHE DI SICUREZZA&amp;quot; &lt;br /&gt;
&lt;br /&gt;
The meeting is held at: Sala delle conferenze dell'Istituto Centrale della Banche Popolari Italiane Via Verziere, 11 &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.owasp.org/images/a/aa/Top10-ComputerCrimes.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== March 31th, 2005 - ISACA Rome meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March 31th we'll be in ISACA Rome to present OWASP and the Web Application Security. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.15 Registration 14.30 Matteo Meucci - Web Application Security - OWASP Guide: how to build secure web application - How to test your Web Application: WebScarab and the WebApp PenTest Checklist - How to learn the most common web application vulnerability: WebGoat - The Top Ten WebApp vulnerabilities - Common error on developing Web Application: Authentication mechanisms not &amp;quot;secure&amp;quot; Buffer Overflow and crash of the service Thief of identity: Cross Site Scripting Manipulation of company data: SQL Injection Reserved information: misconfiguration Bad session management and thief of identity - OWASP-Italy: projects and next challenges &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050331/meucci.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== March 21th, 2005 - OWASP-Italy conducts a seminar in AlmaWeb  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March, the 21th OWASP-Italy has been invited at the University of Bologna to conduct a seminar regards to [http://www.almaweb.unibo.it/830.dyn Master in Management and Information Technology] titled “Web Application Security and OWASP”. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: - OWASP &amp;amp;amp; Web Application Security - Common Web Application Vulnerabilities - A real case of web application vulnerability: MMS Spoofing&amp;amp;amp;Billing - Training: WebGoat &lt;br /&gt;
&lt;br /&gt;
==== Publications  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== October 2009 Interview on &amp;quot;Il sole 24 ore&amp;quot;  ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/5/5c/Nova09.pdf Gary McGraw and Matteo Meucci] interviewed by NOVA, talking about BSIMM and OWASP.&lt;br /&gt;
&lt;br /&gt;
=== March, 2007 Interview on HTML.it  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) ) [http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
=== October, 2006 ISACA Roma interviews OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
After the speeches that OWASP-Italy has done at [http://www.smau.it/catnews.asp?l=2&amp;amp;codcat=385 SMAU E-Academy 2006], ISACA Roma has interviewed some of the people of the Italian chapter. Follow the links for the full interviews (in italian): &amp;lt;br&amp;gt; [[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli] ] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/322 Stefano Di Paola &amp;amp; Giorgio Fedon]] &lt;br /&gt;
&lt;br /&gt;
=== Aug, 2006 - Article on Banca Finanza magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Banca Finanza, the italian magazine about finance and banking, has interviewed Raoul Chiesa talking about the new risks for the on-line banking security. Raoul speaks about OWASP and web application security [[Media:042006BF.pdf]] &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Quaderno CLUSIT  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but it will be public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Paper on SQL Injection and Inference on PHP/MySQLInference  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Antonio &amp;quot;s4tan&amp;quot; Parata has published an article about SQL Injection based on Inference for testing web application on PHP/MySQL platform. [http://www.ictsc.it/papers/sqlInferenceOnMySql.html Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== May, 2006 - Published an article about OWASP and Top-10 Vulnerabilities  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published the article &amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;. [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== June, 2005 - OWASP Pen Test Checklist v 1.1 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Massimiliano Graziani we have translated in italian the &amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;. You can download it [http://www.owasp.org/documentation/testing.html here.] Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
=== May, 2005 - Isaca Roma Newsletter about OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
ISACA Roma Newsletter has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy] &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published &amp;quot;MMS Spoofing&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)]. &lt;br /&gt;
&lt;br /&gt;
Jim Hewitt, CISSP PMP working at CGI-AMS, affirms (slide#78): &amp;quot;Very interesting analysis of spoofed cell phone messaging and fraudulent billing&amp;quot;. See: www.techvalleynyissa.org/Resources/2005_07_WebApplicationSecurity.ppt &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published an article on ICT Security magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005. &lt;br /&gt;
&lt;br /&gt;
=== March, 2005 - OWASP Top-10 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here]. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
==== Tools &amp;amp;amp; Research  ====&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Nov, 2007 - sqlmap v0.5  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released the fifth versions of the tool [http://sqlmap.sourceforge.net sqlmap]. sqlmap is an automatic SQL injection tool entirely developed in Python. It is capable to perform an extensive database management system back-end fingerprint, retrieve remote DBMS databases, usernames, tables, columns, enumerate entire DBMS, read system files and much more taking advantage of web application programming security flaws that lead to SQL injection vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
You can download the latest stable version from its [https://sourceforge.net/project/showfiles.php?group_id=171598&amp;amp;package_id=196107 SourceForge File List page] or the latest development version from its [https://sqlmap.svn.sourceforge.net/svnroot/sqlmap SourceForge SVN repository]. &lt;br /&gt;
&lt;br /&gt;
=== Dec, 2006 - sqlmap v0.2  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released a second version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://sqlmap.sourceforge.net/ Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
=== September, 2006 - Wisec Project  ===&lt;br /&gt;
&lt;br /&gt;
Stefano Di Paola is developing Wisec - The Wiki Security Project [http://www.wisec.it Here] you can accesses the project. &lt;br /&gt;
&lt;br /&gt;
=== July, 2006 - Sqlmap v0.0.1  ===&lt;br /&gt;
&lt;br /&gt;
Daniele Bellucci has developed a first version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://www.linux.it/~belch/?p=17 Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Chapter]]&lt;br /&gt;
[[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256475</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256475"/>
				<updated>2019-12-23T10:51:23Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modelling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Agenda and presentations =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256474</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256474"/>
				<updated>2019-12-23T10:29:26Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: a&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modelling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Agenda and presentations =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
MoranaTM2019OWASPDay.pdf|Marco&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256423</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256423"/>
				<updated>2019-12-17T16:57:03Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modelling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Agenda and presentations =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256422</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256422"/>
				<updated>2019-12-17T16:56:35Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: new&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference we are proud to announce that the 2019 OWASP Italy conference has been held at the University of Udine on December 14th, 2019.   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies. This year special topic of interest is threat modelling.&lt;br /&gt;
&lt;br /&gt;
This conference provided a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
= Agenda and presentations =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: Introduction to Threat Modeling and the Process for Attack SImulation and Threat Analysis&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;12.15h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=&amp;quot;top&amp;quot;&amp;gt;13:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;font size=&amp;quot;2pt&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256117</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256117"/>
				<updated>2019-11-19T11:46:27Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference we are proud to announce that the 2019 OWASP Italy conference will be held at the University of Udine on December 14th, 2019   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies and cloud security. This year special topic of interest is the security of emerging technologies.&lt;br /&gt;
&lt;br /&gt;
This conference provides a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
The address of the conference is: [http://www.uniud.it Università degli Studi di Udine], Palazzo Antonini, Via Tarcisio Petracco, 8, 33100 Udine UD, Italy, [https://www.google.com/maps/place/Università+degli+Studi+di+Udine,+Palazzo+Antonini-Cernazai/@46.0666611,13.2331162,15z/data=!4m5!3m4!1s0x0:0xbe8859d1092f1d40!8m2!3d46.0666611!4d13.2331162 map] &lt;br /&gt;
&lt;br /&gt;
= Agenda =&lt;br /&gt;
&lt;br /&gt;
The schedule will be as follow:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: My journey in Software Security &amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;11:50h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;How to be me&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Paolo Perego, Gruppo MutuiOnline - Security manager&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;12.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;13:10h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Conference will be in ITALIAN language.&lt;br /&gt;
&lt;br /&gt;
= Registration =&lt;br /&gt;
The conference is FREE but registration is required in order to reserve a seat at the conference. &lt;br /&gt;
&lt;br /&gt;
Please use the following [https://www.eventbrite.com/e/italy-owasp-day-udine-2019-tickets-71599089805| link] to reserve your seat&lt;br /&gt;
&lt;br /&gt;
= Organization and goals =&lt;br /&gt;
&lt;br /&gt;
* This conference will be organized by OWASP Italy with the logistical support of OWASP foundation. The conference hosts are [https://www.researchgate.net/profile/Marino_Miculan Prof Marino Miculan] Department of Computer Sciences, University of Udine and OWASP Italy chair [https://www.owasp.org/index.php/Matteo_Meucci Ing. Matteo Meucci].   &lt;br /&gt;
* The conference main goal is to stimulate interest in application and secure software engineering practices and learn about web application security, cloud security and security of emerging technologies.&lt;br /&gt;
&lt;br /&gt;
= Sponsors =&lt;br /&gt;
&lt;br /&gt;
Conference, breakfast &amp;amp; coffee break, lunch, dinner and lanyard sponsorships are available with details provided in the [https://www.owasp.org/images/c/c7/OWASP_Day_2019_CFS_New.pdf CFS]. Sponsorship is the best opportunity to provide visibility to your company’s brand to the attendees during and before the conference. Conference sponsors company logos will also be published on the conference web pages the will be also announced through OWASP channels and social media sites. Companies that wish to sponsor the event can contact [https://www.owasp.org/index.php/Italy OWASP Italy] or the conference organizers.&lt;br /&gt;
&lt;br /&gt;
Conference speakers of event sponsoring companies are encourage to submit their presentations. Please refer to the call for papers section of this page on how to submit a paper/presentation that follows OWASP guidelines.&lt;br /&gt;
&lt;br /&gt;
= Call For Papers =&lt;br /&gt;
&lt;br /&gt;
The [https://www.owasp.org/images/7/7f/OWASP_Day_2019_CFP_New.pdf CFP] is now CLOSED. &lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256116</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256116"/>
				<updated>2019-11-19T11:45:16Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: a&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference we are proud to announce that the 2019 OWASP Italy conference will be held at the University of Udine on December 14th, 2019   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies and cloud security. This year special topic of interest is the security of emerging technologies.&lt;br /&gt;
&lt;br /&gt;
This conference provides a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
The address of the conference is: [http://www.uniud.it Università degli Studi di Udine], Palazzo Antonini, Via Tarcisio Petracco, 8, 33100 Udine UD, Italy, [https://www.google.com/maps/place/Università+degli+Studi+di+Udine,+Palazzo+Antonini-Cernazai/@46.0666611,13.2331162,15z/data=!4m5!3m4!1s0x0:0xbe8859d1092f1d40!8m2!3d46.0666611!4d13.2331162 map] &lt;br /&gt;
&lt;br /&gt;
= Agenda =&lt;br /&gt;
&lt;br /&gt;
The schedule will be as follow:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: My journey in Software Security &amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;11:50h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;How to be me&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Paolo Perego, Gruppo MutuiOnline - Security manager&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;12.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;13:10h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Conference will be in ITALIAN language.&lt;br /&gt;
&lt;br /&gt;
= Registration =&lt;br /&gt;
The conference is FREE but registration is required in order to reserve a seat at the conference. &lt;br /&gt;
&lt;br /&gt;
Please use the following [https://www.eventbrite.com/e/italy-owasp-day-udine-2019-tickets-71599089805| link] to reserve your seat&lt;br /&gt;
&lt;br /&gt;
= Organization and goals =&lt;br /&gt;
&lt;br /&gt;
* This conference will be organized by OWASP Italy with the logistical support of OWASP foundation. The conference hosts are [https://www.researchgate.net/profile/Marino_Miculan Prof Marino Miculan] Department of Computer Sciences, University of Udine and OWASP Italy chair [https://www.owasp.org/index.php/Matteo_Meucci Ing. Matteo Meucci].   &lt;br /&gt;
* The conference main goal is to stimulate interest in application and secure software engineering practices and learn about web application security, cloud security and security of emerging technologies.&lt;br /&gt;
&lt;br /&gt;
= Sponsors =&lt;br /&gt;
&lt;br /&gt;
Conference, breakfast &amp;amp; coffee break, lunch, dinner and lanyard sponsorships are available with details provided in the [https://www.owasp.org/images/c/c7/OWASP_Day_2019_CFS_New.pdf CFS]. Sponsorship is the best opportunity to provide visibility to your company’s brand to the attendees during and before the conference. Conference sponsors company logos will also published on the conference web pages the will be also announced through OWASP channels and social media sites. Companies that wish to sponsor the event can contact [https://www.owasp.org/index.php/Italy OWASP Italy] or the conference organizers.&lt;br /&gt;
&lt;br /&gt;
Conference speakers of event sponsoring companies are encourage to submit their presentations. Please refer to the call for papers section of this page on how to submit a paper/presentation that follows OWASP guidelines.&lt;br /&gt;
&lt;br /&gt;
= Call For Papers =&lt;br /&gt;
&lt;br /&gt;
The [https://www.owasp.org/images/7/7f/OWASP_Day_2019_CFP_New.pdf CFP] is now open. The deadline for paper submission to the CFP is November 14th. The top 5 papers will be selected. For the format of the presentations refer to the [https://www.owasp.org/index.php/Category:OWASP_Presentations OWASP presentation guidelines] . The contents of the presentation must follow OWASP guidelines regarding copyright and non-product bias presentation style.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256109</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256109"/>
				<updated>2019-11-18T21:20:52Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: agenda&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference we are proud to announce that the 2019 OWASP Italy conference will be held at the University of Udine on December 14th, 2019   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies and cloud security. This year special topic of interest is the security of emerging technologies.&lt;br /&gt;
&lt;br /&gt;
This conference provides a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
The address of the conference is: [http://www.uniud.it Università degli Studi di Udine], Palazzo Antonini, Via Tarcisio Petracco, 8, 33100 Udine UD, Italy, [https://www.google.com/maps/place/Università+degli+Studi+di+Udine,+Palazzo+Antonini-Cernazai/@46.0666611,13.2331162,15z/data=!4m5!3m4!1s0x0:0xbe8859d1092f1d40!8m2!3d46.0666611!4d13.2331162 map] &lt;br /&gt;
&lt;br /&gt;
= Agenda =&lt;br /&gt;
&lt;br /&gt;
The Conference will be in ITALIAN language except for the keynote speaker that will be in ENGLISH. &lt;br /&gt;
&lt;br /&gt;
The schedule will be as follow:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:00h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Registration of the participants&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: My journey in Software Security &amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber Security Citi&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;11:50h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;How to be me&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Paolo Perego, Gruppo MutuiOnline - Security manager&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;12.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;13:10h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Registration =&lt;br /&gt;
The conference is FREE but registration is required in order to reserve a seat at the conference. &lt;br /&gt;
&lt;br /&gt;
Please use the following [https://www.eventbrite.com/e/italy-owasp-day-udine-2019-tickets-71599089805| link] to reserve your seat&lt;br /&gt;
&lt;br /&gt;
= Organization and goals =&lt;br /&gt;
&lt;br /&gt;
* This conference will be organized by OWASP Italy with the logistical support of OWASP foundation. The conference hosts are [https://www.researchgate.net/profile/Marino_Miculan Prof Marino Miculan] Department of Computer Sciences, University of Udine and OWASP Italy chair [https://www.owasp.org/index.php/Matteo_Meucci Ing. Matteo Meucci].   &lt;br /&gt;
* The conference main goal is to stimulate interest in application and secure software engineering practices and learn about web application security, cloud security and security of emerging technologies.&lt;br /&gt;
&lt;br /&gt;
= Sponsors =&lt;br /&gt;
&lt;br /&gt;
Conference, breakfast &amp;amp; coffee break, lunch, dinner and lanyard sponsorships are available with details provided in the [https://www.owasp.org/images/c/c7/OWASP_Day_2019_CFS_New.pdf CFS]. Sponsorship is the best opportunity to provide visibility to your company’s brand to the attendees during and before the conference. Conference sponsors company logos will also published on the conference web pages the will be also announced through OWASP channels and social media sites. Companies that wish to sponsor the event can contact [https://www.owasp.org/index.php/Italy OWASP Italy] or the conference organizers.&lt;br /&gt;
&lt;br /&gt;
Conference speakers of event sponsoring companies are encourage to submit their presentations. Please refer to the call for papers section of this page on how to submit a paper/presentation that follows OWASP guidelines.&lt;br /&gt;
&lt;br /&gt;
= Call For Papers =&lt;br /&gt;
&lt;br /&gt;
The [https://www.owasp.org/images/7/7f/OWASP_Day_2019_CFP_New.pdf CFP] is now open. The deadline for paper submission to the CFP is November 14th. The top 5 papers will be selected. For the format of the presentations refer to the [https://www.owasp.org/index.php/Category:OWASP_Presentations OWASP presentation guidelines] . The contents of the presentation must follow OWASP guidelines regarding copyright and non-product bias presentation style.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256107</id>
		<title>Italy OWASP Day Udine 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy_OWASP_Day_Udine_2019&amp;diff=256107"/>
				<updated>2019-11-18T18:26:44Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: agenda&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://www.owasp.org/index.php/Italy Back to the Italian Chapter]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[File:Screen Shot 2019-01-31 at 10.23.04 PM.png|frameless|616x616px]]&lt;br /&gt;
&amp;lt;/center&amp;gt;Following on from the great successes of [https://www.owasp.org/index.php/Italy_OWASP_Day_Cagliari_2018 last year] OWASP Italy day conference we are proud to announce that the 2019 OWASP Italy conference will be held at the University of Udine on December 14th, 2019   &lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org Open Web Application Security Project], or OWASP, is an international non-profit organization dedicated to web and application security. OWASP is organized as an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. Many standards, books, tools, and organizations reference the Top OWASP 10 project, including MITRE, PCI DSS, the Defense Information Systems Agency (DISA-STIG), the United States Federal Trade Commission (FTC) and many more. The OWASP Testing Guide includes a &amp;quot;best practice&amp;quot; penetration testing framework that users can implement in their own organizations and a &amp;quot;low level&amp;quot; penetration testing guide that describes techniques for testing most common web application and web service security issues. &lt;br /&gt;
&lt;br /&gt;
[http://www.esnnaseudine.it/?q=blog/universitaUdine The University of Udine] The University of Udine is a young and dynamic university, whose mission, since its foundation in 1978, has been to promote higher education through generation of new ideas and worldwide connections. It is situated in Udine, a town in Friuli Venezia Giulia Region, which historically has been a meeting place and crossroads of different worlds and cultures. The University of Udine is ranked eighth among Universities in Italy in terms of education quality and research and it has just celebrated its 40th birthday last year. &lt;br /&gt;
&lt;br /&gt;
OWASP Italy Day is a one-day conference focused on web application and software security, application security testing tools and technologies and cloud security. This year special topic of interest is the security of emerging technologies.&lt;br /&gt;
&lt;br /&gt;
This conference provides a unique opportunity to learn about application security topics and to network with application security professionals/managers, software engineers, software quality engineers/testers and computer science students.&lt;br /&gt;
&lt;br /&gt;
The address of the conference is: [http://www.uniud.it Università degli Studi di Udine], Palazzo Antonini, Via Tarcisio Petracco, 8, 33100 Udine UD, Italy, [https://www.google.com/maps/place/Università+degli+Studi+di+Udine,+Palazzo+Antonini-Cernazai/@46.0666611,13.2331162,15z/data=!4m5!3m4!1s0x0:0xbe8859d1092f1d40!8m2!3d46.0666611!4d13.2331162 map] &lt;br /&gt;
&lt;br /&gt;
= Agenda =&lt;br /&gt;
&lt;br /&gt;
The Conference will be in ITALIAN language except for the keynote speaker that will be in ENGLISH. &lt;br /&gt;
&lt;br /&gt;
The schedule will be as follow:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Welcome and opening of the works&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Prof. Marino Miculan,- Università degli Studi di Udine, Matteo Meucci OWASP Italy&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;9:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Keynote: My journey in Software Security &amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt; Marco Morana, SVP Cyber SecurityCiti&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;10:45h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;SSRF present and future&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;David Calligaris, Director of Vulnerability Research &amp;amp; Security Testing Automation Huawei Technologies GMBH&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;11.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Coffee Break&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;11:50h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;How to be me&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Paolo Perego, Gruppo MutuiOnline - Security manager&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;12.30h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#b9c2dc&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;Testing for integrity flaws in web sessions&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;Stefano Calzavara, Assistant professor - Università Ca' Foscari Venezia&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td valign=top&amp;gt;13:10h&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=&amp;quot;#eeeeee&amp;quot;&amp;gt;&amp;lt;b&amp;gt;&amp;quot;End of the OWASP day&amp;quot;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Registration =&lt;br /&gt;
The conference is FREE but registration is required in order to reserve a seat at the conference. &lt;br /&gt;
&lt;br /&gt;
Please use the following [https://www.eventbrite.com/e/italy-owasp-day-udine-2019-tickets-71599089805| link] to reserve your seat&lt;br /&gt;
&lt;br /&gt;
= Organization and goals =&lt;br /&gt;
&lt;br /&gt;
* This conference will be organized by OWASP Italy with the logistical support of OWASP foundation. The conference hosts are [https://www.researchgate.net/profile/Marino_Miculan Prof Marino Miculan] Department of Computer Sciences, University of Udine and OWASP Italy chair [https://www.owasp.org/index.php/Matteo_Meucci Ing. Matteo Meucci].   &lt;br /&gt;
* The conference main goal is to stimulate interest in application and secure software engineering practices and learn about web application security, cloud security and security of emerging technologies.&lt;br /&gt;
&lt;br /&gt;
= Sponsors =&lt;br /&gt;
&lt;br /&gt;
Conference, breakfast &amp;amp; coffee break, lunch, dinner and lanyard sponsorships are available with details provided in the [https://www.owasp.org/images/c/c7/OWASP_Day_2019_CFS_New.pdf CFS]. Sponsorship is the best opportunity to provide visibility to your company’s brand to the attendees during and before the conference. Conference sponsors company logos will also published on the conference web pages the will be also announced through OWASP channels and social media sites. Companies that wish to sponsor the event can contact [https://www.owasp.org/index.php/Italy OWASP Italy] or the conference organizers.&lt;br /&gt;
&lt;br /&gt;
Conference speakers of event sponsoring companies are encourage to submit their presentations. Please refer to the call for papers section of this page on how to submit a paper/presentation that follows OWASP guidelines.&lt;br /&gt;
&lt;br /&gt;
= Call For Papers =&lt;br /&gt;
&lt;br /&gt;
The [https://www.owasp.org/images/7/7f/OWASP_Day_2019_CFP_New.pdf CFP] is now open. The deadline for paper submission to the CFP is November 14th. The top 5 papers will be selected. For the format of the presentations refer to the [https://www.owasp.org/index.php/Category:OWASP_Presentations OWASP presentation guidelines] . The contents of the presentation must follow OWASP guidelines regarding copyright and non-product bias presentation style.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy&amp;diff=251437</id>
		<title>Italy</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy&amp;diff=251437"/>
				<updated>2019-05-13T15:11:59Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: udine&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[Image:OWASP-Italy.PNG]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== WELCOME  ====&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Italy|extra=The chapter leader is [mailto:matteo.meucci@owasp.org Matteo Meucci]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-italy|emailarchives=http://lists.owasp.org/pipermail/owasp-italy}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Italy&amp;lt;/paypal&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''NEXT EVENT: OWASP Day in Udine - 27th September 2019''' ==&lt;br /&gt;
The conference will take place next September 27th 2019.&lt;br /&gt;
&lt;br /&gt;
The details of the conference agenda and selected speakers will be announced after closing the (CFP) Call For Papers on August 15th.&lt;br /&gt;
&lt;br /&gt;
Confirmed keynote speaker is the American computer scientist, author, and researcher [https://en.wikipedia.org/wiki/Gary_McGraw Dr Gary McGraw]&lt;br /&gt;
&lt;br /&gt;
More information here:&lt;br /&gt;
&lt;br /&gt;
[[Italy OWASP Day Udine 2019|https://www.owasp.org/index.php/Italy_OWASP_Day_Udine_2019]]&lt;br /&gt;
&lt;br /&gt;
== '''OWASP/WIA initiatives - 26th March 2019''' ==&lt;br /&gt;
Thanks to Loredana Mancini and Zoe Braiterman we will have an OWASP-Italy /WIA initiatives at the Link Campus in Rome next 26th March.&amp;lt;br&amp;gt;&lt;br /&gt;
Venue: Link Campus University Via del Casale di San Pio V, 44 - 00165 Roma (RM)&lt;br /&gt;
&lt;br /&gt;
Speakers: Prof.ssa Paola Giannetakis (Link Campus University), Zoe Braiterman (OWASP/WIA Chair), Luciana Scognamiglio (Senior security expert /HPE), Matteo Meucci (OWASP-Italy Chair).&lt;br /&gt;
&lt;br /&gt;
http://it.expandi-web.com/aruba/2019/aruba_oswap/form.html&lt;br /&gt;
== '''OWASP-Italy@Security Summit 2019''' ==&lt;br /&gt;
Thanks to CLUSIT, Giuseppe Trotta and Lorenzo De Meo had a talk at the OWASP-Italy corner during the Security Summit in Milan &amp;lt;br&amp;gt;&lt;br /&gt;
When: 14th March 2019 at 16:10-16:50&amp;lt;br&amp;gt;&lt;br /&gt;
Where: UNAHOTELS EXPO FIERA, via Keplero 12, Pero &amp;lt;br&amp;gt;&lt;br /&gt;
Please see the presentations here:&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/a/aa/OWASPCloudTestingMar19.pdf Federico De Meo: &amp;quot;Cloud Security Testing&amp;quot;]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[https://drive.google.com/file/d/1AU2zQXcy2Lnc1jI9UxYnkw1rKrDwPcYW/view Giuseppe Trotta: &amp;quot;New generation of phishing attacks&amp;quot;]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''OWASP-Italy Cagliari Day 2018 - 19th October 2018''' ==&lt;br /&gt;
Università di Cagliari.&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day Cagliari 2018|Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
=='''OWASP-Italy Day 2018 @ Milano 16th June 2018''' ==&lt;br /&gt;
Politecnico of Milano&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2018 ==&lt;br /&gt;
OWASP Italy did participate to the Security Summit 2018 in Milan with 2 talks.&amp;lt;br&amp;gt;More information here: [https://www.securitysummit.it/agenda-details/333 https://www.securitysummit.it/agenda-details/93]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day 2017 @ Cagliari 20th October 2017 ==&lt;br /&gt;
Cagliari , 6th October 2017, Università di Cagliari&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2017]]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 6th October 2017 ==&lt;br /&gt;
'''V Conference on Application Security and Modern Technologies'''&lt;br /&gt;
&lt;br /&gt;
Mestre, 6th October 2017, Università Ca' Foscari&lt;br /&gt;
&lt;br /&gt;
http://www.isaca.org/chapters5/Venice/Pages/default.aspx&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2017 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2017 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
Antonio Parata will give a talk on EyePyramid malware and Fabrizio Bugli will talk about (3rd) Party like nobody's watching&lt;br /&gt;
&lt;br /&gt;
https://www.securitysummit.it/agenda-details/93&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP AppSec Europe 2016 in Rome! ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASPAppSecEU2016.jpg]]&lt;br /&gt;
&lt;br /&gt;
OWASP is organizing the next OWASP AppSecEU in Rome.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;See the agenda and buy your ticket here:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
http://2016.appsec.eu/&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2016 ==&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2016 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2016/seminari-associazioni/talk-257/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Adopt OSS. First Edition ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy is pleased to announce a new initiative: '''Adopt''' '''O'''pen'''S'''ource'''S'''oftware&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Given OWASP’s mission to help organizations with application security, we have established a new initiative to provide free, voluntary-based support to open source software projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Thanks to Adopt OSS, security enthusiasts are paired with participating open source projects, thus gaining exposure to real-life security engineering challenges and the opportunity for career growth. In turn, the participating projects are able to obtain free professional expertise to better improve their security posture, and ultimately build secure software. Over a six months period, OWASP Italy will facilitate the effort by coordinating the initiative and providing support when needed.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The first edition of this initiative will take place between ''May and November 2015'', and will see the participation of '''7 OWASP Italy members''' and '''3 major OpenSource projects'''. At the end of the six months period, OWASP Italy will publish results and feedback from both volunteers and OSS maintainers.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The official flyer can be [https://www.owasp.org/images/0/07/AdoptOSSManifest-OWASPItaly.pdf downloaded from here].&lt;br /&gt;
&lt;br /&gt;
===Ntopng===&lt;br /&gt;
''Alessio Petracca, Mattia Folador, Giuseppe Longo''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.ntop.org/products/traffic-analysis/ntop/ Ntop] is the de-facto standard for real-time network traffic monitoring. OWASP Italy wants to help the project by increasing the security level of ntopng, performing security testing activities and supporting the remediation process.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will act in two steps:&lt;br /&gt;
* First, a penetration test targeting the web interface of ntopng will be performed, following the [https://www.owasp.org/index.php/OWASP_Testing_Guide_v3_Table_of_Contents OWASP Testing Methodology]&lt;br /&gt;
* Secondly, source code review of ntopng main components (such as the C++ core engine) will be statically reviewed. The objective is to address all relevant checks contained within the [https://www.owasp.org/index.php/OWASP_Code_review_V2_Table_of_Contents OWASP Code Review Guide]&lt;br /&gt;
&lt;br /&gt;
In case the activities above are completed before the end of the six-months period, additional activities (such as the development of security plugins) will be discussed.&lt;br /&gt;
Luca Deri and Arianna Avanzini will support Alessio Petracca and Mattia Folador in these activities, by providing guidance and insights.&lt;br /&gt;
&lt;br /&gt;
===WordPress===&lt;br /&gt;
''Paolo Perego, Sandro Zaccarini''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://wordpress.org/ WordPress] is the facto standard for web publishing. If you need a blog, if you need a new showcase website for your portfolio or a tiny e-commerce web site for your small company you will look at WordPress to start.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Paying the cost to be the boss, WordPress during the years suffered tons of security issues, 3 major issues only in the beginning of May 2015. Either the core, plugins and themes are developed with easy to use in mind and they need to be hardened.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Italy wants to support WordPress adopting it with the &amp;quot;Stand by WordPress&amp;quot; initiative. We will deploy the software in three different standard configurations: blog, company's portfolio and e-commerce.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will do continuous appsec during development of 4.3 version in order to quickly spot security issues before the August release. In addition, we will take care of hardening guidelines and both plugins and themes subsystems in order to improve the overall architecture.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You can follow the progress of the &amp;quot;Stand by WordPress&amp;quot; initiative here: https://standbywordpress.wordpress.com&lt;br /&gt;
&lt;br /&gt;
===GlobaLeaks===&lt;br /&gt;
''Luca Carettoni, Giovanni Cerrato, Marco Lancini''&lt;br /&gt;
&lt;br /&gt;
[https://www.globaleaks.org/ GlobaLeaks] is the first open-source whistleblowing framework. It empowers anyone to easily set up and maintain an anonymous whistleblowing platform.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Considering the potential hostile environments in which the application may be hosted, security vulnerabilities and abuses are primary concerns for GlobaLeaks’ maintainers.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We want to help the team in their excellent application security practices, by performing vulnerability research activities in order to discover unknown bugs within the boundaries of their specific [https://docs.google.com/document/d/1niYFyEar1FUmStC03OidYAIfVJf18ErUFwSWCmWBhcA/pub threat model]. In particular, we will be focusing on two main software components (GLBackend and GLClient) and new security-relevant changes (upcoming authentication re-factoring and end-to-end encryption).&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information on '''Adopt OSS''', please send an email to [mailto:owasp-italy@lists.owasp.org owasp-italy@lists.owasp.org]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2015 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2015 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2015/seminari-associazioni/talk-140/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Rome 11-12th December 2014 ==&lt;br /&gt;
The agenda is online! &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
http://www.isacaroma.it/images/owasp_agenda_11-12-12-2014.JPG&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 3rd October 2014 ==&lt;br /&gt;
The agenda: &amp;lt;br&amp;gt;&lt;br /&gt;
[[File:Venice2014.jpg]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Here is the [https://www.owasp.org/images/d/d3/OWASPVenice2014.pdf flyer]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day @ the University of Genova (14th May 2014) ==&lt;br /&gt;
Thank to the collaboration with [http://www.ai-lab.it/armando Prof. Alessandro Armando] and to the availability of Gary McGraw, Ph.D. CTO, Cigital we are planning an incredible [https://www.owasp.org/index.php/Italy_OWASP_Day_2014_Genova OWASP Day next 14th May].&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2014 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2014 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2014/seminari-associazioni/talk-34/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP EU Tour 2013 - 27th June - Rome==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;{{:EUTour2013 header}}&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with Università Degli Studi Roma Tre, next 27th June we will have the OWASP EU Tour Rome Conference.&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Europe TOUR, is an event across the European region that promotes awareness about application security, so that people and organizations can make informed decisions about true application security risks. &amp;lt;br&amp;gt;Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.&lt;br /&gt;
&lt;br /&gt;
The conference will be held at Università Degli Studi Roma Tre. Address: Via Vito Volterra, 62, Rome.&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/EUTour2013_Rome_Agenda Here you can find the agenda and all the information to participate]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2013 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy participated to the Security Summit 2013 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[http://milano2013.securitysummit.it/eventi/view/35 See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy Day 2012: &amp;quot;Web Security in a Mobile World&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;center&amp;gt;[[File:OWASPITDay2012.jpg]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Italy OWASP Italy chapter] will host the OWASP Italy Day 2012 conference in Rome, Italy at the University of Rome La Sapienza next 23rd November 2012.&lt;br /&gt;
&lt;br /&gt;
More information [https://www.owasp.org/index.php?title=Italy_OWASP_Day_2012 here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Board  ==&lt;br /&gt;
&lt;br /&gt;
*This is the '''OWASP-Italy Board''':&lt;br /&gt;
Founder and Chair: Matteo Meucci (Jan 2005)&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Italy Board: Paolo Perego, Luca Carettoni, Antonio Parata, Giorgio Fedon, Stefano Di Paola, Mauro Bregolin, Claudio Merloni, Raoul Chiesa.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Partnerships  ====&lt;br /&gt;
&lt;br /&gt;
*ISC2-Italian Chapter: Thanks to Marco Misitano, Paolo Ottolino and Claudio Sasso, OWASP Italy collaborates with the ISC2-Italian Chapter for new initiatives regarding Security Conferences, articles and contentes regarding SDLC.&lt;br /&gt;
&lt;br /&gt;
[http://www.isc2chapter-italy.it https://www.owasp.org/images/a/a3/ISC2Italy.jpg]&lt;br /&gt;
&lt;br /&gt;
*CSA Italy Partnership&lt;br /&gt;
&lt;br /&gt;
[http://chapters.cloudsecurityalliance.org/italy/ https://www.owasp.org/images/6/6a/CSAItalylogo.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Alberto Manfredi (CSA Italy President) we are starting a collaboration with the Italian Chapter of the Cloud Security Alliance.&lt;br /&gt;
&lt;br /&gt;
*IsecLab Partnership&lt;br /&gt;
&lt;br /&gt;
[http://www.iseclab.org http://www.owasp.org/images/4/4b/LogoIsecLab.png]&lt;br /&gt;
&lt;br /&gt;
We are beginning a collaboration with David Balzarotti and Marco Balduzzi of International Secure Systems Lab(IsecLab) with the goal of sharing and improving new WebAppSec projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*CLUSIT Member&lt;br /&gt;
&lt;br /&gt;
http://www.clusit.it/logo_clusit/clusit_logo_b130.gif &lt;br /&gt;
&lt;br /&gt;
Thanks to CLUSIT and OWASP Foundation we have established a cross-membership between the two organizations. So OWASP-Italy is now a [http://www.clusit.it/soci.htm CLUSIT member] and CLUSIT is an OWASP Educational Member.&lt;br /&gt;
&lt;br /&gt;
*ISACA Rome&lt;br /&gt;
&lt;br /&gt;
[http://www.isacaroma.it http://www.owasp.org/images/9/98/Isacaroma.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Ugo Spaziani, we are developing seminars and new ideas with ISACA Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2012 ==&lt;br /&gt;
- 21st March 2012, OWASP Italy will present 3 talks:&lt;br /&gt;
&lt;br /&gt;
- Antonio Parata e Paolo Perego:&amp;quot;Security Testing for developers&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;Banking Malware evolution in Italy: defense approach&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Stefano Di Paola:&amp;quot;DOM Xss: la nuova generazione di vulnerabilità applicative&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
Please subscribe for free here: https://www.securitysummit.it/eventi/view/21&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2011 ==&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''OWASP Books are out!'''&lt;br /&gt;
&lt;br /&gt;
Now you can download or buy a book on the OWASP Projects. Check it here: http://stores.lulu.com/owasp &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Activities  ====&lt;br /&gt;
&lt;br /&gt;
*(Jun 10): OWASP Testing Guide presentation at FBK (Fondazione Bruno Kessler). &lt;br /&gt;
&lt;br /&gt;
*(May 10): OWASP Training at London: last 28th May in London, OWASP leaders deliver a course focused on the main OWASP Projects. This course aims to change that by providing a selection of mature and enterprise ready projects together with practical examples of how to use them. &lt;br /&gt;
This Course was FREE for OWASP Members. &lt;br /&gt;
http://www.owasp.org/index.php/London/Training/OWASP_projects_and_resources_you_can_use_TODAY&lt;br /&gt;
&lt;br /&gt;
*(Jan 09) OWASP Testing Guide v3 is finished! You can download or browse it [http://www.owasp.org/index.php/Category:OWASP_Testing_Project here]&lt;br /&gt;
&lt;br /&gt;
*(Mar 07) Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) )&lt;br /&gt;
&lt;br /&gt;
[http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
*(Oct 06) ISACA Roma has published several interview with OWASP-Italy members:&lt;br /&gt;
&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli]] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/328 Carlo Pelliccioni]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Paolo Perego has created the new '''OWASP Orizon Project'''. Go to [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Matteo Meucci has been selected as the new editor of the '''OWASP Testing Guide v2'''. See OWASP [http://www.owasp.org/index.php/OWASP_Autumn_Of_Code_2006_:_Selected_Projects_Press_Release press release] and go to [http://www.owasp.org/index.php/OWASP_Autumn_of_Code_2006_-_Projects:_Testing_Guide OWASP Testing Project v2]&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Carlo Pelliccioni is writing an article about the [http://www.owasp.org/index.php/Analysis_about_error_codes analysis of error codes] received by web servers.&lt;br /&gt;
&lt;br /&gt;
*Top10 Vulnerabilities - OWASP-Italy survey:&lt;br /&gt;
&lt;br /&gt;
[[Image:Top 10 vulnerabilities-mini.GIF]] &lt;br /&gt;
&lt;br /&gt;
*(21 Jun 06) '''Infosecurity 2006''': the event is organized and managed by the CLUSIT.&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. [http://www.infosecurity.it/Roma/programma.php More info here] &lt;br /&gt;
&lt;br /&gt;
*(1 Jun 06) '''&amp;quot;Quaderno CLUSIT&amp;quot;'''&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but will be made public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
*(31 May 06) Luca Carettoni has published the article '''&amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;.''' [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article.&lt;br /&gt;
&lt;br /&gt;
*(1 Mar 06) '''OWASP-Boston, Microsoft'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler, Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting. [http://www.owasp.org/local/boston.html More info here] &lt;br /&gt;
&lt;br /&gt;
*(18 Nov 05) '''IDC - European Banking Forum'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we will have a great speech at the [http://www.idc.com/italy/events/banking05/banking05_agenda.jsp IDC European IT Banking Forum 2005]. Agenda: - New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair - Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy &lt;br /&gt;
&lt;br /&gt;
*(Oct 05) '''SMAU 2005''' is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy.&lt;br /&gt;
&lt;br /&gt;
SMAU has accepted our submission! [http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili More info here] &lt;br /&gt;
&lt;br /&gt;
*(Giu 05) Thanks to Massimiliano Graziani we have translated in italian the '''&amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;'''. You can download it [http://www.owasp.org/documentation/testing.html here.]&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
*(May 05) '''ISACA Roma Newsletter''' has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005.&lt;br /&gt;
&lt;br /&gt;
*The presentation of the seminar we have done in '''ISACA Rome''' (31th March 2005) is now available [http://www.isacaroma.it/pdf/050331/meucci.zip here.]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)].&lt;br /&gt;
&lt;br /&gt;
*(Mar 05) Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here].&lt;br /&gt;
&lt;br /&gt;
*[http://www.isacaroma.it/html/newsletter/?q=node/78 Here] you can read an interview talking about OWASP. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Events  ====&lt;br /&gt;
&lt;br /&gt;
=== 15th March, 2011 - OWASP-Italy@Security Summit ===&lt;br /&gt;
&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
=== November, 2010 - OWASP-Italy Day V  ===&lt;br /&gt;
&lt;br /&gt;
- OWASP Day for E-Gov 2010: 9th November 2010 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
An event organized by Consip. More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_10 here]&lt;br /&gt;
&lt;br /&gt;
=== November, 2009 - OWASP-Italy Day IV  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Following on from the great success of last OWASP Days the forth conference has taken place in November 2009 in Milan. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_4 here]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Day for E-Gov 2009: 5th November 2009 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_09 here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2009 - OWASP-Italy @ PCI Milan  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Testing Guide and PCI-DSS Standard at the [http://www.pci-portal.com/lang-en/events/event-info/pcimilan PCI Milan event] last 31st March. &lt;br /&gt;
&lt;br /&gt;
The presentation is published [http://www.owasp.org/images/3/38/MeucciPciMilan09.pdf here] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 23rd February, 2009 - OWASP Day III  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_3 &amp;quot;Web Application Security: research meets industry&amp;quot;] &amp;lt;br&amp;gt; Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== 10th October, 2008 - Isaca Roma PCM 2008 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci presented the new OWASP Projects and the Application Security in the Italian Companies. More information [http://www.isacaroma.it/html/ArchivioEventi-081010.html here] &lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2008 - OWASP Day II  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_2 &amp;quot;The State of the Art of the Web Application Security and the OWASP guidelines in the Companies&amp;quot;] Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== February 2008 - OWASP Italy at InfoSecurity 2008  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
5th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - The Owasp Orizon project: internals and hands on&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_94.aspx Paolo Perego] &lt;br /&gt;
&lt;br /&gt;
6th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - Costruire Software Sicuro dalle Fondamenta&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_128.aspx Antonio Parata] &lt;br /&gt;
&lt;br /&gt;
7th February: &lt;br /&gt;
&lt;br /&gt;
*10:30 - Tu programmi. Io buco.&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_137.aspx Luca Carettoni] &lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it Here] you can read more information about it. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== November 30th, 2007 - OWASP-Italy @ Elsag Datamat Security Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Guidelines and SDLC Security at the Elsag Datamat Security Forum 2007 &amp;lt;br&amp;gt;Where: Pescara &amp;lt;br&amp;gt;When: 30th November 2007, h.12.30 &lt;br /&gt;
&lt;br /&gt;
=== October 20th, 2007 - OWASP Italy at SMAU E-Academy 2007  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Last 20th October 2007 we had 5 speeches at SMAU E-Academy 2007, here you can download our presentations: &lt;br /&gt;
&lt;br /&gt;
*Giorgio Fedon, COO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/.pdf &amp;quot;Dove sono finiti i miei soldi? Internet Banking e Cross Site Scripting&amp;quot;] (coming soon) [[Image:FedonSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Paolo Perego, Senior Security Consultant at Spike Reply:&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/7/79/PeregoSMAU07.ppt &amp;quot;The Owasp Orizon project - bring security at the source&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Antonio Parata, Security Consultant at eMaze:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Valutazione del rischio tramite la logica fuzzy&amp;quot; (coming soon) [[Image:ParataSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Alberto Revelli, Senior Security Consultant at Portcullis Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/9/9f/RevelliSMAU07.pdf &amp;quot;Anti-Anti-XSS: bypass delle difese del browser&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, CTO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Cros-site Flashing! Gli attacchi Web di ultima generazione parlano multipiattaforma&amp;quot; (coming soon) [[Image:DiPaolaSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== September 10th, 2007 - OWASP Day WorldWide: &amp;quot;Privacy in the 21st Century&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Italy_OWASP_Day_1 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 29th, 2007 - Seminar: &amp;quot;Software Security&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, Paolo Perego and Matteo Meucci will talk at the Seminar: [http://www.sicurinfo.it/informazioni/visinf.asp?IDInfo=246&amp;amp;CAT=53 &amp;quot;Which approaches to Software Security&amp;quot;] organized by Firenze Tecnologia.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 15th-17th, 2007 - 6th OWASP AppSec Conference in Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We are in the initial planning stages for the next OWASP Europe conference, which we plan to hold in Italy in May 2007.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/6th_OWASP_AppSec_Conference_-_Italy_2007 Here] you can find all the details about the conference, cfp and sponsorship. &lt;br /&gt;
&lt;br /&gt;
=== April 14th, 2007 - Master on Information Security, University of Rome &amp;quot;La Sapienza&amp;quot; ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We have done a 4h seminar for the students of [http://mastersicurezza.uniroma1.it/ Master on Information Security at &amp;quot;La Sapienza&amp;quot;] for the [http://icsecurity.di.uniroma1.it/dokuwiki/doku.php?id=projects:asp Application Security Project of &amp;quot;La Sapienza&amp;quot; University.]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 30th, 2007 - University of Rome &amp;quot;La Sapienza&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Thanks to Prof. Mancini and Roberto D'Addario, we will talk about OWASP at the convention &amp;quot;Institutions, Companies and Information Security: comparing the problems&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[http://w3.uniroma1.it/security/Eventi/eventi.html Here] you can find more details. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2007 - EuSecWest 07  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci presented the new OWASP Testing Guide at [http://www.eusecwest.com/agenda.html EUSecWest]. [http://www.owasp.org/images/e/e9/OWASP_Testing_Guide_Presentation_EUSecWest07.zip Here] you take a look at the presentation. &lt;br /&gt;
&lt;br /&gt;
=== February 6th-8th, 2007 - InfoSecurity  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*February 6th:15.30&lt;br /&gt;
&lt;br /&gt;
After the great success obtained form CCC at Berlin, Stefano Di Paola and Giorgio Fedon will talk about:&amp;quot; Web Security Client Side: attacks at Web 2.0&amp;quot; More information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=aqfi82GOKd6I748s1evI8Q%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 6th:16.30&lt;br /&gt;
&lt;br /&gt;
After the great effort on the Testing Guide Project, Matteo Meucci and Alberto Revelli will present: &amp;quot;The new OWASP Testing Guide&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=nq6tSIuRoPVJBanBSsRiSQ%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 7th:12.30&lt;br /&gt;
&lt;br /&gt;
Authors of innovative SQL injection tools, Alberto Revelli and Antonio Parata will show: &amp;quot;Advanced SQL Injection: testing tools and defensive strategies.&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=3z04F5BgZRgfU0YX8JRYtA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here] &lt;br /&gt;
&lt;br /&gt;
*February 7th:13.30&lt;br /&gt;
&lt;br /&gt;
Author of the new OWASP Orizon project, Paolo Perergo will present:&amp;quot;Secure programming: from theory to practice&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=9HePIzyo5p29ylpGBl6CiA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
=== January 25th, 2007 - Isaca Rome  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci will discuss the new [http://www.owasp.org/index.php/Category:OWASP_Testing_Project OWASP Testing Guide v2]&amp;lt;br&amp;gt; For more information:&amp;lt;br&amp;gt; http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
=== October 7th, 2006 - SMAU 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''The quest for secure code: code review and fundamental of secure coding.''&amp;quot; Matteo Meucci will present an introduction to the new OWASP Projects and OWASP-Italy activities. Paolo Perego (sp0nge) will speak about safe coding and the importance of code periodic review as natural software life cycle. Paolo will give a vision on code review and its phases http://www.webb.it/event/eventview/5772 &lt;br /&gt;
&lt;br /&gt;
Here are the presentations: &amp;lt;br&amp;gt; [[Image:Meucci SMAU06.pdf|Meucci_SMAU06]] &amp;lt;br&amp;gt; [[Image:Perego SMAU06.pdf|Perego_SMAU 06]] &lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''Advanced SQL Injection.''&amp;quot; Antonio Parata (S4tan) will explain SQL Injection, and how SQL Inference works on PHP/MySql platform. He will present an open source tool to support the testing. Alberto Revelli (icesurfer) will focus on Microsoft SQL Server: he will perform a live demo of sqlninja (http://sqlninja.sf.net), explaining how to obtain a pseudo-shell over SQL, how to escalate privileges, and how to play with the exotic equation: &amp;quot;SQL Injection + debug.exe + DNS = DOS prompt&amp;quot;&amp;amp;nbsp;! http://www.webb.it/event/eventview/5774 &lt;br /&gt;
&lt;br /&gt;
[[Image:Revelli SMAU06.pdf|Revelli_SMAU06]] &amp;lt;br&amp;gt; [[Image:Parata SMAU06.pdf|Parate_SMAU06]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP-Italy at SMAU06 2.JPG]] Luca, Carlo, Alberto, Antonio, Stefano &amp;lt;br&amp;gt; Matteo, Paolo, Giorgio &lt;br /&gt;
&lt;br /&gt;
=== September 29th, 2006 - OpenExp 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
September 30th, at 10:45 Antonio Parata (S4tan) will speak about SQL Injection: techniques, tools and practical examples. &lt;br /&gt;
&lt;br /&gt;
Abstract: Antonio will introduce some basic concepts about software security. It will be shown how SQL Inference works on PHP/MySql platform and presented an open source tool to support the testing. Finally will be listed some advises to avoid common bugs. http://www.openexp.it/ &lt;br /&gt;
&lt;br /&gt;
OWASP-Italy will have a stand from September 29th to October 1st. &lt;br /&gt;
&lt;br /&gt;
[[Image:Antonio Matteo Carlo.JPG]] [[Image:Antonio speech.JPG]] [[Image:Carlo.JPG]] [[Image:Claudio Luca.JPG]] [[Image:Mayhem Matteo.JPG]] [[Image:OWASP Banner2.JPG]] [[Image:OWASP Banner.JPG]] &lt;br /&gt;
&lt;br /&gt;
=== June 21th, 2006 - InfoSecurity 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. The event is organized and managed by the CLUSIT. &lt;br /&gt;
&lt;br /&gt;
Where: Sheraton Roma Hotel - Viale Del Pattinaggio, 100 When: 10,30 - 17,00 Who: Matteo Meucci and Alberto Revelli Link: http://www.infosecurity.it/Roma/programma.php &lt;br /&gt;
&lt;br /&gt;
Agenda: -- I Session -- Introduction to Web Application Security • Which are the risks? • Risk assessment of a web application • Core pillars of web security How to develop secure web applications: • Guidelines and case-studies &lt;br /&gt;
&lt;br /&gt;
-- II Session -- How to realize a security audit of a web application • The methodology OWASP Penetration Testing • The tools: OWASP WebScarab • Hands-on web application vulnerabilities: OWASP WebGoat • Advanced SQL Injection. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2006 - OWASP-Boston, Microsoft  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler (OWASP-Boston Chair), Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting of march. [http://www.owasp.org/index.php/Boston More info here] &lt;br /&gt;
&lt;br /&gt;
=== November 5th, 2005 - IDC - European Banking Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we have had a great speech at the IDC European IT Banking Forum 2005 (18 Nov 2005). http://www.idc.com/italy/events/banking05/banking05_agenda.jsp Agenda: &lt;br /&gt;
&lt;br /&gt;
*New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair &lt;br /&gt;
*Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy.&lt;br /&gt;
&lt;br /&gt;
You can download the report [http://cdn.idc.com/italy/downloads/report_banking05_eng.pdf here]. &lt;br /&gt;
&lt;br /&gt;
You can download the Case-Study of a vulnerable Home Banking Web Application [http://www.owasp.org/docroot/owasp/misc/IDC_BankingForum05v1.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== October 5th, 2005 - OWASP-Italy@SMAU2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
SMAU is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy. Alberto Revelli (our Technical Director) and Matteo Meucci have conducted a seminar talking about Web Application Security. Alberto has presented his new project: [http://sqlninja.sourceforge.net sqlninja]. Very cool!! &lt;br /&gt;
&lt;br /&gt;
http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili &lt;br /&gt;
&lt;br /&gt;
=== May 25th, 2005 - ISACA Rome 2nd meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
May 25th we'll be in ISACA Rome to present OWASP WebGoat and a real case of a Web Application Vulnerability. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.30 Registration 14.45 Matteo Meucci - Web Application Security Phase II - OWASP WebScarab and PenTest Checklist &lt;br /&gt;
&lt;br /&gt;
*A case-study of a Web Application Vulnerability: MMS Spoofing&lt;br /&gt;
&lt;br /&gt;
--- Web Application analysis --- Authentication and Billing of the MMS service --- Vulnerabilities --- Attack Analysis &lt;br /&gt;
&lt;br /&gt;
*Learning the most common web application vulnerabilities: OWASP WebGoat&lt;br /&gt;
&lt;br /&gt;
--- Http Basics --- HTML Clues --- Hidden Field Tampering --- How to spoof a Session Cookie --- Stored Cross Site Scripting --- Command Injection --- SQL Injection --- Fail Open Authentication &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050525/OWASP.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== May 18th, 2005 - Workshop on Computer Crime 2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; May 18th, 2005 OWASP-Italy is invited to present OWASP Top 10 to the &amp;quot;Workshop on Computer Crime 2005&amp;quot; titled: &amp;quot;EVOLUZIONI NORMATIVE E RECENTI PROBLEMATICHE DI SICUREZZA&amp;quot; &lt;br /&gt;
&lt;br /&gt;
The meeting is held at: Sala delle conferenze dell'Istituto Centrale della Banche Popolari Italiane Via Verziere, 11 &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.owasp.org/images/a/aa/Top10-ComputerCrimes.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== March 31th, 2005 - ISACA Rome meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March 31th we'll be in ISACA Rome to present OWASP and the Web Application Security. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.15 Registration 14.30 Matteo Meucci - Web Application Security - OWASP Guide: how to build secure web application - How to test your Web Application: WebScarab and the WebApp PenTest Checklist - How to learn the most common web application vulnerability: WebGoat - The Top Ten WebApp vulnerabilities - Common error on developing Web Application: Authentication mechanisms not &amp;quot;secure&amp;quot; Buffer Overflow and crash of the service Thief of identity: Cross Site Scripting Manipulation of company data: SQL Injection Reserved information: misconfiguration Bad session management and thief of identity - OWASP-Italy: projects and next challenges &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050331/meucci.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== March 21th, 2005 - OWASP-Italy conducts a seminar in AlmaWeb  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March, the 21th OWASP-Italy has been invited at the University of Bologna to conduct a seminar regards to [http://www.almaweb.unibo.it/830.dyn Master in Management and Information Technology] titled “Web Application Security and OWASP”. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: - OWASP &amp;amp;amp; Web Application Security - Common Web Application Vulnerabilities - A real case of web application vulnerability: MMS Spoofing&amp;amp;amp;Billing - Training: WebGoat &lt;br /&gt;
&lt;br /&gt;
==== Publications  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== October 2009 Interview on &amp;quot;Il sole 24 ore&amp;quot;  ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/5/5c/Nova09.pdf Gary McGraw and Matteo Meucci] interviewed by NOVA, talking about BSIMM and OWASP.&lt;br /&gt;
&lt;br /&gt;
=== March, 2007 Interview on HTML.it  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) ) [http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
=== October, 2006 ISACA Roma interviews OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
After the speeches that OWASP-Italy has done at [http://www.smau.it/catnews.asp?l=2&amp;amp;codcat=385 SMAU E-Academy 2006], ISACA Roma has interviewed some of the people of the Italian chapter. Follow the links for the full interviews (in italian): &amp;lt;br&amp;gt; [[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli] ] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/322 Stefano Di Paola &amp;amp; Giorgio Fedon]] &lt;br /&gt;
&lt;br /&gt;
=== Aug, 2006 - Article on Banca Finanza magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Banca Finanza, the italian magazine about finance and banking, has interviewed Raoul Chiesa talking about the new risks for the on-line banking security. Raoul speaks about OWASP and web application security [[Media:042006BF.pdf]] &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Quaderno CLUSIT  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but it will be public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Paper on SQL Injection and Inference on PHP/MySQLInference  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Antonio &amp;quot;s4tan&amp;quot; Parata has published an article about SQL Injection based on Inference for testing web application on PHP/MySQL platform. [http://www.ictsc.it/papers/sqlInferenceOnMySql.html Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== May, 2006 - Published an article about OWASP and Top-10 Vulnerabilities  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published the article &amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;. [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== June, 2005 - OWASP Pen Test Checklist v 1.1 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Massimiliano Graziani we have translated in italian the &amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;. You can download it [http://www.owasp.org/documentation/testing.html here.] Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
=== May, 2005 - Isaca Roma Newsletter about OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
ISACA Roma Newsletter has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy] &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published &amp;quot;MMS Spoofing&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)]. &lt;br /&gt;
&lt;br /&gt;
Jim Hewitt, CISSP PMP working at CGI-AMS, affirms (slide#78): &amp;quot;Very interesting analysis of spoofed cell phone messaging and fraudulent billing&amp;quot;. See: www.techvalleynyissa.org/Resources/2005_07_WebApplicationSecurity.ppt &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published an article on ICT Security magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005. &lt;br /&gt;
&lt;br /&gt;
=== March, 2005 - OWASP Top-10 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here]. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
==== Tools &amp;amp;amp; Research  ====&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Nov, 2007 - sqlmap v0.5  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released the fifth versions of the tool [http://sqlmap.sourceforge.net sqlmap]. sqlmap is an automatic SQL injection tool entirely developed in Python. It is capable to perform an extensive database management system back-end fingerprint, retrieve remote DBMS databases, usernames, tables, columns, enumerate entire DBMS, read system files and much more taking advantage of web application programming security flaws that lead to SQL injection vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
You can download the latest stable version from its [https://sourceforge.net/project/showfiles.php?group_id=171598&amp;amp;package_id=196107 SourceForge File List page] or the latest development version from its [https://sqlmap.svn.sourceforge.net/svnroot/sqlmap SourceForge SVN repository]. &lt;br /&gt;
&lt;br /&gt;
=== Dec, 2006 - sqlmap v0.2  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released a second version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://sqlmap.sourceforge.net/ Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
=== September, 2006 - Wisec Project  ===&lt;br /&gt;
&lt;br /&gt;
Stefano Di Paola is developing Wisec - The Wiki Security Project [http://www.wisec.it Here] you can accesses the project. &lt;br /&gt;
&lt;br /&gt;
=== July, 2006 - Sqlmap v0.0.1  ===&lt;br /&gt;
&lt;br /&gt;
Daniele Bellucci has developed a first version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://www.linux.it/~belch/?p=17 Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Chapter]]&lt;br /&gt;
[[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy&amp;diff=249131</id>
		<title>Italy</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy&amp;diff=249131"/>
				<updated>2019-03-21T16:01:05Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[Image:OWASP-Italy.PNG]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== WELCOME  ====&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Italy|extra=The chapter leader is [mailto:matteo.meucci@owasp.org Matteo Meucci]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-italy|emailarchives=http://lists.owasp.org/pipermail/owasp-italy}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Italy&amp;lt;/paypal&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''NEXT EVENT: OWASP/WIA initiatives - 26th March 2019''' ==&lt;br /&gt;
Thanks to Loredana Mancini and Zoe Braiterman we will have an OWASP-Italy /WIA initiatives at the Link Campus in Rome next 26th March.&amp;lt;br&amp;gt;&lt;br /&gt;
Venue: Link Campus University Via del Casale di San Pio V, 44 - 00165 Roma (RM)&lt;br /&gt;
&lt;br /&gt;
Speakers: Prof.ssa Paola Giannetakis (Link Campus University), Zoe Braiterman (OWASP/WIA Chair), Luciana Scognamiglio (Senior security expert /HPE), Matteo Meucci (OWASP-Italy Chair).&lt;br /&gt;
&lt;br /&gt;
http://it.expandi-web.com/aruba/2019/aruba_oswap/form.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''OWASP-Italy@Security Summit 2019''' ==&lt;br /&gt;
Thanks to CLUSIT, Giuseppe Trotta and Lorenzo De Meo had a talk at the OWASP-Italy corner during the Security Summit in Milan &amp;lt;br&amp;gt;&lt;br /&gt;
When: 14th March 2019 at 16:10-16:50&amp;lt;br&amp;gt;&lt;br /&gt;
Where: UNAHOTELS EXPO FIERA, via Keplero 12, Pero &amp;lt;br&amp;gt;&lt;br /&gt;
Please see the presentations here:&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/a/aa/OWASPCloudTestingMar19.pdf Federico De Meo: &amp;quot;Cloud Security Testing&amp;quot;]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[https://drive.google.com/file/d/1AU2zQXcy2Lnc1jI9UxYnkw1rKrDwPcYW/view Giuseppe Trotta: &amp;quot;New generation of phishing attacks&amp;quot;]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''OWASP-Italy Cagliari Day 2018 - 19th October 2018''' ==&lt;br /&gt;
Università di Cagliari.&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day Cagliari 2018|Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
=='''OWASP-Italy Day 2018 @ Milano 16th June 2018''' ==&lt;br /&gt;
Politecnico of Milano&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2018 ==&lt;br /&gt;
OWASP Italy did participate to the Security Summit 2018 in Milan with 2 talks.&amp;lt;br&amp;gt;More information here: [https://www.securitysummit.it/agenda-details/333 https://www.securitysummit.it/agenda-details/93]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day 2017 @ Cagliari 20th October 2017 ==&lt;br /&gt;
Cagliari , 6th October 2017, Università di Cagliari&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2017]]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 6th October 2017 ==&lt;br /&gt;
'''V Conference on Application Security and Modern Technologies'''&lt;br /&gt;
&lt;br /&gt;
Mestre, 6th October 2017, Università Ca' Foscari&lt;br /&gt;
&lt;br /&gt;
http://www.isaca.org/chapters5/Venice/Pages/default.aspx&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2017 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2017 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
Antonio Parata will give a talk on EyePyramid malware and Fabrizio Bugli will talk about (3rd) Party like nobody's watching&lt;br /&gt;
&lt;br /&gt;
https://www.securitysummit.it/agenda-details/93&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP AppSec Europe 2016 in Rome! ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASPAppSecEU2016.jpg]]&lt;br /&gt;
&lt;br /&gt;
OWASP is organizing the next OWASP AppSecEU in Rome.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;See the agenda and buy your ticket here:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
http://2016.appsec.eu/&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2016 ==&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2016 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2016/seminari-associazioni/talk-257/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Adopt OSS. First Edition ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy is pleased to announce a new initiative: '''Adopt''' '''O'''pen'''S'''ource'''S'''oftware&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Given OWASP’s mission to help organizations with application security, we have established a new initiative to provide free, voluntary-based support to open source software projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Thanks to Adopt OSS, security enthusiasts are paired with participating open source projects, thus gaining exposure to real-life security engineering challenges and the opportunity for career growth. In turn, the participating projects are able to obtain free professional expertise to better improve their security posture, and ultimately build secure software. Over a six months period, OWASP Italy will facilitate the effort by coordinating the initiative and providing support when needed.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The first edition of this initiative will take place between ''May and November 2015'', and will see the participation of '''7 OWASP Italy members''' and '''3 major OpenSource projects'''. At the end of the six months period, OWASP Italy will publish results and feedback from both volunteers and OSS maintainers.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The official flyer can be [https://www.owasp.org/images/0/07/AdoptOSSManifest-OWASPItaly.pdf downloaded from here].&lt;br /&gt;
&lt;br /&gt;
===Ntopng===&lt;br /&gt;
''Alessio Petracca, Mattia Folador, Giuseppe Longo''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.ntop.org/products/traffic-analysis/ntop/ Ntop] is the de-facto standard for real-time network traffic monitoring. OWASP Italy wants to help the project by increasing the security level of ntopng, performing security testing activities and supporting the remediation process.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will act in two steps:&lt;br /&gt;
* First, a penetration test targeting the web interface of ntopng will be performed, following the [https://www.owasp.org/index.php/OWASP_Testing_Guide_v3_Table_of_Contents OWASP Testing Methodology]&lt;br /&gt;
* Secondly, source code review of ntopng main components (such as the C++ core engine) will be statically reviewed. The objective is to address all relevant checks contained within the [https://www.owasp.org/index.php/OWASP_Code_review_V2_Table_of_Contents OWASP Code Review Guide]&lt;br /&gt;
&lt;br /&gt;
In case the activities above are completed before the end of the six-months period, additional activities (such as the development of security plugins) will be discussed.&lt;br /&gt;
Luca Deri and Arianna Avanzini will support Alessio Petracca and Mattia Folador in these activities, by providing guidance and insights.&lt;br /&gt;
&lt;br /&gt;
===WordPress===&lt;br /&gt;
''Paolo Perego, Sandro Zaccarini''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://wordpress.org/ WordPress] is the facto standard for web publishing. If you need a blog, if you need a new showcase website for your portfolio or a tiny e-commerce web site for your small company you will look at WordPress to start.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Paying the cost to be the boss, WordPress during the years suffered tons of security issues, 3 major issues only in the beginning of May 2015. Either the core, plugins and themes are developed with easy to use in mind and they need to be hardened.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Italy wants to support WordPress adopting it with the &amp;quot;Stand by WordPress&amp;quot; initiative. We will deploy the software in three different standard configurations: blog, company's portfolio and e-commerce.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will do continuous appsec during development of 4.3 version in order to quickly spot security issues before the August release. In addition, we will take care of hardening guidelines and both plugins and themes subsystems in order to improve the overall architecture.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You can follow the progress of the &amp;quot;Stand by WordPress&amp;quot; initiative here: https://standbywordpress.wordpress.com&lt;br /&gt;
&lt;br /&gt;
===GlobaLeaks===&lt;br /&gt;
''Luca Carettoni, Giovanni Cerrato, Marco Lancini''&lt;br /&gt;
&lt;br /&gt;
[https://www.globaleaks.org/ GlobaLeaks] is the first open-source whistleblowing framework. It empowers anyone to easily set up and maintain an anonymous whistleblowing platform.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Considering the potential hostile environments in which the application may be hosted, security vulnerabilities and abuses are primary concerns for GlobaLeaks’ maintainers.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We want to help the team in their excellent application security practices, by performing vulnerability research activities in order to discover unknown bugs within the boundaries of their specific [https://docs.google.com/document/d/1niYFyEar1FUmStC03OidYAIfVJf18ErUFwSWCmWBhcA/pub threat model]. In particular, we will be focusing on two main software components (GLBackend and GLClient) and new security-relevant changes (upcoming authentication re-factoring and end-to-end encryption).&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information on '''Adopt OSS''', please send an email to [mailto:owasp-italy@lists.owasp.org owasp-italy@lists.owasp.org]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2015 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2015 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2015/seminari-associazioni/talk-140/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Rome 11-12th December 2014 ==&lt;br /&gt;
The agenda is online! &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
http://www.isacaroma.it/images/owasp_agenda_11-12-12-2014.JPG&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 3rd October 2014 ==&lt;br /&gt;
The agenda: &amp;lt;br&amp;gt;&lt;br /&gt;
[[File:Venice2014.jpg]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Here is the [https://www.owasp.org/images/d/d3/OWASPVenice2014.pdf flyer]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day @ the University of Genova (14th May 2014) ==&lt;br /&gt;
Thank to the collaboration with [http://www.ai-lab.it/armando Prof. Alessandro Armando] and to the availability of Gary McGraw, Ph.D. CTO, Cigital we are planning an incredible [https://www.owasp.org/index.php/Italy_OWASP_Day_2014_Genova OWASP Day next 14th May].&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2014 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2014 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2014/seminari-associazioni/talk-34/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP EU Tour 2013 - 27th June - Rome==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;{{:EUTour2013 header}}&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with Università Degli Studi Roma Tre, next 27th June we will have the OWASP EU Tour Rome Conference.&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Europe TOUR, is an event across the European region that promotes awareness about application security, so that people and organizations can make informed decisions about true application security risks. &amp;lt;br&amp;gt;Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.&lt;br /&gt;
&lt;br /&gt;
The conference will be held at Università Degli Studi Roma Tre. Address: Via Vito Volterra, 62, Rome.&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/EUTour2013_Rome_Agenda Here you can find the agenda and all the information to participate]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2013 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy participated to the Security Summit 2013 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[http://milano2013.securitysummit.it/eventi/view/35 See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy Day 2012: &amp;quot;Web Security in a Mobile World&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;center&amp;gt;[[File:OWASPITDay2012.jpg]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Italy OWASP Italy chapter] will host the OWASP Italy Day 2012 conference in Rome, Italy at the University of Rome La Sapienza next 23rd November 2012.&lt;br /&gt;
&lt;br /&gt;
More information [https://www.owasp.org/index.php?title=Italy_OWASP_Day_2012 here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Board  ==&lt;br /&gt;
&lt;br /&gt;
*This is the '''OWASP-Italy Board''':&lt;br /&gt;
Founder and Chair: Matteo Meucci (Jan 2005)&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Italy Board: Paolo Perego, Luca Carettoni, Antonio Parata, Giorgio Fedon, Stefano Di Paola, Mauro Bregolin, Claudio Merloni, Raoul Chiesa.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Partnerships  ====&lt;br /&gt;
&lt;br /&gt;
*ISC2-Italian Chapter: Thanks to Marco Misitano, Paolo Ottolino and Claudio Sasso, OWASP Italy collaborates with the ISC2-Italian Chapter for new initiatives regarding Security Conferences, articles and contentes regarding SDLC.&lt;br /&gt;
&lt;br /&gt;
[http://www.isc2chapter-italy.it https://www.owasp.org/images/a/a3/ISC2Italy.jpg]&lt;br /&gt;
&lt;br /&gt;
*CSA Italy Partnership&lt;br /&gt;
&lt;br /&gt;
[http://chapters.cloudsecurityalliance.org/italy/ https://www.owasp.org/images/6/6a/CSAItalylogo.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Alberto Manfredi (CSA Italy President) we are starting a collaboration with the Italian Chapter of the Cloud Security Alliance.&lt;br /&gt;
&lt;br /&gt;
*IsecLab Partnership&lt;br /&gt;
&lt;br /&gt;
[http://www.iseclab.org http://www.owasp.org/images/4/4b/LogoIsecLab.png]&lt;br /&gt;
&lt;br /&gt;
We are beginning a collaboration with David Balzarotti and Marco Balduzzi of International Secure Systems Lab(IsecLab) with the goal of sharing and improving new WebAppSec projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*CLUSIT Member&lt;br /&gt;
&lt;br /&gt;
http://www.clusit.it/logo_clusit/clusit_logo_b130.gif &lt;br /&gt;
&lt;br /&gt;
Thanks to CLUSIT and OWASP Foundation we have established a cross-membership between the two organizations. So OWASP-Italy is now a [http://www.clusit.it/soci.htm CLUSIT member] and CLUSIT is an OWASP Educational Member.&lt;br /&gt;
&lt;br /&gt;
*ISACA Rome&lt;br /&gt;
&lt;br /&gt;
[http://www.isacaroma.it http://www.owasp.org/images/9/98/Isacaroma.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Ugo Spaziani, we are developing seminars and new ideas with ISACA Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2012 ==&lt;br /&gt;
- 21st March 2012, OWASP Italy will present 3 talks:&lt;br /&gt;
&lt;br /&gt;
- Antonio Parata e Paolo Perego:&amp;quot;Security Testing for developers&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;Banking Malware evolution in Italy: defense approach&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Stefano Di Paola:&amp;quot;DOM Xss: la nuova generazione di vulnerabilità applicative&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
Please subscribe for free here: https://www.securitysummit.it/eventi/view/21&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2011 ==&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''OWASP Books are out!'''&lt;br /&gt;
&lt;br /&gt;
Now you can download or buy a book on the OWASP Projects. Check it here: http://stores.lulu.com/owasp &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Activities  ====&lt;br /&gt;
&lt;br /&gt;
*(Jun 10): OWASP Testing Guide presentation at FBK (Fondazione Bruno Kessler). &lt;br /&gt;
&lt;br /&gt;
*(May 10): OWASP Training at London: last 28th May in London, OWASP leaders deliver a course focused on the main OWASP Projects. This course aims to change that by providing a selection of mature and enterprise ready projects together with practical examples of how to use them. &lt;br /&gt;
This Course was FREE for OWASP Members. &lt;br /&gt;
http://www.owasp.org/index.php/London/Training/OWASP_projects_and_resources_you_can_use_TODAY&lt;br /&gt;
&lt;br /&gt;
*(Jan 09) OWASP Testing Guide v3 is finished! You can download or browse it [http://www.owasp.org/index.php/Category:OWASP_Testing_Project here]&lt;br /&gt;
&lt;br /&gt;
*(Mar 07) Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) )&lt;br /&gt;
&lt;br /&gt;
[http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
*(Oct 06) ISACA Roma has published several interview with OWASP-Italy members:&lt;br /&gt;
&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli]] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/328 Carlo Pelliccioni]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Paolo Perego has created the new '''OWASP Orizon Project'''. Go to [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Matteo Meucci has been selected as the new editor of the '''OWASP Testing Guide v2'''. See OWASP [http://www.owasp.org/index.php/OWASP_Autumn_Of_Code_2006_:_Selected_Projects_Press_Release press release] and go to [http://www.owasp.org/index.php/OWASP_Autumn_of_Code_2006_-_Projects:_Testing_Guide OWASP Testing Project v2]&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Carlo Pelliccioni is writing an article about the [http://www.owasp.org/index.php/Analysis_about_error_codes analysis of error codes] received by web servers.&lt;br /&gt;
&lt;br /&gt;
*Top10 Vulnerabilities - OWASP-Italy survey:&lt;br /&gt;
&lt;br /&gt;
[[Image:Top 10 vulnerabilities-mini.GIF]] &lt;br /&gt;
&lt;br /&gt;
*(21 Jun 06) '''Infosecurity 2006''': the event is organized and managed by the CLUSIT.&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. [http://www.infosecurity.it/Roma/programma.php More info here] &lt;br /&gt;
&lt;br /&gt;
*(1 Jun 06) '''&amp;quot;Quaderno CLUSIT&amp;quot;'''&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but will be made public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
*(31 May 06) Luca Carettoni has published the article '''&amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;.''' [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article.&lt;br /&gt;
&lt;br /&gt;
*(1 Mar 06) '''OWASP-Boston, Microsoft'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler, Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting. [http://www.owasp.org/local/boston.html More info here] &lt;br /&gt;
&lt;br /&gt;
*(18 Nov 05) '''IDC - European Banking Forum'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we will have a great speech at the [http://www.idc.com/italy/events/banking05/banking05_agenda.jsp IDC European IT Banking Forum 2005]. Agenda: - New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair - Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy &lt;br /&gt;
&lt;br /&gt;
*(Oct 05) '''SMAU 2005''' is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy.&lt;br /&gt;
&lt;br /&gt;
SMAU has accepted our submission! [http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili More info here] &lt;br /&gt;
&lt;br /&gt;
*(Giu 05) Thanks to Massimiliano Graziani we have translated in italian the '''&amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;'''. You can download it [http://www.owasp.org/documentation/testing.html here.]&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
*(May 05) '''ISACA Roma Newsletter''' has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005.&lt;br /&gt;
&lt;br /&gt;
*The presentation of the seminar we have done in '''ISACA Rome''' (31th March 2005) is now available [http://www.isacaroma.it/pdf/050331/meucci.zip here.]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)].&lt;br /&gt;
&lt;br /&gt;
*(Mar 05) Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here].&lt;br /&gt;
&lt;br /&gt;
*[http://www.isacaroma.it/html/newsletter/?q=node/78 Here] you can read an interview talking about OWASP. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Events  ====&lt;br /&gt;
&lt;br /&gt;
=== 15th March, 2011 - OWASP-Italy@Security Summit ===&lt;br /&gt;
&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
=== November, 2010 - OWASP-Italy Day V  ===&lt;br /&gt;
&lt;br /&gt;
- OWASP Day for E-Gov 2010: 9th November 2010 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
An event organized by Consip. More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_10 here]&lt;br /&gt;
&lt;br /&gt;
=== November, 2009 - OWASP-Italy Day IV  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Following on from the great success of last OWASP Days the forth conference has taken place in November 2009 in Milan. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_4 here]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Day for E-Gov 2009: 5th November 2009 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_09 here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2009 - OWASP-Italy @ PCI Milan  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Testing Guide and PCI-DSS Standard at the [http://www.pci-portal.com/lang-en/events/event-info/pcimilan PCI Milan event] last 31st March. &lt;br /&gt;
&lt;br /&gt;
The presentation is published [http://www.owasp.org/images/3/38/MeucciPciMilan09.pdf here] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 23rd February, 2009 - OWASP Day III  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_3 &amp;quot;Web Application Security: research meets industry&amp;quot;] &amp;lt;br&amp;gt; Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== 10th October, 2008 - Isaca Roma PCM 2008 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci presented the new OWASP Projects and the Application Security in the Italian Companies. More information [http://www.isacaroma.it/html/ArchivioEventi-081010.html here] &lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2008 - OWASP Day II  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_2 &amp;quot;The State of the Art of the Web Application Security and the OWASP guidelines in the Companies&amp;quot;] Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== February 2008 - OWASP Italy at InfoSecurity 2008  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
5th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - The Owasp Orizon project: internals and hands on&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_94.aspx Paolo Perego] &lt;br /&gt;
&lt;br /&gt;
6th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - Costruire Software Sicuro dalle Fondamenta&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_128.aspx Antonio Parata] &lt;br /&gt;
&lt;br /&gt;
7th February: &lt;br /&gt;
&lt;br /&gt;
*10:30 - Tu programmi. Io buco.&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_137.aspx Luca Carettoni] &lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it Here] you can read more information about it. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== November 30th, 2007 - OWASP-Italy @ Elsag Datamat Security Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Guidelines and SDLC Security at the Elsag Datamat Security Forum 2007 &amp;lt;br&amp;gt;Where: Pescara &amp;lt;br&amp;gt;When: 30th November 2007, h.12.30 &lt;br /&gt;
&lt;br /&gt;
=== October 20th, 2007 - OWASP Italy at SMAU E-Academy 2007  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Last 20th October 2007 we had 5 speeches at SMAU E-Academy 2007, here you can download our presentations: &lt;br /&gt;
&lt;br /&gt;
*Giorgio Fedon, COO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/.pdf &amp;quot;Dove sono finiti i miei soldi? Internet Banking e Cross Site Scripting&amp;quot;] (coming soon) [[Image:FedonSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Paolo Perego, Senior Security Consultant at Spike Reply:&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/7/79/PeregoSMAU07.ppt &amp;quot;The Owasp Orizon project - bring security at the source&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Antonio Parata, Security Consultant at eMaze:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Valutazione del rischio tramite la logica fuzzy&amp;quot; (coming soon) [[Image:ParataSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Alberto Revelli, Senior Security Consultant at Portcullis Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/9/9f/RevelliSMAU07.pdf &amp;quot;Anti-Anti-XSS: bypass delle difese del browser&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, CTO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Cros-site Flashing! Gli attacchi Web di ultima generazione parlano multipiattaforma&amp;quot; (coming soon) [[Image:DiPaolaSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== September 10th, 2007 - OWASP Day WorldWide: &amp;quot;Privacy in the 21st Century&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Italy_OWASP_Day_1 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 29th, 2007 - Seminar: &amp;quot;Software Security&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, Paolo Perego and Matteo Meucci will talk at the Seminar: [http://www.sicurinfo.it/informazioni/visinf.asp?IDInfo=246&amp;amp;CAT=53 &amp;quot;Which approaches to Software Security&amp;quot;] organized by Firenze Tecnologia.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 15th-17th, 2007 - 6th OWASP AppSec Conference in Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We are in the initial planning stages for the next OWASP Europe conference, which we plan to hold in Italy in May 2007.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/6th_OWASP_AppSec_Conference_-_Italy_2007 Here] you can find all the details about the conference, cfp and sponsorship. &lt;br /&gt;
&lt;br /&gt;
=== April 14th, 2007 - Master on Information Security, University of Rome &amp;quot;La Sapienza&amp;quot; ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We have done a 4h seminar for the students of [http://mastersicurezza.uniroma1.it/ Master on Information Security at &amp;quot;La Sapienza&amp;quot;] for the [http://icsecurity.di.uniroma1.it/dokuwiki/doku.php?id=projects:asp Application Security Project of &amp;quot;La Sapienza&amp;quot; University.]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 30th, 2007 - University of Rome &amp;quot;La Sapienza&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Thanks to Prof. Mancini and Roberto D'Addario, we will talk about OWASP at the convention &amp;quot;Institutions, Companies and Information Security: comparing the problems&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[http://w3.uniroma1.it/security/Eventi/eventi.html Here] you can find more details. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2007 - EuSecWest 07  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci presented the new OWASP Testing Guide at [http://www.eusecwest.com/agenda.html EUSecWest]. [http://www.owasp.org/images/e/e9/OWASP_Testing_Guide_Presentation_EUSecWest07.zip Here] you take a look at the presentation. &lt;br /&gt;
&lt;br /&gt;
=== February 6th-8th, 2007 - InfoSecurity  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*February 6th:15.30&lt;br /&gt;
&lt;br /&gt;
After the great success obtained form CCC at Berlin, Stefano Di Paola and Giorgio Fedon will talk about:&amp;quot; Web Security Client Side: attacks at Web 2.0&amp;quot; More information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=aqfi82GOKd6I748s1evI8Q%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 6th:16.30&lt;br /&gt;
&lt;br /&gt;
After the great effort on the Testing Guide Project, Matteo Meucci and Alberto Revelli will present: &amp;quot;The new OWASP Testing Guide&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=nq6tSIuRoPVJBanBSsRiSQ%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 7th:12.30&lt;br /&gt;
&lt;br /&gt;
Authors of innovative SQL injection tools, Alberto Revelli and Antonio Parata will show: &amp;quot;Advanced SQL Injection: testing tools and defensive strategies.&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=3z04F5BgZRgfU0YX8JRYtA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here] &lt;br /&gt;
&lt;br /&gt;
*February 7th:13.30&lt;br /&gt;
&lt;br /&gt;
Author of the new OWASP Orizon project, Paolo Perergo will present:&amp;quot;Secure programming: from theory to practice&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=9HePIzyo5p29ylpGBl6CiA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
=== January 25th, 2007 - Isaca Rome  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci will discuss the new [http://www.owasp.org/index.php/Category:OWASP_Testing_Project OWASP Testing Guide v2]&amp;lt;br&amp;gt; For more information:&amp;lt;br&amp;gt; http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
=== October 7th, 2006 - SMAU 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''The quest for secure code: code review and fundamental of secure coding.''&amp;quot; Matteo Meucci will present an introduction to the new OWASP Projects and OWASP-Italy activities. Paolo Perego (sp0nge) will speak about safe coding and the importance of code periodic review as natural software life cycle. Paolo will give a vision on code review and its phases http://www.webb.it/event/eventview/5772 &lt;br /&gt;
&lt;br /&gt;
Here are the presentations: &amp;lt;br&amp;gt; [[Image:Meucci SMAU06.pdf|Meucci_SMAU06]] &amp;lt;br&amp;gt; [[Image:Perego SMAU06.pdf|Perego_SMAU 06]] &lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''Advanced SQL Injection.''&amp;quot; Antonio Parata (S4tan) will explain SQL Injection, and how SQL Inference works on PHP/MySql platform. He will present an open source tool to support the testing. Alberto Revelli (icesurfer) will focus on Microsoft SQL Server: he will perform a live demo of sqlninja (http://sqlninja.sf.net), explaining how to obtain a pseudo-shell over SQL, how to escalate privileges, and how to play with the exotic equation: &amp;quot;SQL Injection + debug.exe + DNS = DOS prompt&amp;quot;&amp;amp;nbsp;! http://www.webb.it/event/eventview/5774 &lt;br /&gt;
&lt;br /&gt;
[[Image:Revelli SMAU06.pdf|Revelli_SMAU06]] &amp;lt;br&amp;gt; [[Image:Parata SMAU06.pdf|Parate_SMAU06]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP-Italy at SMAU06 2.JPG]] Luca, Carlo, Alberto, Antonio, Stefano &amp;lt;br&amp;gt; Matteo, Paolo, Giorgio &lt;br /&gt;
&lt;br /&gt;
=== September 29th, 2006 - OpenExp 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
September 30th, at 10:45 Antonio Parata (S4tan) will speak about SQL Injection: techniques, tools and practical examples. &lt;br /&gt;
&lt;br /&gt;
Abstract: Antonio will introduce some basic concepts about software security. It will be shown how SQL Inference works on PHP/MySql platform and presented an open source tool to support the testing. Finally will be listed some advises to avoid common bugs. http://www.openexp.it/ &lt;br /&gt;
&lt;br /&gt;
OWASP-Italy will have a stand from September 29th to October 1st. &lt;br /&gt;
&lt;br /&gt;
[[Image:Antonio Matteo Carlo.JPG]] [[Image:Antonio speech.JPG]] [[Image:Carlo.JPG]] [[Image:Claudio Luca.JPG]] [[Image:Mayhem Matteo.JPG]] [[Image:OWASP Banner2.JPG]] [[Image:OWASP Banner.JPG]] &lt;br /&gt;
&lt;br /&gt;
=== June 21th, 2006 - InfoSecurity 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. The event is organized and managed by the CLUSIT. &lt;br /&gt;
&lt;br /&gt;
Where: Sheraton Roma Hotel - Viale Del Pattinaggio, 100 When: 10,30 - 17,00 Who: Matteo Meucci and Alberto Revelli Link: http://www.infosecurity.it/Roma/programma.php &lt;br /&gt;
&lt;br /&gt;
Agenda: -- I Session -- Introduction to Web Application Security • Which are the risks? • Risk assessment of a web application • Core pillars of web security How to develop secure web applications: • Guidelines and case-studies &lt;br /&gt;
&lt;br /&gt;
-- II Session -- How to realize a security audit of a web application • The methodology OWASP Penetration Testing • The tools: OWASP WebScarab • Hands-on web application vulnerabilities: OWASP WebGoat • Advanced SQL Injection. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2006 - OWASP-Boston, Microsoft  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler (OWASP-Boston Chair), Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting of march. [http://www.owasp.org/index.php/Boston More info here] &lt;br /&gt;
&lt;br /&gt;
=== November 5th, 2005 - IDC - European Banking Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we have had a great speech at the IDC European IT Banking Forum 2005 (18 Nov 2005). http://www.idc.com/italy/events/banking05/banking05_agenda.jsp Agenda: &lt;br /&gt;
&lt;br /&gt;
*New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair &lt;br /&gt;
*Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy.&lt;br /&gt;
&lt;br /&gt;
You can download the report [http://cdn.idc.com/italy/downloads/report_banking05_eng.pdf here]. &lt;br /&gt;
&lt;br /&gt;
You can download the Case-Study of a vulnerable Home Banking Web Application [http://www.owasp.org/docroot/owasp/misc/IDC_BankingForum05v1.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== October 5th, 2005 - OWASP-Italy@SMAU2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
SMAU is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy. Alberto Revelli (our Technical Director) and Matteo Meucci have conducted a seminar talking about Web Application Security. Alberto has presented his new project: [http://sqlninja.sourceforge.net sqlninja]. Very cool!! &lt;br /&gt;
&lt;br /&gt;
http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili &lt;br /&gt;
&lt;br /&gt;
=== May 25th, 2005 - ISACA Rome 2nd meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
May 25th we'll be in ISACA Rome to present OWASP WebGoat and a real case of a Web Application Vulnerability. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.30 Registration 14.45 Matteo Meucci - Web Application Security Phase II - OWASP WebScarab and PenTest Checklist &lt;br /&gt;
&lt;br /&gt;
*A case-study of a Web Application Vulnerability: MMS Spoofing&lt;br /&gt;
&lt;br /&gt;
--- Web Application analysis --- Authentication and Billing of the MMS service --- Vulnerabilities --- Attack Analysis &lt;br /&gt;
&lt;br /&gt;
*Learning the most common web application vulnerabilities: OWASP WebGoat&lt;br /&gt;
&lt;br /&gt;
--- Http Basics --- HTML Clues --- Hidden Field Tampering --- How to spoof a Session Cookie --- Stored Cross Site Scripting --- Command Injection --- SQL Injection --- Fail Open Authentication &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050525/OWASP.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== May 18th, 2005 - Workshop on Computer Crime 2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; May 18th, 2005 OWASP-Italy is invited to present OWASP Top 10 to the &amp;quot;Workshop on Computer Crime 2005&amp;quot; titled: &amp;quot;EVOLUZIONI NORMATIVE E RECENTI PROBLEMATICHE DI SICUREZZA&amp;quot; &lt;br /&gt;
&lt;br /&gt;
The meeting is held at: Sala delle conferenze dell'Istituto Centrale della Banche Popolari Italiane Via Verziere, 11 &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.owasp.org/images/a/aa/Top10-ComputerCrimes.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== March 31th, 2005 - ISACA Rome meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March 31th we'll be in ISACA Rome to present OWASP and the Web Application Security. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.15 Registration 14.30 Matteo Meucci - Web Application Security - OWASP Guide: how to build secure web application - How to test your Web Application: WebScarab and the WebApp PenTest Checklist - How to learn the most common web application vulnerability: WebGoat - The Top Ten WebApp vulnerabilities - Common error on developing Web Application: Authentication mechanisms not &amp;quot;secure&amp;quot; Buffer Overflow and crash of the service Thief of identity: Cross Site Scripting Manipulation of company data: SQL Injection Reserved information: misconfiguration Bad session management and thief of identity - OWASP-Italy: projects and next challenges &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050331/meucci.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== March 21th, 2005 - OWASP-Italy conducts a seminar in AlmaWeb  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March, the 21th OWASP-Italy has been invited at the University of Bologna to conduct a seminar regards to [http://www.almaweb.unibo.it/830.dyn Master in Management and Information Technology] titled “Web Application Security and OWASP”. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: - OWASP &amp;amp;amp; Web Application Security - Common Web Application Vulnerabilities - A real case of web application vulnerability: MMS Spoofing&amp;amp;amp;Billing - Training: WebGoat &lt;br /&gt;
&lt;br /&gt;
==== Publications  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== October 2009 Interview on &amp;quot;Il sole 24 ore&amp;quot;  ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/5/5c/Nova09.pdf Gary McGraw and Matteo Meucci] interviewed by NOVA, talking about BSIMM and OWASP.&lt;br /&gt;
&lt;br /&gt;
=== March, 2007 Interview on HTML.it  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) ) [http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
=== October, 2006 ISACA Roma interviews OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
After the speeches that OWASP-Italy has done at [http://www.smau.it/catnews.asp?l=2&amp;amp;codcat=385 SMAU E-Academy 2006], ISACA Roma has interviewed some of the people of the Italian chapter. Follow the links for the full interviews (in italian): &amp;lt;br&amp;gt; [[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli] ] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/322 Stefano Di Paola &amp;amp; Giorgio Fedon]] &lt;br /&gt;
&lt;br /&gt;
=== Aug, 2006 - Article on Banca Finanza magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Banca Finanza, the italian magazine about finance and banking, has interviewed Raoul Chiesa talking about the new risks for the on-line banking security. Raoul speaks about OWASP and web application security [[Media:042006BF.pdf]] &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Quaderno CLUSIT  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but it will be public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Paper on SQL Injection and Inference on PHP/MySQLInference  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Antonio &amp;quot;s4tan&amp;quot; Parata has published an article about SQL Injection based on Inference for testing web application on PHP/MySQL platform. [http://www.ictsc.it/papers/sqlInferenceOnMySql.html Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== May, 2006 - Published an article about OWASP and Top-10 Vulnerabilities  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published the article &amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;. [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== June, 2005 - OWASP Pen Test Checklist v 1.1 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Massimiliano Graziani we have translated in italian the &amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;. You can download it [http://www.owasp.org/documentation/testing.html here.] Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
=== May, 2005 - Isaca Roma Newsletter about OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
ISACA Roma Newsletter has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy] &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published &amp;quot;MMS Spoofing&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)]. &lt;br /&gt;
&lt;br /&gt;
Jim Hewitt, CISSP PMP working at CGI-AMS, affirms (slide#78): &amp;quot;Very interesting analysis of spoofed cell phone messaging and fraudulent billing&amp;quot;. See: www.techvalleynyissa.org/Resources/2005_07_WebApplicationSecurity.ppt &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published an article on ICT Security magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005. &lt;br /&gt;
&lt;br /&gt;
=== March, 2005 - OWASP Top-10 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here]. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
==== Tools &amp;amp;amp; Research  ====&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Nov, 2007 - sqlmap v0.5  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released the fifth versions of the tool [http://sqlmap.sourceforge.net sqlmap]. sqlmap is an automatic SQL injection tool entirely developed in Python. It is capable to perform an extensive database management system back-end fingerprint, retrieve remote DBMS databases, usernames, tables, columns, enumerate entire DBMS, read system files and much more taking advantage of web application programming security flaws that lead to SQL injection vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
You can download the latest stable version from its [https://sourceforge.net/project/showfiles.php?group_id=171598&amp;amp;package_id=196107 SourceForge File List page] or the latest development version from its [https://sqlmap.svn.sourceforge.net/svnroot/sqlmap SourceForge SVN repository]. &lt;br /&gt;
&lt;br /&gt;
=== Dec, 2006 - sqlmap v0.2  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released a second version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://sqlmap.sourceforge.net/ Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
=== September, 2006 - Wisec Project  ===&lt;br /&gt;
&lt;br /&gt;
Stefano Di Paola is developing Wisec - The Wiki Security Project [http://www.wisec.it Here] you can accesses the project. &lt;br /&gt;
&lt;br /&gt;
=== July, 2006 - Sqlmap v0.0.1  ===&lt;br /&gt;
&lt;br /&gt;
Daniele Bellucci has developed a first version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://www.linux.it/~belch/?p=17 Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Chapter]]&lt;br /&gt;
[[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy&amp;diff=249130</id>
		<title>Italy</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy&amp;diff=249130"/>
				<updated>2019-03-21T15:55:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[Image:OWASP-Italy.PNG]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== WELCOME  ====&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Italy|extra=The chapter leader is [mailto:matteo.meucci@owasp.org Matteo Meucci]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-italy|emailarchives=http://lists.owasp.org/pipermail/owasp-italy}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Italy&amp;lt;/paypal&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''NEXT EVENT: OWASP/WIA initiatives - 26th March 2019''' ==&lt;br /&gt;
Thanks to Loredana Mancini and Zoe Braiterman we will have an OWASP-Italy /WIA initiatives at the Link Campus in Rome next 26th March.&amp;lt;br&amp;gt;&lt;br /&gt;
Venue: Link Campus University Via del Casale di San Pio V, 44 - 00165 Roma (RM)&lt;br /&gt;
&lt;br /&gt;
Speakers: Prof.ssa Paola Giannetakis (Link Campus University), Zoe Braiterman (OWASP/WIA Chair), Luciana Scognamiglio (Senior security expert /HPE), Matteo Meucci (OWASP-Italy Chair).&lt;br /&gt;
&lt;br /&gt;
http://it.expandi-web.com/aruba/2019/aruba_oswap/form.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''OWASP-Italy@Security Summit 2019''' ==&lt;br /&gt;
Thanks to CLUSIT, Giuseppe Trotta and Lorenzo De Meo had a talk at the OWASP-Italy corner during the Security Summit in Milan &amp;lt;br&amp;gt;&lt;br /&gt;
When: 14th March 2019 at 16:10-16:50&amp;lt;br&amp;gt;&lt;br /&gt;
Where: UNAHOTELS EXPO FIERA, via Keplero 12, Pero &amp;lt;br&amp;gt;&lt;br /&gt;
Please see the presentations here:&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/a/aa/OWASPCloudTestingMar19.pdf Federico De Meo: &amp;quot;Cloud Security Testing&amp;quot;]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[https://drive.google.com/file/d/1AU2zQXcy2Lnc1jI9UxYnkw1rKrDwPcYW/view Giuseppe Trotta: &amp;quot;New phishing attacks&amp;quot;]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''OWASP-Italy Cagliari Day 2018 - 19th October 2018''' ==&lt;br /&gt;
Università di Cagliari.&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day Cagliari 2018|Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
=='''OWASP-Italy Day 2018 @ Milano 16th June 2018''' ==&lt;br /&gt;
Politecnico of Milano&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2018 ==&lt;br /&gt;
OWASP Italy did participate to the Security Summit 2018 in Milan with 2 talks.&amp;lt;br&amp;gt;More information here: [https://www.securitysummit.it/agenda-details/333 https://www.securitysummit.it/agenda-details/93]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day 2017 @ Cagliari 20th October 2017 ==&lt;br /&gt;
Cagliari , 6th October 2017, Università di Cagliari&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2017]]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 6th October 2017 ==&lt;br /&gt;
'''V Conference on Application Security and Modern Technologies'''&lt;br /&gt;
&lt;br /&gt;
Mestre, 6th October 2017, Università Ca' Foscari&lt;br /&gt;
&lt;br /&gt;
http://www.isaca.org/chapters5/Venice/Pages/default.aspx&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2017 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2017 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
Antonio Parata will give a talk on EyePyramid malware and Fabrizio Bugli will talk about (3rd) Party like nobody's watching&lt;br /&gt;
&lt;br /&gt;
https://www.securitysummit.it/agenda-details/93&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP AppSec Europe 2016 in Rome! ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASPAppSecEU2016.jpg]]&lt;br /&gt;
&lt;br /&gt;
OWASP is organizing the next OWASP AppSecEU in Rome.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;See the agenda and buy your ticket here:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
http://2016.appsec.eu/&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2016 ==&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2016 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2016/seminari-associazioni/talk-257/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Adopt OSS. First Edition ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy is pleased to announce a new initiative: '''Adopt''' '''O'''pen'''S'''ource'''S'''oftware&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Given OWASP’s mission to help organizations with application security, we have established a new initiative to provide free, voluntary-based support to open source software projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Thanks to Adopt OSS, security enthusiasts are paired with participating open source projects, thus gaining exposure to real-life security engineering challenges and the opportunity for career growth. In turn, the participating projects are able to obtain free professional expertise to better improve their security posture, and ultimately build secure software. Over a six months period, OWASP Italy will facilitate the effort by coordinating the initiative and providing support when needed.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The first edition of this initiative will take place between ''May and November 2015'', and will see the participation of '''7 OWASP Italy members''' and '''3 major OpenSource projects'''. At the end of the six months period, OWASP Italy will publish results and feedback from both volunteers and OSS maintainers.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The official flyer can be [https://www.owasp.org/images/0/07/AdoptOSSManifest-OWASPItaly.pdf downloaded from here].&lt;br /&gt;
&lt;br /&gt;
===Ntopng===&lt;br /&gt;
''Alessio Petracca, Mattia Folador, Giuseppe Longo''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.ntop.org/products/traffic-analysis/ntop/ Ntop] is the de-facto standard for real-time network traffic monitoring. OWASP Italy wants to help the project by increasing the security level of ntopng, performing security testing activities and supporting the remediation process.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will act in two steps:&lt;br /&gt;
* First, a penetration test targeting the web interface of ntopng will be performed, following the [https://www.owasp.org/index.php/OWASP_Testing_Guide_v3_Table_of_Contents OWASP Testing Methodology]&lt;br /&gt;
* Secondly, source code review of ntopng main components (such as the C++ core engine) will be statically reviewed. The objective is to address all relevant checks contained within the [https://www.owasp.org/index.php/OWASP_Code_review_V2_Table_of_Contents OWASP Code Review Guide]&lt;br /&gt;
&lt;br /&gt;
In case the activities above are completed before the end of the six-months period, additional activities (such as the development of security plugins) will be discussed.&lt;br /&gt;
Luca Deri and Arianna Avanzini will support Alessio Petracca and Mattia Folador in these activities, by providing guidance and insights.&lt;br /&gt;
&lt;br /&gt;
===WordPress===&lt;br /&gt;
''Paolo Perego, Sandro Zaccarini''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://wordpress.org/ WordPress] is the facto standard for web publishing. If you need a blog, if you need a new showcase website for your portfolio or a tiny e-commerce web site for your small company you will look at WordPress to start.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Paying the cost to be the boss, WordPress during the years suffered tons of security issues, 3 major issues only in the beginning of May 2015. Either the core, plugins and themes are developed with easy to use in mind and they need to be hardened.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Italy wants to support WordPress adopting it with the &amp;quot;Stand by WordPress&amp;quot; initiative. We will deploy the software in three different standard configurations: blog, company's portfolio and e-commerce.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will do continuous appsec during development of 4.3 version in order to quickly spot security issues before the August release. In addition, we will take care of hardening guidelines and both plugins and themes subsystems in order to improve the overall architecture.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You can follow the progress of the &amp;quot;Stand by WordPress&amp;quot; initiative here: https://standbywordpress.wordpress.com&lt;br /&gt;
&lt;br /&gt;
===GlobaLeaks===&lt;br /&gt;
''Luca Carettoni, Giovanni Cerrato, Marco Lancini''&lt;br /&gt;
&lt;br /&gt;
[https://www.globaleaks.org/ GlobaLeaks] is the first open-source whistleblowing framework. It empowers anyone to easily set up and maintain an anonymous whistleblowing platform.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Considering the potential hostile environments in which the application may be hosted, security vulnerabilities and abuses are primary concerns for GlobaLeaks’ maintainers.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We want to help the team in their excellent application security practices, by performing vulnerability research activities in order to discover unknown bugs within the boundaries of their specific [https://docs.google.com/document/d/1niYFyEar1FUmStC03OidYAIfVJf18ErUFwSWCmWBhcA/pub threat model]. In particular, we will be focusing on two main software components (GLBackend and GLClient) and new security-relevant changes (upcoming authentication re-factoring and end-to-end encryption).&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information on '''Adopt OSS''', please send an email to [mailto:owasp-italy@lists.owasp.org owasp-italy@lists.owasp.org]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2015 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2015 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2015/seminari-associazioni/talk-140/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Rome 11-12th December 2014 ==&lt;br /&gt;
The agenda is online! &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
http://www.isacaroma.it/images/owasp_agenda_11-12-12-2014.JPG&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 3rd October 2014 ==&lt;br /&gt;
The agenda: &amp;lt;br&amp;gt;&lt;br /&gt;
[[File:Venice2014.jpg]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Here is the [https://www.owasp.org/images/d/d3/OWASPVenice2014.pdf flyer]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day @ the University of Genova (14th May 2014) ==&lt;br /&gt;
Thank to the collaboration with [http://www.ai-lab.it/armando Prof. Alessandro Armando] and to the availability of Gary McGraw, Ph.D. CTO, Cigital we are planning an incredible [https://www.owasp.org/index.php/Italy_OWASP_Day_2014_Genova OWASP Day next 14th May].&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2014 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2014 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2014/seminari-associazioni/talk-34/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP EU Tour 2013 - 27th June - Rome==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;{{:EUTour2013 header}}&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with Università Degli Studi Roma Tre, next 27th June we will have the OWASP EU Tour Rome Conference.&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Europe TOUR, is an event across the European region that promotes awareness about application security, so that people and organizations can make informed decisions about true application security risks. &amp;lt;br&amp;gt;Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.&lt;br /&gt;
&lt;br /&gt;
The conference will be held at Università Degli Studi Roma Tre. Address: Via Vito Volterra, 62, Rome.&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/EUTour2013_Rome_Agenda Here you can find the agenda and all the information to participate]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2013 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy participated to the Security Summit 2013 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[http://milano2013.securitysummit.it/eventi/view/35 See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy Day 2012: &amp;quot;Web Security in a Mobile World&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;center&amp;gt;[[File:OWASPITDay2012.jpg]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Italy OWASP Italy chapter] will host the OWASP Italy Day 2012 conference in Rome, Italy at the University of Rome La Sapienza next 23rd November 2012.&lt;br /&gt;
&lt;br /&gt;
More information [https://www.owasp.org/index.php?title=Italy_OWASP_Day_2012 here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Board  ==&lt;br /&gt;
&lt;br /&gt;
*This is the '''OWASP-Italy Board''':&lt;br /&gt;
Founder and Chair: Matteo Meucci (Jan 2005)&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Italy Board: Paolo Perego, Luca Carettoni, Antonio Parata, Giorgio Fedon, Stefano Di Paola, Mauro Bregolin, Claudio Merloni, Raoul Chiesa.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Partnerships  ====&lt;br /&gt;
&lt;br /&gt;
*ISC2-Italian Chapter: Thanks to Marco Misitano, Paolo Ottolino and Claudio Sasso, OWASP Italy collaborates with the ISC2-Italian Chapter for new initiatives regarding Security Conferences, articles and contentes regarding SDLC.&lt;br /&gt;
&lt;br /&gt;
[http://www.isc2chapter-italy.it https://www.owasp.org/images/a/a3/ISC2Italy.jpg]&lt;br /&gt;
&lt;br /&gt;
*CSA Italy Partnership&lt;br /&gt;
&lt;br /&gt;
[http://chapters.cloudsecurityalliance.org/italy/ https://www.owasp.org/images/6/6a/CSAItalylogo.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Alberto Manfredi (CSA Italy President) we are starting a collaboration with the Italian Chapter of the Cloud Security Alliance.&lt;br /&gt;
&lt;br /&gt;
*IsecLab Partnership&lt;br /&gt;
&lt;br /&gt;
[http://www.iseclab.org http://www.owasp.org/images/4/4b/LogoIsecLab.png]&lt;br /&gt;
&lt;br /&gt;
We are beginning a collaboration with David Balzarotti and Marco Balduzzi of International Secure Systems Lab(IsecLab) with the goal of sharing and improving new WebAppSec projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*CLUSIT Member&lt;br /&gt;
&lt;br /&gt;
http://www.clusit.it/logo_clusit/clusit_logo_b130.gif &lt;br /&gt;
&lt;br /&gt;
Thanks to CLUSIT and OWASP Foundation we have established a cross-membership between the two organizations. So OWASP-Italy is now a [http://www.clusit.it/soci.htm CLUSIT member] and CLUSIT is an OWASP Educational Member.&lt;br /&gt;
&lt;br /&gt;
*ISACA Rome&lt;br /&gt;
&lt;br /&gt;
[http://www.isacaroma.it http://www.owasp.org/images/9/98/Isacaroma.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Ugo Spaziani, we are developing seminars and new ideas with ISACA Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2012 ==&lt;br /&gt;
- 21st March 2012, OWASP Italy will present 3 talks:&lt;br /&gt;
&lt;br /&gt;
- Antonio Parata e Paolo Perego:&amp;quot;Security Testing for developers&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;Banking Malware evolution in Italy: defense approach&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Stefano Di Paola:&amp;quot;DOM Xss: la nuova generazione di vulnerabilità applicative&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
Please subscribe for free here: https://www.securitysummit.it/eventi/view/21&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2011 ==&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''OWASP Books are out!'''&lt;br /&gt;
&lt;br /&gt;
Now you can download or buy a book on the OWASP Projects. Check it here: http://stores.lulu.com/owasp &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Activities  ====&lt;br /&gt;
&lt;br /&gt;
*(Jun 10): OWASP Testing Guide presentation at FBK (Fondazione Bruno Kessler). &lt;br /&gt;
&lt;br /&gt;
*(May 10): OWASP Training at London: last 28th May in London, OWASP leaders deliver a course focused on the main OWASP Projects. This course aims to change that by providing a selection of mature and enterprise ready projects together with practical examples of how to use them. &lt;br /&gt;
This Course was FREE for OWASP Members. &lt;br /&gt;
http://www.owasp.org/index.php/London/Training/OWASP_projects_and_resources_you_can_use_TODAY&lt;br /&gt;
&lt;br /&gt;
*(Jan 09) OWASP Testing Guide v3 is finished! You can download or browse it [http://www.owasp.org/index.php/Category:OWASP_Testing_Project here]&lt;br /&gt;
&lt;br /&gt;
*(Mar 07) Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) )&lt;br /&gt;
&lt;br /&gt;
[http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
*(Oct 06) ISACA Roma has published several interview with OWASP-Italy members:&lt;br /&gt;
&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli]] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/328 Carlo Pelliccioni]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Paolo Perego has created the new '''OWASP Orizon Project'''. Go to [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Matteo Meucci has been selected as the new editor of the '''OWASP Testing Guide v2'''. See OWASP [http://www.owasp.org/index.php/OWASP_Autumn_Of_Code_2006_:_Selected_Projects_Press_Release press release] and go to [http://www.owasp.org/index.php/OWASP_Autumn_of_Code_2006_-_Projects:_Testing_Guide OWASP Testing Project v2]&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Carlo Pelliccioni is writing an article about the [http://www.owasp.org/index.php/Analysis_about_error_codes analysis of error codes] received by web servers.&lt;br /&gt;
&lt;br /&gt;
*Top10 Vulnerabilities - OWASP-Italy survey:&lt;br /&gt;
&lt;br /&gt;
[[Image:Top 10 vulnerabilities-mini.GIF]] &lt;br /&gt;
&lt;br /&gt;
*(21 Jun 06) '''Infosecurity 2006''': the event is organized and managed by the CLUSIT.&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. [http://www.infosecurity.it/Roma/programma.php More info here] &lt;br /&gt;
&lt;br /&gt;
*(1 Jun 06) '''&amp;quot;Quaderno CLUSIT&amp;quot;'''&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but will be made public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
*(31 May 06) Luca Carettoni has published the article '''&amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;.''' [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article.&lt;br /&gt;
&lt;br /&gt;
*(1 Mar 06) '''OWASP-Boston, Microsoft'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler, Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting. [http://www.owasp.org/local/boston.html More info here] &lt;br /&gt;
&lt;br /&gt;
*(18 Nov 05) '''IDC - European Banking Forum'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we will have a great speech at the [http://www.idc.com/italy/events/banking05/banking05_agenda.jsp IDC European IT Banking Forum 2005]. Agenda: - New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair - Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy &lt;br /&gt;
&lt;br /&gt;
*(Oct 05) '''SMAU 2005''' is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy.&lt;br /&gt;
&lt;br /&gt;
SMAU has accepted our submission! [http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili More info here] &lt;br /&gt;
&lt;br /&gt;
*(Giu 05) Thanks to Massimiliano Graziani we have translated in italian the '''&amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;'''. You can download it [http://www.owasp.org/documentation/testing.html here.]&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
*(May 05) '''ISACA Roma Newsletter''' has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005.&lt;br /&gt;
&lt;br /&gt;
*The presentation of the seminar we have done in '''ISACA Rome''' (31th March 2005) is now available [http://www.isacaroma.it/pdf/050331/meucci.zip here.]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)].&lt;br /&gt;
&lt;br /&gt;
*(Mar 05) Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here].&lt;br /&gt;
&lt;br /&gt;
*[http://www.isacaroma.it/html/newsletter/?q=node/78 Here] you can read an interview talking about OWASP. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Events  ====&lt;br /&gt;
&lt;br /&gt;
=== 15th March, 2011 - OWASP-Italy@Security Summit ===&lt;br /&gt;
&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
=== November, 2010 - OWASP-Italy Day V  ===&lt;br /&gt;
&lt;br /&gt;
- OWASP Day for E-Gov 2010: 9th November 2010 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
An event organized by Consip. More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_10 here]&lt;br /&gt;
&lt;br /&gt;
=== November, 2009 - OWASP-Italy Day IV  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Following on from the great success of last OWASP Days the forth conference has taken place in November 2009 in Milan. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_4 here]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Day for E-Gov 2009: 5th November 2009 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_09 here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2009 - OWASP-Italy @ PCI Milan  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Testing Guide and PCI-DSS Standard at the [http://www.pci-portal.com/lang-en/events/event-info/pcimilan PCI Milan event] last 31st March. &lt;br /&gt;
&lt;br /&gt;
The presentation is published [http://www.owasp.org/images/3/38/MeucciPciMilan09.pdf here] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 23rd February, 2009 - OWASP Day III  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_3 &amp;quot;Web Application Security: research meets industry&amp;quot;] &amp;lt;br&amp;gt; Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== 10th October, 2008 - Isaca Roma PCM 2008 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci presented the new OWASP Projects and the Application Security in the Italian Companies. More information [http://www.isacaroma.it/html/ArchivioEventi-081010.html here] &lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2008 - OWASP Day II  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_2 &amp;quot;The State of the Art of the Web Application Security and the OWASP guidelines in the Companies&amp;quot;] Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== February 2008 - OWASP Italy at InfoSecurity 2008  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
5th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - The Owasp Orizon project: internals and hands on&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_94.aspx Paolo Perego] &lt;br /&gt;
&lt;br /&gt;
6th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - Costruire Software Sicuro dalle Fondamenta&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_128.aspx Antonio Parata] &lt;br /&gt;
&lt;br /&gt;
7th February: &lt;br /&gt;
&lt;br /&gt;
*10:30 - Tu programmi. Io buco.&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_137.aspx Luca Carettoni] &lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it Here] you can read more information about it. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== November 30th, 2007 - OWASP-Italy @ Elsag Datamat Security Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Guidelines and SDLC Security at the Elsag Datamat Security Forum 2007 &amp;lt;br&amp;gt;Where: Pescara &amp;lt;br&amp;gt;When: 30th November 2007, h.12.30 &lt;br /&gt;
&lt;br /&gt;
=== October 20th, 2007 - OWASP Italy at SMAU E-Academy 2007  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Last 20th October 2007 we had 5 speeches at SMAU E-Academy 2007, here you can download our presentations: &lt;br /&gt;
&lt;br /&gt;
*Giorgio Fedon, COO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/.pdf &amp;quot;Dove sono finiti i miei soldi? Internet Banking e Cross Site Scripting&amp;quot;] (coming soon) [[Image:FedonSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Paolo Perego, Senior Security Consultant at Spike Reply:&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/7/79/PeregoSMAU07.ppt &amp;quot;The Owasp Orizon project - bring security at the source&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Antonio Parata, Security Consultant at eMaze:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Valutazione del rischio tramite la logica fuzzy&amp;quot; (coming soon) [[Image:ParataSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Alberto Revelli, Senior Security Consultant at Portcullis Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/9/9f/RevelliSMAU07.pdf &amp;quot;Anti-Anti-XSS: bypass delle difese del browser&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, CTO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Cros-site Flashing! Gli attacchi Web di ultima generazione parlano multipiattaforma&amp;quot; (coming soon) [[Image:DiPaolaSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== September 10th, 2007 - OWASP Day WorldWide: &amp;quot;Privacy in the 21st Century&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Italy_OWASP_Day_1 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 29th, 2007 - Seminar: &amp;quot;Software Security&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, Paolo Perego and Matteo Meucci will talk at the Seminar: [http://www.sicurinfo.it/informazioni/visinf.asp?IDInfo=246&amp;amp;CAT=53 &amp;quot;Which approaches to Software Security&amp;quot;] organized by Firenze Tecnologia.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 15th-17th, 2007 - 6th OWASP AppSec Conference in Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We are in the initial planning stages for the next OWASP Europe conference, which we plan to hold in Italy in May 2007.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/6th_OWASP_AppSec_Conference_-_Italy_2007 Here] you can find all the details about the conference, cfp and sponsorship. &lt;br /&gt;
&lt;br /&gt;
=== April 14th, 2007 - Master on Information Security, University of Rome &amp;quot;La Sapienza&amp;quot; ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We have done a 4h seminar for the students of [http://mastersicurezza.uniroma1.it/ Master on Information Security at &amp;quot;La Sapienza&amp;quot;] for the [http://icsecurity.di.uniroma1.it/dokuwiki/doku.php?id=projects:asp Application Security Project of &amp;quot;La Sapienza&amp;quot; University.]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 30th, 2007 - University of Rome &amp;quot;La Sapienza&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Thanks to Prof. Mancini and Roberto D'Addario, we will talk about OWASP at the convention &amp;quot;Institutions, Companies and Information Security: comparing the problems&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[http://w3.uniroma1.it/security/Eventi/eventi.html Here] you can find more details. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2007 - EuSecWest 07  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci presented the new OWASP Testing Guide at [http://www.eusecwest.com/agenda.html EUSecWest]. [http://www.owasp.org/images/e/e9/OWASP_Testing_Guide_Presentation_EUSecWest07.zip Here] you take a look at the presentation. &lt;br /&gt;
&lt;br /&gt;
=== February 6th-8th, 2007 - InfoSecurity  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*February 6th:15.30&lt;br /&gt;
&lt;br /&gt;
After the great success obtained form CCC at Berlin, Stefano Di Paola and Giorgio Fedon will talk about:&amp;quot; Web Security Client Side: attacks at Web 2.0&amp;quot; More information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=aqfi82GOKd6I748s1evI8Q%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 6th:16.30&lt;br /&gt;
&lt;br /&gt;
After the great effort on the Testing Guide Project, Matteo Meucci and Alberto Revelli will present: &amp;quot;The new OWASP Testing Guide&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=nq6tSIuRoPVJBanBSsRiSQ%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 7th:12.30&lt;br /&gt;
&lt;br /&gt;
Authors of innovative SQL injection tools, Alberto Revelli and Antonio Parata will show: &amp;quot;Advanced SQL Injection: testing tools and defensive strategies.&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=3z04F5BgZRgfU0YX8JRYtA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here] &lt;br /&gt;
&lt;br /&gt;
*February 7th:13.30&lt;br /&gt;
&lt;br /&gt;
Author of the new OWASP Orizon project, Paolo Perergo will present:&amp;quot;Secure programming: from theory to practice&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=9HePIzyo5p29ylpGBl6CiA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
=== January 25th, 2007 - Isaca Rome  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci will discuss the new [http://www.owasp.org/index.php/Category:OWASP_Testing_Project OWASP Testing Guide v2]&amp;lt;br&amp;gt; For more information:&amp;lt;br&amp;gt; http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
=== October 7th, 2006 - SMAU 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''The quest for secure code: code review and fundamental of secure coding.''&amp;quot; Matteo Meucci will present an introduction to the new OWASP Projects and OWASP-Italy activities. Paolo Perego (sp0nge) will speak about safe coding and the importance of code periodic review as natural software life cycle. Paolo will give a vision on code review and its phases http://www.webb.it/event/eventview/5772 &lt;br /&gt;
&lt;br /&gt;
Here are the presentations: &amp;lt;br&amp;gt; [[Image:Meucci SMAU06.pdf|Meucci_SMAU06]] &amp;lt;br&amp;gt; [[Image:Perego SMAU06.pdf|Perego_SMAU 06]] &lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''Advanced SQL Injection.''&amp;quot; Antonio Parata (S4tan) will explain SQL Injection, and how SQL Inference works on PHP/MySql platform. He will present an open source tool to support the testing. Alberto Revelli (icesurfer) will focus on Microsoft SQL Server: he will perform a live demo of sqlninja (http://sqlninja.sf.net), explaining how to obtain a pseudo-shell over SQL, how to escalate privileges, and how to play with the exotic equation: &amp;quot;SQL Injection + debug.exe + DNS = DOS prompt&amp;quot;&amp;amp;nbsp;! http://www.webb.it/event/eventview/5774 &lt;br /&gt;
&lt;br /&gt;
[[Image:Revelli SMAU06.pdf|Revelli_SMAU06]] &amp;lt;br&amp;gt; [[Image:Parata SMAU06.pdf|Parate_SMAU06]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP-Italy at SMAU06 2.JPG]] Luca, Carlo, Alberto, Antonio, Stefano &amp;lt;br&amp;gt; Matteo, Paolo, Giorgio &lt;br /&gt;
&lt;br /&gt;
=== September 29th, 2006 - OpenExp 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
September 30th, at 10:45 Antonio Parata (S4tan) will speak about SQL Injection: techniques, tools and practical examples. &lt;br /&gt;
&lt;br /&gt;
Abstract: Antonio will introduce some basic concepts about software security. It will be shown how SQL Inference works on PHP/MySql platform and presented an open source tool to support the testing. Finally will be listed some advises to avoid common bugs. http://www.openexp.it/ &lt;br /&gt;
&lt;br /&gt;
OWASP-Italy will have a stand from September 29th to October 1st. &lt;br /&gt;
&lt;br /&gt;
[[Image:Antonio Matteo Carlo.JPG]] [[Image:Antonio speech.JPG]] [[Image:Carlo.JPG]] [[Image:Claudio Luca.JPG]] [[Image:Mayhem Matteo.JPG]] [[Image:OWASP Banner2.JPG]] [[Image:OWASP Banner.JPG]] &lt;br /&gt;
&lt;br /&gt;
=== June 21th, 2006 - InfoSecurity 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. The event is organized and managed by the CLUSIT. &lt;br /&gt;
&lt;br /&gt;
Where: Sheraton Roma Hotel - Viale Del Pattinaggio, 100 When: 10,30 - 17,00 Who: Matteo Meucci and Alberto Revelli Link: http://www.infosecurity.it/Roma/programma.php &lt;br /&gt;
&lt;br /&gt;
Agenda: -- I Session -- Introduction to Web Application Security • Which are the risks? • Risk assessment of a web application • Core pillars of web security How to develop secure web applications: • Guidelines and case-studies &lt;br /&gt;
&lt;br /&gt;
-- II Session -- How to realize a security audit of a web application • The methodology OWASP Penetration Testing • The tools: OWASP WebScarab • Hands-on web application vulnerabilities: OWASP WebGoat • Advanced SQL Injection. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2006 - OWASP-Boston, Microsoft  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler (OWASP-Boston Chair), Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting of march. [http://www.owasp.org/index.php/Boston More info here] &lt;br /&gt;
&lt;br /&gt;
=== November 5th, 2005 - IDC - European Banking Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we have had a great speech at the IDC European IT Banking Forum 2005 (18 Nov 2005). http://www.idc.com/italy/events/banking05/banking05_agenda.jsp Agenda: &lt;br /&gt;
&lt;br /&gt;
*New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair &lt;br /&gt;
*Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy.&lt;br /&gt;
&lt;br /&gt;
You can download the report [http://cdn.idc.com/italy/downloads/report_banking05_eng.pdf here]. &lt;br /&gt;
&lt;br /&gt;
You can download the Case-Study of a vulnerable Home Banking Web Application [http://www.owasp.org/docroot/owasp/misc/IDC_BankingForum05v1.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== October 5th, 2005 - OWASP-Italy@SMAU2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
SMAU is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy. Alberto Revelli (our Technical Director) and Matteo Meucci have conducted a seminar talking about Web Application Security. Alberto has presented his new project: [http://sqlninja.sourceforge.net sqlninja]. Very cool!! &lt;br /&gt;
&lt;br /&gt;
http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili &lt;br /&gt;
&lt;br /&gt;
=== May 25th, 2005 - ISACA Rome 2nd meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
May 25th we'll be in ISACA Rome to present OWASP WebGoat and a real case of a Web Application Vulnerability. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.30 Registration 14.45 Matteo Meucci - Web Application Security Phase II - OWASP WebScarab and PenTest Checklist &lt;br /&gt;
&lt;br /&gt;
*A case-study of a Web Application Vulnerability: MMS Spoofing&lt;br /&gt;
&lt;br /&gt;
--- Web Application analysis --- Authentication and Billing of the MMS service --- Vulnerabilities --- Attack Analysis &lt;br /&gt;
&lt;br /&gt;
*Learning the most common web application vulnerabilities: OWASP WebGoat&lt;br /&gt;
&lt;br /&gt;
--- Http Basics --- HTML Clues --- Hidden Field Tampering --- How to spoof a Session Cookie --- Stored Cross Site Scripting --- Command Injection --- SQL Injection --- Fail Open Authentication &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050525/OWASP.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== May 18th, 2005 - Workshop on Computer Crime 2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; May 18th, 2005 OWASP-Italy is invited to present OWASP Top 10 to the &amp;quot;Workshop on Computer Crime 2005&amp;quot; titled: &amp;quot;EVOLUZIONI NORMATIVE E RECENTI PROBLEMATICHE DI SICUREZZA&amp;quot; &lt;br /&gt;
&lt;br /&gt;
The meeting is held at: Sala delle conferenze dell'Istituto Centrale della Banche Popolari Italiane Via Verziere, 11 &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.owasp.org/images/a/aa/Top10-ComputerCrimes.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== March 31th, 2005 - ISACA Rome meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March 31th we'll be in ISACA Rome to present OWASP and the Web Application Security. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.15 Registration 14.30 Matteo Meucci - Web Application Security - OWASP Guide: how to build secure web application - How to test your Web Application: WebScarab and the WebApp PenTest Checklist - How to learn the most common web application vulnerability: WebGoat - The Top Ten WebApp vulnerabilities - Common error on developing Web Application: Authentication mechanisms not &amp;quot;secure&amp;quot; Buffer Overflow and crash of the service Thief of identity: Cross Site Scripting Manipulation of company data: SQL Injection Reserved information: misconfiguration Bad session management and thief of identity - OWASP-Italy: projects and next challenges &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050331/meucci.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== March 21th, 2005 - OWASP-Italy conducts a seminar in AlmaWeb  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March, the 21th OWASP-Italy has been invited at the University of Bologna to conduct a seminar regards to [http://www.almaweb.unibo.it/830.dyn Master in Management and Information Technology] titled “Web Application Security and OWASP”. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: - OWASP &amp;amp;amp; Web Application Security - Common Web Application Vulnerabilities - A real case of web application vulnerability: MMS Spoofing&amp;amp;amp;Billing - Training: WebGoat &lt;br /&gt;
&lt;br /&gt;
==== Publications  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== October 2009 Interview on &amp;quot;Il sole 24 ore&amp;quot;  ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/5/5c/Nova09.pdf Gary McGraw and Matteo Meucci] interviewed by NOVA, talking about BSIMM and OWASP.&lt;br /&gt;
&lt;br /&gt;
=== March, 2007 Interview on HTML.it  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) ) [http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
=== October, 2006 ISACA Roma interviews OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
After the speeches that OWASP-Italy has done at [http://www.smau.it/catnews.asp?l=2&amp;amp;codcat=385 SMAU E-Academy 2006], ISACA Roma has interviewed some of the people of the Italian chapter. Follow the links for the full interviews (in italian): &amp;lt;br&amp;gt; [[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli] ] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/322 Stefano Di Paola &amp;amp; Giorgio Fedon]] &lt;br /&gt;
&lt;br /&gt;
=== Aug, 2006 - Article on Banca Finanza magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Banca Finanza, the italian magazine about finance and banking, has interviewed Raoul Chiesa talking about the new risks for the on-line banking security. Raoul speaks about OWASP and web application security [[Media:042006BF.pdf]] &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Quaderno CLUSIT  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but it will be public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Paper on SQL Injection and Inference on PHP/MySQLInference  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Antonio &amp;quot;s4tan&amp;quot; Parata has published an article about SQL Injection based on Inference for testing web application on PHP/MySQL platform. [http://www.ictsc.it/papers/sqlInferenceOnMySql.html Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== May, 2006 - Published an article about OWASP and Top-10 Vulnerabilities  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published the article &amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;. [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== June, 2005 - OWASP Pen Test Checklist v 1.1 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Massimiliano Graziani we have translated in italian the &amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;. You can download it [http://www.owasp.org/documentation/testing.html here.] Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
=== May, 2005 - Isaca Roma Newsletter about OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
ISACA Roma Newsletter has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy] &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published &amp;quot;MMS Spoofing&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)]. &lt;br /&gt;
&lt;br /&gt;
Jim Hewitt, CISSP PMP working at CGI-AMS, affirms (slide#78): &amp;quot;Very interesting analysis of spoofed cell phone messaging and fraudulent billing&amp;quot;. See: www.techvalleynyissa.org/Resources/2005_07_WebApplicationSecurity.ppt &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published an article on ICT Security magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005. &lt;br /&gt;
&lt;br /&gt;
=== March, 2005 - OWASP Top-10 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here]. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
==== Tools &amp;amp;amp; Research  ====&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Nov, 2007 - sqlmap v0.5  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released the fifth versions of the tool [http://sqlmap.sourceforge.net sqlmap]. sqlmap is an automatic SQL injection tool entirely developed in Python. It is capable to perform an extensive database management system back-end fingerprint, retrieve remote DBMS databases, usernames, tables, columns, enumerate entire DBMS, read system files and much more taking advantage of web application programming security flaws that lead to SQL injection vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
You can download the latest stable version from its [https://sourceforge.net/project/showfiles.php?group_id=171598&amp;amp;package_id=196107 SourceForge File List page] or the latest development version from its [https://sqlmap.svn.sourceforge.net/svnroot/sqlmap SourceForge SVN repository]. &lt;br /&gt;
&lt;br /&gt;
=== Dec, 2006 - sqlmap v0.2  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released a second version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://sqlmap.sourceforge.net/ Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
=== September, 2006 - Wisec Project  ===&lt;br /&gt;
&lt;br /&gt;
Stefano Di Paola is developing Wisec - The Wiki Security Project [http://www.wisec.it Here] you can accesses the project. &lt;br /&gt;
&lt;br /&gt;
=== July, 2006 - Sqlmap v0.0.1  ===&lt;br /&gt;
&lt;br /&gt;
Daniele Bellucci has developed a first version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://www.linux.it/~belch/?p=17 Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Chapter]]&lt;br /&gt;
[[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Security_5D_Framework&amp;diff=249129</id>
		<title>OWASP Software Security 5D Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Security_5D_Framework&amp;diff=249129"/>
				<updated>2019-03-21T15:54:20Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The new Minded Security Software Security 5D framework (now OWASP Software Security 5D framework) is derived from many years of experience performing software security assessment to many Companies and from the experience from the OWASP Community and in particular OWASP SAMM Community.&lt;br /&gt;
&lt;br /&gt;
Minded Security donated it to OWASP in September 2018.&lt;br /&gt;
&lt;br /&gt;
Traditional Secure SDLC frameworks lack of:&lt;br /&gt;
- level of awareness for all the people involved in the process&lt;br /&gt;
- description of the application security roles involved&lt;br /&gt;
- set of security standards&lt;br /&gt;
- security testing tools adopted&lt;br /&gt;
&lt;br /&gt;
OWASP SwSec 5D represents a more practical framework that focus on 5 dimensions to evaluate the maturity of a SDLC that are the following:&amp;lt;br&amp;gt;&lt;br /&gt;
- SwSec PROCESSES&amp;lt;br&amp;gt;&lt;br /&gt;
- SwSec TESTING&amp;lt;br&amp;gt;&lt;br /&gt;
- SwSec TEAM&amp;lt;br&amp;gt;&lt;br /&gt;
- SwSec AWARENESS&amp;lt;br&amp;gt;&lt;br /&gt;
- SwSec STANDARDS&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Software_Security_5D_Framework_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Project goal is to review the 5D framework and create an open source framework adopted by the OWASP Community.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Starting at October 2018.&lt;br /&gt;
By the end of the year:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Documentation Project &lt;br /&gt;
* Get other people to review the Documentation Project and provide feedback&lt;br /&gt;
* Incorporate feedback &lt;br /&gt;
* Finalize the Documentation Project and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;SwSec 5D project&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:matteo.meucci@owasp.org Matteo Meucci]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/9/92/OWASP_SwSec5D_Presentation_-_Oct18.pdf Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Software-Security-5D-Framework GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Software_Security_5D_Framework_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Mmeucci|Matteo Meucci]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[OWASP SAMM Project|OWASP SAMM]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Security_5D_Framework&amp;diff=249127</id>
		<title>OWASP Software Security 5D Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Security_5D_Framework&amp;diff=249127"/>
				<updated>2019-03-21T15:32:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The new Minded Security Software Security 5D framework (now OWASP Software Security 5D framework) is derived from many years of experience performing software security assessment to many Companies and from the experience from the OWASP Community and in particular OWASP SAMM Community.&lt;br /&gt;
&lt;br /&gt;
Minded Security donated it to OWASP in September 2018.&lt;br /&gt;
&lt;br /&gt;
Traditional Secure SDLC frameworks lack of:&lt;br /&gt;
- level of awareness for all the people involved in the process&lt;br /&gt;
- description of the application security roles involved&lt;br /&gt;
- set of security standards&lt;br /&gt;
- security testing tools adopted&lt;br /&gt;
&lt;br /&gt;
OWASP SwSec 5D represents a more practical framework that focus on 5 dimensions to evaluate the maturity of a SDLC that are the following:&amp;lt;br&amp;gt;&lt;br /&gt;
- SwSec PROCESSES&amp;lt;br&amp;gt;&lt;br /&gt;
- SwSec TESTING&amp;lt;br&amp;gt;&lt;br /&gt;
- SwSec TEAM&amp;lt;br&amp;gt;&lt;br /&gt;
- SwSec AWARENESS&amp;lt;br&amp;gt;&lt;br /&gt;
- SwSec STANDARDS&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Software_Security_5D_Framework_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Project goal is to review the 5D framework and create an open source framework adopted by the OWASP Community.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Starting at October 2018.&lt;br /&gt;
By the end of the year:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Documentation Project &lt;br /&gt;
* Get other people to review the Documentation Project and provide feedback&lt;br /&gt;
* Incorporate feedback &lt;br /&gt;
* Finalize the Documentation Project and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;SwSec 5D project&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:matteo.meucci@owasp.org Matteo Meucci]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/9/92/OWASP_SwSec5D_Presentation_-_Oct18.pdf Presentation]&lt;br /&gt;
[[File:OWASP_5D_Mar19.pdf]]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Software-Security-5D-Framework GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Software_Security_5D_Framework_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Mmeucci|Matteo Meucci]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[OWASP SAMM Project|OWASP SAMM]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249126</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249126"/>
				<updated>2019-03-21T15:06:29Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
Wiki home page:&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/a/aa/OWASPCloudTestingMar19.pdf Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/OWASP_Cloud_Testing_Guide GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Testing_Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASPCloudTestingMar19.pdf&amp;diff=249125</id>
		<title>File:OWASPCloudTestingMar19.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASPCloudTestingMar19.pdf&amp;diff=249125"/>
				<updated>2019-03-21T15:05:39Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249124</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249124"/>
				<updated>2019-03-21T14:41:11Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
Wiki home page:&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[File:OWASPCloudTestingMar19.pdf]] Presentation&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/OWASP_Cloud_Testing_Guide GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Testing_Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249123</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249123"/>
				<updated>2019-03-21T14:40:46Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
Wiki home page:&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[File:OWASPCloudTestingMar19.pdf Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/OWASP_Cloud_Testing_Guide GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Testing_Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249122</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249122"/>
				<updated>2019-03-21T14:40:00Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
Wiki home page:&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/9/92/OWASPCloudTestingMar19.pdf Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/OWASP_Cloud_Testing_Guide GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Testing_Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249121</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249121"/>
				<updated>2019-03-21T14:38:57Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
Wiki home page:&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/9/92/OWASPCloudTestingMar19 Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/OWASP_Cloud_Testing_Guide GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Testing_Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249119</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=249119"/>
				<updated>2019-03-21T14:35:56Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
Wiki home page:&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[OWASPCloudTestingSecSummit.pdf Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/OWASP_Cloud_Testing_Guide GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Testing_Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents&amp;diff=248742</id>
		<title>OWASP Cloud Testing Guide Table of Contents</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents&amp;diff=248742"/>
				<updated>2019-03-13T12:15:50Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Back to the OWASP Cloud Testing Guide project [[OWASP Cloud Testing Guide]]  &lt;br /&gt;
&lt;br /&gt;
Here is the draft index: &lt;br /&gt;
&lt;br /&gt;
Amazon AWS &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
- Testing S3 buckets &amp;lt;br&amp;gt;&lt;br /&gt;
-- Identify S3 buckets &amp;lt;br&amp;gt;&lt;br /&gt;
-- Testing listing bucket's content &amp;lt;br&amp;gt; &lt;br /&gt;
-- Testing for writing privileges on bucket &amp;lt;br&amp;gt; &lt;br /&gt;
-- Testing if bucket ACL can be read &amp;lt;br&amp;gt;&lt;br /&gt;
-- Testing if bucket ACL can be written &amp;lt;br&amp;gt;&lt;br /&gt;
-- Testing for &amp;quot;any authenticated AWS client&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
-- Leaked AWS S3 key secret &amp;lt;br&amp;gt;&lt;br /&gt;
-- References &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
- Testing Amazon EC2 &amp;lt;br&amp;gt; &lt;br /&gt;
-- Publicly accessible EC2 snapshots &amp;lt;br&amp;gt; &lt;br /&gt;
-- AWS Metadata leakage &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS Elastic Load Balancer &amp;lt;br&amp;gt; &lt;br /&gt;
-- AWS SNS &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS SQS &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS RDS &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS Cognito &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS CloudFront &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS-CLI tiny man &amp;lt;br&amp;gt;&lt;br /&gt;
-- Tools &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Google Cloud&amp;lt;br&amp;gt; &lt;br /&gt;
-- Doc &amp;lt;br&amp;gt;&lt;br /&gt;
-- Tools &amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents&amp;diff=248741</id>
		<title>OWASP Cloud Testing Guide Table of Contents</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents&amp;diff=248741"/>
				<updated>2019-03-13T12:15:09Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Back to the OWASP Cloud Testing Guide project [[OWASP Cloud Testing Guide]] &amp;lt;nowiki&amp;gt;&amp;lt;br&amp;gt;&amp;lt;/nowiki&amp;gt;  &lt;br /&gt;
&lt;br /&gt;
Here is the draft index: &lt;br /&gt;
&lt;br /&gt;
Amazon AWS &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
- Testing S3 buckets &amp;lt;br&amp;gt;&lt;br /&gt;
-- Identify S3 buckets &amp;lt;br&amp;gt;&lt;br /&gt;
-- Testing listing bucket's content &amp;lt;br&amp;gt; &lt;br /&gt;
-- Testing for writing privileges on bucket &amp;lt;br&amp;gt; &lt;br /&gt;
-- Testing if bucket ACL can be read &amp;lt;br&amp;gt;&lt;br /&gt;
-- Testing if bucket ACL can be written &amp;lt;br&amp;gt;&lt;br /&gt;
-- Testing for &amp;quot;any authenticated AWS client&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
-- Leaked AWS S3 key secret &amp;lt;br&amp;gt;&lt;br /&gt;
-- References &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
- Testing Amazon EC2 &amp;lt;br&amp;gt; &lt;br /&gt;
-- Publicly accessible EC2 snapshots &amp;lt;br&amp;gt; &lt;br /&gt;
-- AWS Metadata leakage &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS Elastic Load Balancer &amp;lt;br&amp;gt; &lt;br /&gt;
-- AWS SNS &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS SQS &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS RDS &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS Cognito &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS CloudFront &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS-CLI tiny man &amp;lt;br&amp;gt;&lt;br /&gt;
-- Tools &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Google Cloud&amp;lt;br&amp;gt; &lt;br /&gt;
-- Doc &amp;lt;br&amp;gt;&lt;br /&gt;
-- Tools &amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents&amp;diff=248740</id>
		<title>OWASP Cloud Testing Guide Table of Contents</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents&amp;diff=248740"/>
				<updated>2019-03-13T12:13:26Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Here is the draft index: &lt;br /&gt;
&lt;br /&gt;
Amazon AWS &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
- Testing S3 buckets &amp;lt;br&amp;gt;&lt;br /&gt;
-- Identify S3 buckets &amp;lt;br&amp;gt;&lt;br /&gt;
-- Testing listing bucket's content &amp;lt;br&amp;gt; &lt;br /&gt;
-- Testing for writing privileges on bucket &amp;lt;br&amp;gt; &lt;br /&gt;
-- Testing if bucket ACL can be read &amp;lt;br&amp;gt;&lt;br /&gt;
-- Testing if bucket ACL can be written &amp;lt;br&amp;gt;&lt;br /&gt;
-- Testing for &amp;quot;any authenticated AWS client&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
-- Leaked AWS S3 key secret &amp;lt;br&amp;gt;&lt;br /&gt;
-- References &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
- Testing Amazon EC2 &amp;lt;br&amp;gt; &lt;br /&gt;
-- Publicly accessible EC2 snapshots &amp;lt;br&amp;gt; &lt;br /&gt;
-- AWS Metadata leakage &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS Elastic Load Balancer &amp;lt;br&amp;gt; &lt;br /&gt;
-- AWS SNS &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS SQS &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS RDS &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS Cognito &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS CloudFront &amp;lt;br&amp;gt;&lt;br /&gt;
-- AWS-CLI tiny man &amp;lt;br&amp;gt;&lt;br /&gt;
-- Tools &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Google Cloud&amp;lt;br&amp;gt; &lt;br /&gt;
-- Doc &amp;lt;br&amp;gt;&lt;br /&gt;
-- Tools &amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents&amp;diff=248739</id>
		<title>OWASP Cloud Testing Guide Table of Contents</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents&amp;diff=248739"/>
				<updated>2019-03-13T11:34:20Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Here is the draft index: &lt;br /&gt;
&lt;br /&gt;
Amazon AWS &lt;br /&gt;
&lt;br /&gt;
- Testing S3 buckets &lt;br /&gt;
-- Identify S3 buckets &lt;br /&gt;
-- Testing listing bucket's content &lt;br /&gt;
-- Testing for writing privileges on bucket &lt;br /&gt;
-- Testing if bucket ACL can be read &lt;br /&gt;
-- Testing if bucket ACL can be written &lt;br /&gt;
-- Testing for &amp;quot;any authenticated AWS client&amp;quot; &lt;br /&gt;
-- Leaked AWS S3 key secret &lt;br /&gt;
-- References &lt;br /&gt;
&lt;br /&gt;
- Testing Amazon EC2 &lt;br /&gt;
-- Publicly accessible EC2 snapshots &lt;br /&gt;
-- AWS Metadata leakage &lt;br /&gt;
-- AWS Elastic Load Balancer &lt;br /&gt;
-- AWS SNS &lt;br /&gt;
-- AWS SQS &lt;br /&gt;
-- AWS RDS &lt;br /&gt;
-- AWS Cognito &lt;br /&gt;
-- AWS CloudFront &lt;br /&gt;
-- AWS-CLI tiny man &lt;br /&gt;
-- Tools &lt;br /&gt;
&lt;br /&gt;
Google Cloud &lt;br /&gt;
-- Doc &lt;br /&gt;
-- Tools&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248738</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248738"/>
				<updated>2019-03-13T11:28:39Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
Wiki home page:&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/OWASP_Cloud_Testing_Guide GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Testing_Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248737</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248737"/>
				<updated>2019-03-13T11:28:03Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
Wiki home page:&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/OWASP_Cloud_Testing_Guide GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Testing_Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248736</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248736"/>
				<updated>2019-03-13T11:25:32Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/OWASP_Cloud_Testing_Guide GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Testing_Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248734</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248734"/>
				<updated>2019-03-13T11:24:20Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/OWASP_Cloud_Testing_Guide GitHub]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide_Table_of_Contents Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	OWASP Testing Guide&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Testing_Guide]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248733</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248733"/>
				<updated>2019-03-13T11:01:10Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	OWASP Testing Guide&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Tool_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248732</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248732"/>
				<updated>2019-03-13T10:58:07Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;OWASP Cloud Testing Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	OWASP Testing Guide&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Tool_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248731</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248731"/>
				<updated>2019-03-13T10:55:18Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
Project roadmap&lt;br /&gt;
- (1) 1st phase: Brainstorming and create a new table of contents (1st April)&lt;br /&gt;
Objective: creating a new table of contents of the OWASP Cloud Testing Project &lt;br /&gt;
assigning a task for each contributor. &lt;br /&gt;
&lt;br /&gt;
- (2) 2nd phase: Writing (1st May) &lt;br /&gt;
1st April: Start writing the articles &lt;br /&gt;
1st June: publish the 1st Draft &lt;br /&gt;
15th September: end of the writing phase &lt;br /&gt;
&lt;br /&gt;
- (3) 3rd phase: Reviewing &lt;br /&gt;
- 15th September: Starting the review phase, &lt;br /&gt;
- 15th November: Create the RC1, &lt;br /&gt;
- 15th January 2020: Release version 1!&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;SwSec 5D project&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Please send an email to: [mailto:stefano@owasp.org Stefano Di Paola]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Stefano Di Paola&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Tool_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248730</id>
		<title>OWASP Cloud Testing Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Cloud_Testing_Guide&amp;diff=248730"/>
				<updated>2019-03-13T10:38:18Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The deliverable of the project will consist of a methodology to perform a Cloud Security Testing activity. &lt;br /&gt;
&lt;br /&gt;
The project will start analyzing the keys technologies used today to build an application on the cloud. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Documentation Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Documentation Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Documentation Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Documentation project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Documentation Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
This project is under the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Documentation Project Template&lt;br /&gt;
* Get other people to review the Documentation Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Documentation Project Template&lt;br /&gt;
* Finalize the Documentation Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Documentation Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Stefano Di Paola&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Tool_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy&amp;diff=247706</id>
		<title>Italy</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy&amp;diff=247706"/>
				<updated>2019-02-21T08:48:26Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 1&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[Image:OWASP-Italy.PNG]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== WELCOME  ====&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Italy|extra=The chapter leader is [mailto:matteo.meucci@owasp.org Matteo Meucci]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-italy|emailarchives=http://lists.owasp.org/pipermail/owasp-italy}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Italy&amp;lt;/paypal&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''NEXT EVENT: OWASP-Italy@Security Summit 2019''' ==&lt;br /&gt;
Thanks to CLUSIT, we will have Giuseppe Trotta and Lorenzo De Meo as speakers at the OWASP-Italy corner at the next Security Summit in Milan &amp;lt;br&amp;gt;&lt;br /&gt;
When: 14th March 2019 at 16:10-16:50&amp;lt;br&amp;gt;&lt;br /&gt;
Where: UNAHOTELS EXPO FIERA, via Keplero 12, Pero &amp;lt;br&amp;gt;&lt;br /&gt;
Participation is free, but you need to reserve your seat here: https://securitysummit.it/agenda-details/461&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''NEXT EVENT: OWASP/WIA initiatives - 26th March 2019''' ==&lt;br /&gt;
Thanks to Loredana Mancini and Zoe Braiterman we will have an OWASP-Italy /WIA initiatives at the Link Campus in Rome next 26th March.&amp;lt;br&amp;gt;&lt;br /&gt;
Venue: Link Campus University Via del Casale di San Pio V, 44 - 00165 Roma (RM)&lt;br /&gt;
&lt;br /&gt;
Speakers: Prof.ssa Paola Giannetakis (Link Campus University), Zoe Braiterman (OWASP/WIA Chair), Luciana Scognamiglio (Senior security expert /HPE), Matteo Meucci (OWASP-Italy Chair).&lt;br /&gt;
&lt;br /&gt;
== '''OWASP-Italy Cagliari Day 2018 - 19th October 2018''' ==&lt;br /&gt;
Università di Cagliari.&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day Cagliari 2018|Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
=='''OWASP-Italy Day 2018 @ Milano 16th June 2018''' ==&lt;br /&gt;
Politecnico of Milano&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2018 ==&lt;br /&gt;
OWASP Italy did participate to the Security Summit 2018 in Milan with 2 talks.&amp;lt;br&amp;gt;More information here: [https://www.securitysummit.it/agenda-details/333 https://www.securitysummit.it/agenda-details/93]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day 2017 @ Cagliari 20th October 2017 ==&lt;br /&gt;
Cagliari , 6th October 2017, Università di Cagliari&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2017]]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 6th October 2017 ==&lt;br /&gt;
'''V Conference on Application Security and Modern Technologies'''&lt;br /&gt;
&lt;br /&gt;
Mestre, 6th October 2017, Università Ca' Foscari&lt;br /&gt;
&lt;br /&gt;
http://www.isaca.org/chapters5/Venice/Pages/default.aspx&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2017 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2017 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
Antonio Parata will give a talk on EyePyramid malware and Fabrizio Bugli will talk about (3rd) Party like nobody's watching&lt;br /&gt;
&lt;br /&gt;
https://www.securitysummit.it/agenda-details/93&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP AppSec Europe 2016 in Rome! ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASPAppSecEU2016.jpg]]&lt;br /&gt;
&lt;br /&gt;
OWASP is organizing the next OWASP AppSecEU in Rome.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;See the agenda and buy your ticket here:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
http://2016.appsec.eu/&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2016 ==&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2016 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2016/seminari-associazioni/talk-257/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Adopt OSS. First Edition ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy is pleased to announce a new initiative: '''Adopt''' '''O'''pen'''S'''ource'''S'''oftware&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Given OWASP’s mission to help organizations with application security, we have established a new initiative to provide free, voluntary-based support to open source software projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Thanks to Adopt OSS, security enthusiasts are paired with participating open source projects, thus gaining exposure to real-life security engineering challenges and the opportunity for career growth. In turn, the participating projects are able to obtain free professional expertise to better improve their security posture, and ultimately build secure software. Over a six months period, OWASP Italy will facilitate the effort by coordinating the initiative and providing support when needed.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The first edition of this initiative will take place between ''May and November 2015'', and will see the participation of '''7 OWASP Italy members''' and '''3 major OpenSource projects'''. At the end of the six months period, OWASP Italy will publish results and feedback from both volunteers and OSS maintainers.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The official flyer can be [https://www.owasp.org/images/0/07/AdoptOSSManifest-OWASPItaly.pdf downloaded from here].&lt;br /&gt;
&lt;br /&gt;
===Ntopng===&lt;br /&gt;
''Alessio Petracca, Mattia Folador, Giuseppe Longo''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.ntop.org/products/traffic-analysis/ntop/ Ntop] is the de-facto standard for real-time network traffic monitoring. OWASP Italy wants to help the project by increasing the security level of ntopng, performing security testing activities and supporting the remediation process.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will act in two steps:&lt;br /&gt;
* First, a penetration test targeting the web interface of ntopng will be performed, following the [https://www.owasp.org/index.php/OWASP_Testing_Guide_v3_Table_of_Contents OWASP Testing Methodology]&lt;br /&gt;
* Secondly, source code review of ntopng main components (such as the C++ core engine) will be statically reviewed. The objective is to address all relevant checks contained within the [https://www.owasp.org/index.php/OWASP_Code_review_V2_Table_of_Contents OWASP Code Review Guide]&lt;br /&gt;
&lt;br /&gt;
In case the activities above are completed before the end of the six-months period, additional activities (such as the development of security plugins) will be discussed.&lt;br /&gt;
Luca Deri and Arianna Avanzini will support Alessio Petracca and Mattia Folador in these activities, by providing guidance and insights.&lt;br /&gt;
&lt;br /&gt;
===WordPress===&lt;br /&gt;
''Paolo Perego, Sandro Zaccarini''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://wordpress.org/ WordPress] is the facto standard for web publishing. If you need a blog, if you need a new showcase website for your portfolio or a tiny e-commerce web site for your small company you will look at WordPress to start.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Paying the cost to be the boss, WordPress during the years suffered tons of security issues, 3 major issues only in the beginning of May 2015. Either the core, plugins and themes are developed with easy to use in mind and they need to be hardened.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Italy wants to support WordPress adopting it with the &amp;quot;Stand by WordPress&amp;quot; initiative. We will deploy the software in three different standard configurations: blog, company's portfolio and e-commerce.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will do continuous appsec during development of 4.3 version in order to quickly spot security issues before the August release. In addition, we will take care of hardening guidelines and both plugins and themes subsystems in order to improve the overall architecture.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You can follow the progress of the &amp;quot;Stand by WordPress&amp;quot; initiative here: https://standbywordpress.wordpress.com&lt;br /&gt;
&lt;br /&gt;
===GlobaLeaks===&lt;br /&gt;
''Luca Carettoni, Giovanni Cerrato, Marco Lancini''&lt;br /&gt;
&lt;br /&gt;
[https://www.globaleaks.org/ GlobaLeaks] is the first open-source whistleblowing framework. It empowers anyone to easily set up and maintain an anonymous whistleblowing platform.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Considering the potential hostile environments in which the application may be hosted, security vulnerabilities and abuses are primary concerns for GlobaLeaks’ maintainers.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We want to help the team in their excellent application security practices, by performing vulnerability research activities in order to discover unknown bugs within the boundaries of their specific [https://docs.google.com/document/d/1niYFyEar1FUmStC03OidYAIfVJf18ErUFwSWCmWBhcA/pub threat model]. In particular, we will be focusing on two main software components (GLBackend and GLClient) and new security-relevant changes (upcoming authentication re-factoring and end-to-end encryption).&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information on '''Adopt OSS''', please send an email to [mailto:owasp-italy@lists.owasp.org owasp-italy@lists.owasp.org]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2015 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2015 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2015/seminari-associazioni/talk-140/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Rome 11-12th December 2014 ==&lt;br /&gt;
The agenda is online! &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
http://www.isacaroma.it/images/owasp_agenda_11-12-12-2014.JPG&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 3rd October 2014 ==&lt;br /&gt;
The agenda: &amp;lt;br&amp;gt;&lt;br /&gt;
[[File:Venice2014.jpg]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Here is the [https://www.owasp.org/images/d/d3/OWASPVenice2014.pdf flyer]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day @ the University of Genova (14th May 2014) ==&lt;br /&gt;
Thank to the collaboration with [http://www.ai-lab.it/armando Prof. Alessandro Armando] and to the availability of Gary McGraw, Ph.D. CTO, Cigital we are planning an incredible [https://www.owasp.org/index.php/Italy_OWASP_Day_2014_Genova OWASP Day next 14th May].&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2014 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2014 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2014/seminari-associazioni/talk-34/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP EU Tour 2013 - 27th June - Rome==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;{{:EUTour2013 header}}&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with Università Degli Studi Roma Tre, next 27th June we will have the OWASP EU Tour Rome Conference.&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Europe TOUR, is an event across the European region that promotes awareness about application security, so that people and organizations can make informed decisions about true application security risks. &amp;lt;br&amp;gt;Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.&lt;br /&gt;
&lt;br /&gt;
The conference will be held at Università Degli Studi Roma Tre. Address: Via Vito Volterra, 62, Rome.&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/EUTour2013_Rome_Agenda Here you can find the agenda and all the information to participate]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2013 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy participated to the Security Summit 2013 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[http://milano2013.securitysummit.it/eventi/view/35 See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy Day 2012: &amp;quot;Web Security in a Mobile World&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;center&amp;gt;[[File:OWASPITDay2012.jpg]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Italy OWASP Italy chapter] will host the OWASP Italy Day 2012 conference in Rome, Italy at the University of Rome La Sapienza next 23rd November 2012.&lt;br /&gt;
&lt;br /&gt;
More information [https://www.owasp.org/index.php?title=Italy_OWASP_Day_2012 here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Board  ==&lt;br /&gt;
&lt;br /&gt;
*This is the '''OWASP-Italy Board''':&lt;br /&gt;
Founder and Chair: Matteo Meucci (Jan 2005)&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Italy Board: Paolo Perego, Luca Carettoni, Antonio Parata, Giorgio Fedon, Stefano Di Paola, Mauro Bregolin, Claudio Merloni, Raoul Chiesa.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Partnerships  ====&lt;br /&gt;
&lt;br /&gt;
*ISC2-Italian Chapter: Thanks to Marco Misitano, Paolo Ottolino and Claudio Sasso, OWASP Italy collaborates with the ISC2-Italian Chapter for new initiatives regarding Security Conferences, articles and contentes regarding SDLC.&lt;br /&gt;
&lt;br /&gt;
[http://www.isc2chapter-italy.it https://www.owasp.org/images/a/a3/ISC2Italy.jpg]&lt;br /&gt;
&lt;br /&gt;
*CSA Italy Partnership&lt;br /&gt;
&lt;br /&gt;
[http://chapters.cloudsecurityalliance.org/italy/ https://www.owasp.org/images/6/6a/CSAItalylogo.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Alberto Manfredi (CSA Italy President) we are starting a collaboration with the Italian Chapter of the Cloud Security Alliance.&lt;br /&gt;
&lt;br /&gt;
*IsecLab Partnership&lt;br /&gt;
&lt;br /&gt;
[http://www.iseclab.org http://www.owasp.org/images/4/4b/LogoIsecLab.png]&lt;br /&gt;
&lt;br /&gt;
We are beginning a collaboration with David Balzarotti and Marco Balduzzi of International Secure Systems Lab(IsecLab) with the goal of sharing and improving new WebAppSec projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*CLUSIT Member&lt;br /&gt;
&lt;br /&gt;
http://www.clusit.it/logo_clusit/clusit_logo_b130.gif &lt;br /&gt;
&lt;br /&gt;
Thanks to CLUSIT and OWASP Foundation we have established a cross-membership between the two organizations. So OWASP-Italy is now a [http://www.clusit.it/soci.htm CLUSIT member] and CLUSIT is an OWASP Educational Member.&lt;br /&gt;
&lt;br /&gt;
*ISACA Rome&lt;br /&gt;
&lt;br /&gt;
[http://www.isacaroma.it http://www.owasp.org/images/9/98/Isacaroma.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Ugo Spaziani, we are developing seminars and new ideas with ISACA Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2012 ==&lt;br /&gt;
- 21st March 2012, OWASP Italy will present 3 talks:&lt;br /&gt;
&lt;br /&gt;
- Antonio Parata e Paolo Perego:&amp;quot;Security Testing for developers&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;Banking Malware evolution in Italy: defense approach&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Stefano Di Paola:&amp;quot;DOM Xss: la nuova generazione di vulnerabilità applicative&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
Please subscribe for free here: https://www.securitysummit.it/eventi/view/21&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2011 ==&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''OWASP Books are out!'''&lt;br /&gt;
&lt;br /&gt;
Now you can download or buy a book on the OWASP Projects. Check it here: http://stores.lulu.com/owasp &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Activities  ====&lt;br /&gt;
&lt;br /&gt;
*(Jun 10): OWASP Testing Guide presentation at FBK (Fondazione Bruno Kessler). &lt;br /&gt;
&lt;br /&gt;
*(May 10): OWASP Training at London: last 28th May in London, OWASP leaders deliver a course focused on the main OWASP Projects. This course aims to change that by providing a selection of mature and enterprise ready projects together with practical examples of how to use them. &lt;br /&gt;
This Course was FREE for OWASP Members. &lt;br /&gt;
http://www.owasp.org/index.php/London/Training/OWASP_projects_and_resources_you_can_use_TODAY&lt;br /&gt;
&lt;br /&gt;
*(Jan 09) OWASP Testing Guide v3 is finished! You can download or browse it [http://www.owasp.org/index.php/Category:OWASP_Testing_Project here]&lt;br /&gt;
&lt;br /&gt;
*(Mar 07) Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) )&lt;br /&gt;
&lt;br /&gt;
[http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
*(Oct 06) ISACA Roma has published several interview with OWASP-Italy members:&lt;br /&gt;
&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli]] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/328 Carlo Pelliccioni]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Paolo Perego has created the new '''OWASP Orizon Project'''. Go to [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Matteo Meucci has been selected as the new editor of the '''OWASP Testing Guide v2'''. See OWASP [http://www.owasp.org/index.php/OWASP_Autumn_Of_Code_2006_:_Selected_Projects_Press_Release press release] and go to [http://www.owasp.org/index.php/OWASP_Autumn_of_Code_2006_-_Projects:_Testing_Guide OWASP Testing Project v2]&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Carlo Pelliccioni is writing an article about the [http://www.owasp.org/index.php/Analysis_about_error_codes analysis of error codes] received by web servers.&lt;br /&gt;
&lt;br /&gt;
*Top10 Vulnerabilities - OWASP-Italy survey:&lt;br /&gt;
&lt;br /&gt;
[[Image:Top 10 vulnerabilities-mini.GIF]] &lt;br /&gt;
&lt;br /&gt;
*(21 Jun 06) '''Infosecurity 2006''': the event is organized and managed by the CLUSIT.&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. [http://www.infosecurity.it/Roma/programma.php More info here] &lt;br /&gt;
&lt;br /&gt;
*(1 Jun 06) '''&amp;quot;Quaderno CLUSIT&amp;quot;'''&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but will be made public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
*(31 May 06) Luca Carettoni has published the article '''&amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;.''' [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article.&lt;br /&gt;
&lt;br /&gt;
*(1 Mar 06) '''OWASP-Boston, Microsoft'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler, Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting. [http://www.owasp.org/local/boston.html More info here] &lt;br /&gt;
&lt;br /&gt;
*(18 Nov 05) '''IDC - European Banking Forum'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we will have a great speech at the [http://www.idc.com/italy/events/banking05/banking05_agenda.jsp IDC European IT Banking Forum 2005]. Agenda: - New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair - Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy &lt;br /&gt;
&lt;br /&gt;
*(Oct 05) '''SMAU 2005''' is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy.&lt;br /&gt;
&lt;br /&gt;
SMAU has accepted our submission! [http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili More info here] &lt;br /&gt;
&lt;br /&gt;
*(Giu 05) Thanks to Massimiliano Graziani we have translated in italian the '''&amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;'''. You can download it [http://www.owasp.org/documentation/testing.html here.]&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
*(May 05) '''ISACA Roma Newsletter''' has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005.&lt;br /&gt;
&lt;br /&gt;
*The presentation of the seminar we have done in '''ISACA Rome''' (31th March 2005) is now available [http://www.isacaroma.it/pdf/050331/meucci.zip here.]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)].&lt;br /&gt;
&lt;br /&gt;
*(Mar 05) Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here].&lt;br /&gt;
&lt;br /&gt;
*[http://www.isacaroma.it/html/newsletter/?q=node/78 Here] you can read an interview talking about OWASP. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Events  ====&lt;br /&gt;
&lt;br /&gt;
=== 15th March, 2011 - OWASP-Italy@Security Summit ===&lt;br /&gt;
&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
=== November, 2010 - OWASP-Italy Day V  ===&lt;br /&gt;
&lt;br /&gt;
- OWASP Day for E-Gov 2010: 9th November 2010 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
An event organized by Consip. More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_10 here]&lt;br /&gt;
&lt;br /&gt;
=== November, 2009 - OWASP-Italy Day IV  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Following on from the great success of last OWASP Days the forth conference has taken place in November 2009 in Milan. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_4 here]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Day for E-Gov 2009: 5th November 2009 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_09 here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2009 - OWASP-Italy @ PCI Milan  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Testing Guide and PCI-DSS Standard at the [http://www.pci-portal.com/lang-en/events/event-info/pcimilan PCI Milan event] last 31st March. &lt;br /&gt;
&lt;br /&gt;
The presentation is published [http://www.owasp.org/images/3/38/MeucciPciMilan09.pdf here] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 23rd February, 2009 - OWASP Day III  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_3 &amp;quot;Web Application Security: research meets industry&amp;quot;] &amp;lt;br&amp;gt; Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== 10th October, 2008 - Isaca Roma PCM 2008 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci presented the new OWASP Projects and the Application Security in the Italian Companies. More information [http://www.isacaroma.it/html/ArchivioEventi-081010.html here] &lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2008 - OWASP Day II  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_2 &amp;quot;The State of the Art of the Web Application Security and the OWASP guidelines in the Companies&amp;quot;] Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== February 2008 - OWASP Italy at InfoSecurity 2008  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
5th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - The Owasp Orizon project: internals and hands on&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_94.aspx Paolo Perego] &lt;br /&gt;
&lt;br /&gt;
6th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - Costruire Software Sicuro dalle Fondamenta&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_128.aspx Antonio Parata] &lt;br /&gt;
&lt;br /&gt;
7th February: &lt;br /&gt;
&lt;br /&gt;
*10:30 - Tu programmi. Io buco.&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_137.aspx Luca Carettoni] &lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it Here] you can read more information about it. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== November 30th, 2007 - OWASP-Italy @ Elsag Datamat Security Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Guidelines and SDLC Security at the Elsag Datamat Security Forum 2007 &amp;lt;br&amp;gt;Where: Pescara &amp;lt;br&amp;gt;When: 30th November 2007, h.12.30 &lt;br /&gt;
&lt;br /&gt;
=== October 20th, 2007 - OWASP Italy at SMAU E-Academy 2007  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Last 20th October 2007 we had 5 speeches at SMAU E-Academy 2007, here you can download our presentations: &lt;br /&gt;
&lt;br /&gt;
*Giorgio Fedon, COO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/.pdf &amp;quot;Dove sono finiti i miei soldi? Internet Banking e Cross Site Scripting&amp;quot;] (coming soon) [[Image:FedonSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Paolo Perego, Senior Security Consultant at Spike Reply:&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/7/79/PeregoSMAU07.ppt &amp;quot;The Owasp Orizon project - bring security at the source&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Antonio Parata, Security Consultant at eMaze:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Valutazione del rischio tramite la logica fuzzy&amp;quot; (coming soon) [[Image:ParataSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Alberto Revelli, Senior Security Consultant at Portcullis Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/9/9f/RevelliSMAU07.pdf &amp;quot;Anti-Anti-XSS: bypass delle difese del browser&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, CTO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Cros-site Flashing! Gli attacchi Web di ultima generazione parlano multipiattaforma&amp;quot; (coming soon) [[Image:DiPaolaSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== September 10th, 2007 - OWASP Day WorldWide: &amp;quot;Privacy in the 21st Century&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Italy_OWASP_Day_1 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 29th, 2007 - Seminar: &amp;quot;Software Security&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, Paolo Perego and Matteo Meucci will talk at the Seminar: [http://www.sicurinfo.it/informazioni/visinf.asp?IDInfo=246&amp;amp;CAT=53 &amp;quot;Which approaches to Software Security&amp;quot;] organized by Firenze Tecnologia.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 15th-17th, 2007 - 6th OWASP AppSec Conference in Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We are in the initial planning stages for the next OWASP Europe conference, which we plan to hold in Italy in May 2007.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/6th_OWASP_AppSec_Conference_-_Italy_2007 Here] you can find all the details about the conference, cfp and sponsorship. &lt;br /&gt;
&lt;br /&gt;
=== April 14th, 2007 - Master on Information Security, University of Rome &amp;quot;La Sapienza&amp;quot; ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We have done a 4h seminar for the students of [http://mastersicurezza.uniroma1.it/ Master on Information Security at &amp;quot;La Sapienza&amp;quot;] for the [http://icsecurity.di.uniroma1.it/dokuwiki/doku.php?id=projects:asp Application Security Project of &amp;quot;La Sapienza&amp;quot; University.]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 30th, 2007 - University of Rome &amp;quot;La Sapienza&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Thanks to Prof. Mancini and Roberto D'Addario, we will talk about OWASP at the convention &amp;quot;Institutions, Companies and Information Security: comparing the problems&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[http://w3.uniroma1.it/security/Eventi/eventi.html Here] you can find more details. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2007 - EuSecWest 07  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci presented the new OWASP Testing Guide at [http://www.eusecwest.com/agenda.html EUSecWest]. [http://www.owasp.org/images/e/e9/OWASP_Testing_Guide_Presentation_EUSecWest07.zip Here] you take a look at the presentation. &lt;br /&gt;
&lt;br /&gt;
=== February 6th-8th, 2007 - InfoSecurity  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*February 6th:15.30&lt;br /&gt;
&lt;br /&gt;
After the great success obtained form CCC at Berlin, Stefano Di Paola and Giorgio Fedon will talk about:&amp;quot; Web Security Client Side: attacks at Web 2.0&amp;quot; More information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=aqfi82GOKd6I748s1evI8Q%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 6th:16.30&lt;br /&gt;
&lt;br /&gt;
After the great effort on the Testing Guide Project, Matteo Meucci and Alberto Revelli will present: &amp;quot;The new OWASP Testing Guide&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=nq6tSIuRoPVJBanBSsRiSQ%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 7th:12.30&lt;br /&gt;
&lt;br /&gt;
Authors of innovative SQL injection tools, Alberto Revelli and Antonio Parata will show: &amp;quot;Advanced SQL Injection: testing tools and defensive strategies.&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=3z04F5BgZRgfU0YX8JRYtA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here] &lt;br /&gt;
&lt;br /&gt;
*February 7th:13.30&lt;br /&gt;
&lt;br /&gt;
Author of the new OWASP Orizon project, Paolo Perergo will present:&amp;quot;Secure programming: from theory to practice&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=9HePIzyo5p29ylpGBl6CiA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
=== January 25th, 2007 - Isaca Rome  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci will discuss the new [http://www.owasp.org/index.php/Category:OWASP_Testing_Project OWASP Testing Guide v2]&amp;lt;br&amp;gt; For more information:&amp;lt;br&amp;gt; http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
=== October 7th, 2006 - SMAU 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''The quest for secure code: code review and fundamental of secure coding.''&amp;quot; Matteo Meucci will present an introduction to the new OWASP Projects and OWASP-Italy activities. Paolo Perego (sp0nge) will speak about safe coding and the importance of code periodic review as natural software life cycle. Paolo will give a vision on code review and its phases http://www.webb.it/event/eventview/5772 &lt;br /&gt;
&lt;br /&gt;
Here are the presentations: &amp;lt;br&amp;gt; [[Image:Meucci SMAU06.pdf|Meucci_SMAU06]] &amp;lt;br&amp;gt; [[Image:Perego SMAU06.pdf|Perego_SMAU 06]] &lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''Advanced SQL Injection.''&amp;quot; Antonio Parata (S4tan) will explain SQL Injection, and how SQL Inference works on PHP/MySql platform. He will present an open source tool to support the testing. Alberto Revelli (icesurfer) will focus on Microsoft SQL Server: he will perform a live demo of sqlninja (http://sqlninja.sf.net), explaining how to obtain a pseudo-shell over SQL, how to escalate privileges, and how to play with the exotic equation: &amp;quot;SQL Injection + debug.exe + DNS = DOS prompt&amp;quot;&amp;amp;nbsp;! http://www.webb.it/event/eventview/5774 &lt;br /&gt;
&lt;br /&gt;
[[Image:Revelli SMAU06.pdf|Revelli_SMAU06]] &amp;lt;br&amp;gt; [[Image:Parata SMAU06.pdf|Parate_SMAU06]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP-Italy at SMAU06 2.JPG]] Luca, Carlo, Alberto, Antonio, Stefano &amp;lt;br&amp;gt; Matteo, Paolo, Giorgio &lt;br /&gt;
&lt;br /&gt;
=== September 29th, 2006 - OpenExp 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
September 30th, at 10:45 Antonio Parata (S4tan) will speak about SQL Injection: techniques, tools and practical examples. &lt;br /&gt;
&lt;br /&gt;
Abstract: Antonio will introduce some basic concepts about software security. It will be shown how SQL Inference works on PHP/MySql platform and presented an open source tool to support the testing. Finally will be listed some advises to avoid common bugs. http://www.openexp.it/ &lt;br /&gt;
&lt;br /&gt;
OWASP-Italy will have a stand from September 29th to October 1st. &lt;br /&gt;
&lt;br /&gt;
[[Image:Antonio Matteo Carlo.JPG]] [[Image:Antonio speech.JPG]] [[Image:Carlo.JPG]] [[Image:Claudio Luca.JPG]] [[Image:Mayhem Matteo.JPG]] [[Image:OWASP Banner2.JPG]] [[Image:OWASP Banner.JPG]] &lt;br /&gt;
&lt;br /&gt;
=== June 21th, 2006 - InfoSecurity 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. The event is organized and managed by the CLUSIT. &lt;br /&gt;
&lt;br /&gt;
Where: Sheraton Roma Hotel - Viale Del Pattinaggio, 100 When: 10,30 - 17,00 Who: Matteo Meucci and Alberto Revelli Link: http://www.infosecurity.it/Roma/programma.php &lt;br /&gt;
&lt;br /&gt;
Agenda: -- I Session -- Introduction to Web Application Security • Which are the risks? • Risk assessment of a web application • Core pillars of web security How to develop secure web applications: • Guidelines and case-studies &lt;br /&gt;
&lt;br /&gt;
-- II Session -- How to realize a security audit of a web application • The methodology OWASP Penetration Testing • The tools: OWASP WebScarab • Hands-on web application vulnerabilities: OWASP WebGoat • Advanced SQL Injection. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2006 - OWASP-Boston, Microsoft  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler (OWASP-Boston Chair), Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting of march. [http://www.owasp.org/index.php/Boston More info here] &lt;br /&gt;
&lt;br /&gt;
=== November 5th, 2005 - IDC - European Banking Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we have had a great speech at the IDC European IT Banking Forum 2005 (18 Nov 2005). http://www.idc.com/italy/events/banking05/banking05_agenda.jsp Agenda: &lt;br /&gt;
&lt;br /&gt;
*New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair &lt;br /&gt;
*Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy.&lt;br /&gt;
&lt;br /&gt;
You can download the report [http://cdn.idc.com/italy/downloads/report_banking05_eng.pdf here]. &lt;br /&gt;
&lt;br /&gt;
You can download the Case-Study of a vulnerable Home Banking Web Application [http://www.owasp.org/docroot/owasp/misc/IDC_BankingForum05v1.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== October 5th, 2005 - OWASP-Italy@SMAU2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
SMAU is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy. Alberto Revelli (our Technical Director) and Matteo Meucci have conducted a seminar talking about Web Application Security. Alberto has presented his new project: [http://sqlninja.sourceforge.net sqlninja]. Very cool!! &lt;br /&gt;
&lt;br /&gt;
http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili &lt;br /&gt;
&lt;br /&gt;
=== May 25th, 2005 - ISACA Rome 2nd meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
May 25th we'll be in ISACA Rome to present OWASP WebGoat and a real case of a Web Application Vulnerability. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.30 Registration 14.45 Matteo Meucci - Web Application Security Phase II - OWASP WebScarab and PenTest Checklist &lt;br /&gt;
&lt;br /&gt;
*A case-study of a Web Application Vulnerability: MMS Spoofing&lt;br /&gt;
&lt;br /&gt;
--- Web Application analysis --- Authentication and Billing of the MMS service --- Vulnerabilities --- Attack Analysis &lt;br /&gt;
&lt;br /&gt;
*Learning the most common web application vulnerabilities: OWASP WebGoat&lt;br /&gt;
&lt;br /&gt;
--- Http Basics --- HTML Clues --- Hidden Field Tampering --- How to spoof a Session Cookie --- Stored Cross Site Scripting --- Command Injection --- SQL Injection --- Fail Open Authentication &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050525/OWASP.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== May 18th, 2005 - Workshop on Computer Crime 2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; May 18th, 2005 OWASP-Italy is invited to present OWASP Top 10 to the &amp;quot;Workshop on Computer Crime 2005&amp;quot; titled: &amp;quot;EVOLUZIONI NORMATIVE E RECENTI PROBLEMATICHE DI SICUREZZA&amp;quot; &lt;br /&gt;
&lt;br /&gt;
The meeting is held at: Sala delle conferenze dell'Istituto Centrale della Banche Popolari Italiane Via Verziere, 11 &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.owasp.org/images/a/aa/Top10-ComputerCrimes.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== March 31th, 2005 - ISACA Rome meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March 31th we'll be in ISACA Rome to present OWASP and the Web Application Security. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.15 Registration 14.30 Matteo Meucci - Web Application Security - OWASP Guide: how to build secure web application - How to test your Web Application: WebScarab and the WebApp PenTest Checklist - How to learn the most common web application vulnerability: WebGoat - The Top Ten WebApp vulnerabilities - Common error on developing Web Application: Authentication mechanisms not &amp;quot;secure&amp;quot; Buffer Overflow and crash of the service Thief of identity: Cross Site Scripting Manipulation of company data: SQL Injection Reserved information: misconfiguration Bad session management and thief of identity - OWASP-Italy: projects and next challenges &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050331/meucci.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== March 21th, 2005 - OWASP-Italy conducts a seminar in AlmaWeb  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March, the 21th OWASP-Italy has been invited at the University of Bologna to conduct a seminar regards to [http://www.almaweb.unibo.it/830.dyn Master in Management and Information Technology] titled “Web Application Security and OWASP”. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: - OWASP &amp;amp;amp; Web Application Security - Common Web Application Vulnerabilities - A real case of web application vulnerability: MMS Spoofing&amp;amp;amp;Billing - Training: WebGoat &lt;br /&gt;
&lt;br /&gt;
==== Publications  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== October 2009 Interview on &amp;quot;Il sole 24 ore&amp;quot;  ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/5/5c/Nova09.pdf Gary McGraw and Matteo Meucci] interviewed by NOVA, talking about BSIMM and OWASP.&lt;br /&gt;
&lt;br /&gt;
=== March, 2007 Interview on HTML.it  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) ) [http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
=== October, 2006 ISACA Roma interviews OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
After the speeches that OWASP-Italy has done at [http://www.smau.it/catnews.asp?l=2&amp;amp;codcat=385 SMAU E-Academy 2006], ISACA Roma has interviewed some of the people of the Italian chapter. Follow the links for the full interviews (in italian): &amp;lt;br&amp;gt; [[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli] ] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/322 Stefano Di Paola &amp;amp; Giorgio Fedon]] &lt;br /&gt;
&lt;br /&gt;
=== Aug, 2006 - Article on Banca Finanza magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Banca Finanza, the italian magazine about finance and banking, has interviewed Raoul Chiesa talking about the new risks for the on-line banking security. Raoul speaks about OWASP and web application security [[Media:042006BF.pdf]] &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Quaderno CLUSIT  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but it will be public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Paper on SQL Injection and Inference on PHP/MySQLInference  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Antonio &amp;quot;s4tan&amp;quot; Parata has published an article about SQL Injection based on Inference for testing web application on PHP/MySQL platform. [http://www.ictsc.it/papers/sqlInferenceOnMySql.html Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== May, 2006 - Published an article about OWASP and Top-10 Vulnerabilities  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published the article &amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;. [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== June, 2005 - OWASP Pen Test Checklist v 1.1 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Massimiliano Graziani we have translated in italian the &amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;. You can download it [http://www.owasp.org/documentation/testing.html here.] Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
=== May, 2005 - Isaca Roma Newsletter about OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
ISACA Roma Newsletter has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy] &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published &amp;quot;MMS Spoofing&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)]. &lt;br /&gt;
&lt;br /&gt;
Jim Hewitt, CISSP PMP working at CGI-AMS, affirms (slide#78): &amp;quot;Very interesting analysis of spoofed cell phone messaging and fraudulent billing&amp;quot;. See: www.techvalleynyissa.org/Resources/2005_07_WebApplicationSecurity.ppt &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published an article on ICT Security magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005. &lt;br /&gt;
&lt;br /&gt;
=== March, 2005 - OWASP Top-10 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here]. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
==== Tools &amp;amp;amp; Research  ====&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Nov, 2007 - sqlmap v0.5  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released the fifth versions of the tool [http://sqlmap.sourceforge.net sqlmap]. sqlmap is an automatic SQL injection tool entirely developed in Python. It is capable to perform an extensive database management system back-end fingerprint, retrieve remote DBMS databases, usernames, tables, columns, enumerate entire DBMS, read system files and much more taking advantage of web application programming security flaws that lead to SQL injection vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
You can download the latest stable version from its [https://sourceforge.net/project/showfiles.php?group_id=171598&amp;amp;package_id=196107 SourceForge File List page] or the latest development version from its [https://sqlmap.svn.sourceforge.net/svnroot/sqlmap SourceForge SVN repository]. &lt;br /&gt;
&lt;br /&gt;
=== Dec, 2006 - sqlmap v0.2  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released a second version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://sqlmap.sourceforge.net/ Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
=== September, 2006 - Wisec Project  ===&lt;br /&gt;
&lt;br /&gt;
Stefano Di Paola is developing Wisec - The Wiki Security Project [http://www.wisec.it Here] you can accesses the project. &lt;br /&gt;
&lt;br /&gt;
=== July, 2006 - Sqlmap v0.0.1  ===&lt;br /&gt;
&lt;br /&gt;
Daniele Bellucci has developed a first version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://www.linux.it/~belch/?p=17 Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Chapter]]&lt;br /&gt;
[[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy&amp;diff=247705</id>
		<title>Italy</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy&amp;diff=247705"/>
				<updated>2019-02-21T08:47:20Z</updated>
		
		<summary type="html">&lt;p&gt;Mmeucci: 2 events&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[Image:OWASP-Italy.PNG]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== WELCOME  ====&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Italy|extra=The chapter leader is [mailto:matteo.meucci@owasp.org Matteo Meucci]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-italy|emailarchives=http://lists.owasp.org/pipermail/owasp-italy}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Italy&amp;lt;/paypal&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''NEXT EVENT: OWASP-Italy@Security Summit 2019''' ==&lt;br /&gt;
Thanks to CLUSIT, we will have Giuseppe Trotta and Lorenzo De Meo as speakers at the OWASP-Italy corner at the next Security Summit in Milan &amp;lt;br&amp;gt;&lt;br /&gt;
When: 14th March 2019 at 16:10-16:50&amp;lt;br&amp;gt;&lt;br /&gt;
Where: UNAHOTELS EXPO FIERA, via Keplero 12, Pero &amp;lt;br&amp;gt;&lt;br /&gt;
Participation is free, but you need to reserve your seat here: https://securitysummit.it/agenda-details/461&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''NEXT EVENT: OWASP/WIA initiatives - 26th March 2019''' ==&lt;br /&gt;
Thanks to Loredana Mancini and Zoe Braiterman we will have an OWASP-Italy /WIA initiatives at the Link Campus in Rome next 26th March.&amp;lt;br&amp;gt;&lt;br /&gt;
Venue: Link Campus University Via del Casale di San Pio V, 44 - 00165 Roma (RM)&lt;br /&gt;
Speakers: Prof.ssa Paola Giannetakis (Link Campus University), Zoe Braiterman (OWASP/WIA Chair), Luciana Scognamiglio (Senior security expert /HPE), Matteo Meucci (OWASP-Italy Chair).&lt;br /&gt;
&lt;br /&gt;
== '''OWASP-Italy Cagliari Day 2018 - 19th October 2018''' ==&lt;br /&gt;
Università di Cagliari.&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day Cagliari 2018|Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
=='''OWASP-Italy Day 2018 @ Milano 16th June 2018''' ==&lt;br /&gt;
Politecnico of Milano&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2018]]&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2018 ==&lt;br /&gt;
OWASP Italy did participate to the Security Summit 2018 in Milan with 2 talks.&amp;lt;br&amp;gt;More information here: [https://www.securitysummit.it/agenda-details/333 https://www.securitysummit.it/agenda-details/93]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day 2017 @ Cagliari 20th October 2017 ==&lt;br /&gt;
Cagliari , 6th October 2017, Università di Cagliari&lt;br /&gt;
&lt;br /&gt;
More information here: [[Italy OWASP Day 2017]]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 6th October 2017 ==&lt;br /&gt;
'''V Conference on Application Security and Modern Technologies'''&lt;br /&gt;
&lt;br /&gt;
Mestre, 6th October 2017, Università Ca' Foscari&lt;br /&gt;
&lt;br /&gt;
http://www.isaca.org/chapters5/Venice/Pages/default.aspx&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2017 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2017 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
Antonio Parata will give a talk on EyePyramid malware and Fabrizio Bugli will talk about (3rd) Party like nobody's watching&lt;br /&gt;
&lt;br /&gt;
https://www.securitysummit.it/agenda-details/93&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP AppSec Europe 2016 in Rome! ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASPAppSecEU2016.jpg]]&lt;br /&gt;
&lt;br /&gt;
OWASP is organizing the next OWASP AppSecEU in Rome.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;See the agenda and buy your ticket here:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
http://2016.appsec.eu/&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2016 ==&lt;br /&gt;
OWASP Italy will participate to the Security Summit 2016 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2016/seminari-associazioni/talk-257/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Adopt OSS. First Edition ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy is pleased to announce a new initiative: '''Adopt''' '''O'''pen'''S'''ource'''S'''oftware&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Given OWASP’s mission to help organizations with application security, we have established a new initiative to provide free, voluntary-based support to open source software projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Thanks to Adopt OSS, security enthusiasts are paired with participating open source projects, thus gaining exposure to real-life security engineering challenges and the opportunity for career growth. In turn, the participating projects are able to obtain free professional expertise to better improve their security posture, and ultimately build secure software. Over a six months period, OWASP Italy will facilitate the effort by coordinating the initiative and providing support when needed.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The first edition of this initiative will take place between ''May and November 2015'', and will see the participation of '''7 OWASP Italy members''' and '''3 major OpenSource projects'''. At the end of the six months period, OWASP Italy will publish results and feedback from both volunteers and OSS maintainers.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The official flyer can be [https://www.owasp.org/images/0/07/AdoptOSSManifest-OWASPItaly.pdf downloaded from here].&lt;br /&gt;
&lt;br /&gt;
===Ntopng===&lt;br /&gt;
''Alessio Petracca, Mattia Folador, Giuseppe Longo''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.ntop.org/products/traffic-analysis/ntop/ Ntop] is the de-facto standard for real-time network traffic monitoring. OWASP Italy wants to help the project by increasing the security level of ntopng, performing security testing activities and supporting the remediation process.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will act in two steps:&lt;br /&gt;
* First, a penetration test targeting the web interface of ntopng will be performed, following the [https://www.owasp.org/index.php/OWASP_Testing_Guide_v3_Table_of_Contents OWASP Testing Methodology]&lt;br /&gt;
* Secondly, source code review of ntopng main components (such as the C++ core engine) will be statically reviewed. The objective is to address all relevant checks contained within the [https://www.owasp.org/index.php/OWASP_Code_review_V2_Table_of_Contents OWASP Code Review Guide]&lt;br /&gt;
&lt;br /&gt;
In case the activities above are completed before the end of the six-months period, additional activities (such as the development of security plugins) will be discussed.&lt;br /&gt;
Luca Deri and Arianna Avanzini will support Alessio Petracca and Mattia Folador in these activities, by providing guidance and insights.&lt;br /&gt;
&lt;br /&gt;
===WordPress===&lt;br /&gt;
''Paolo Perego, Sandro Zaccarini''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://wordpress.org/ WordPress] is the facto standard for web publishing. If you need a blog, if you need a new showcase website for your portfolio or a tiny e-commerce web site for your small company you will look at WordPress to start.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Paying the cost to be the boss, WordPress during the years suffered tons of security issues, 3 major issues only in the beginning of May 2015. Either the core, plugins and themes are developed with easy to use in mind and they need to be hardened.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Italy wants to support WordPress adopting it with the &amp;quot;Stand by WordPress&amp;quot; initiative. We will deploy the software in three different standard configurations: blog, company's portfolio and e-commerce.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will do continuous appsec during development of 4.3 version in order to quickly spot security issues before the August release. In addition, we will take care of hardening guidelines and both plugins and themes subsystems in order to improve the overall architecture.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You can follow the progress of the &amp;quot;Stand by WordPress&amp;quot; initiative here: https://standbywordpress.wordpress.com&lt;br /&gt;
&lt;br /&gt;
===GlobaLeaks===&lt;br /&gt;
''Luca Carettoni, Giovanni Cerrato, Marco Lancini''&lt;br /&gt;
&lt;br /&gt;
[https://www.globaleaks.org/ GlobaLeaks] is the first open-source whistleblowing framework. It empowers anyone to easily set up and maintain an anonymous whistleblowing platform.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Considering the potential hostile environments in which the application may be hosted, security vulnerabilities and abuses are primary concerns for GlobaLeaks’ maintainers.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We want to help the team in their excellent application security practices, by performing vulnerability research activities in order to discover unknown bugs within the boundaries of their specific [https://docs.google.com/document/d/1niYFyEar1FUmStC03OidYAIfVJf18ErUFwSWCmWBhcA/pub threat model]. In particular, we will be focusing on two main software components (GLBackend and GLClient) and new security-relevant changes (upcoming authentication re-factoring and end-to-end encryption).&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information on '''Adopt OSS''', please send an email to [mailto:owasp-italy@lists.owasp.org owasp-italy@lists.owasp.org]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2015 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2015 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2015/seminari-associazioni/talk-140/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Rome 11-12th December 2014 ==&lt;br /&gt;
The agenda is online! &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
http://www.isacaroma.it/images/owasp_agenda_11-12-12-2014.JPG&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Isaca Conference @ Venice 3rd October 2014 ==&lt;br /&gt;
The agenda: &amp;lt;br&amp;gt;&lt;br /&gt;
[[File:Venice2014.jpg]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Here is the [https://www.owasp.org/images/d/d3/OWASPVenice2014.pdf flyer]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Day @ the University of Genova (14th May 2014) ==&lt;br /&gt;
Thank to the collaboration with [http://www.ai-lab.it/armando Prof. Alessandro Armando] and to the availability of Gary McGraw, Ph.D. CTO, Cigital we are planning an incredible [https://www.owasp.org/index.php/Italy_OWASP_Day_2014_Genova OWASP Day next 14th May].&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== OWASP Italy  @ Security Summit 2014 ==&lt;br /&gt;
OWASP Italy participated to the Security Summit 2014 in Milan with 3 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.securitysummit.it/milano-2014/seminari-associazioni/talk-34/ See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP EU Tour 2013 - 27th June - Rome==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;{{:EUTour2013 header}}&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with Università Degli Studi Roma Tre, next 27th June we will have the OWASP EU Tour Rome Conference.&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Europe TOUR, is an event across the European region that promotes awareness about application security, so that people and organizations can make informed decisions about true application security risks. &amp;lt;br&amp;gt;Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.&lt;br /&gt;
&lt;br /&gt;
The conference will be held at Università Degli Studi Roma Tre. Address: Via Vito Volterra, 62, Rome.&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/EUTour2013_Rome_Agenda Here you can find the agenda and all the information to participate]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy  @ Security Summit 2013 ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy participated to the Security Summit 2013 in Milan with 2 talks.&amp;lt;br&amp;gt;&lt;br /&gt;
[http://milano2013.securitysummit.it/eventi/view/35 See here for all the details]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP Italy Day 2012: &amp;quot;Web Security in a Mobile World&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;center&amp;gt;[[File:OWASPITDay2012.jpg]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Italy OWASP Italy chapter] will host the OWASP Italy Day 2012 conference in Rome, Italy at the University of Rome La Sapienza next 23rd November 2012.&lt;br /&gt;
&lt;br /&gt;
More information [https://www.owasp.org/index.php?title=Italy_OWASP_Day_2012 here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Board  ==&lt;br /&gt;
&lt;br /&gt;
*This is the '''OWASP-Italy Board''':&lt;br /&gt;
Founder and Chair: Matteo Meucci (Jan 2005)&amp;lt;br&amp;gt;&lt;br /&gt;
OWASP Italy Board: Paolo Perego, Luca Carettoni, Antonio Parata, Giorgio Fedon, Stefano Di Paola, Mauro Bregolin, Claudio Merloni, Raoul Chiesa.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Partnerships  ====&lt;br /&gt;
&lt;br /&gt;
*ISC2-Italian Chapter: Thanks to Marco Misitano, Paolo Ottolino and Claudio Sasso, OWASP Italy collaborates with the ISC2-Italian Chapter for new initiatives regarding Security Conferences, articles and contentes regarding SDLC.&lt;br /&gt;
&lt;br /&gt;
[http://www.isc2chapter-italy.it https://www.owasp.org/images/a/a3/ISC2Italy.jpg]&lt;br /&gt;
&lt;br /&gt;
*CSA Italy Partnership&lt;br /&gt;
&lt;br /&gt;
[http://chapters.cloudsecurityalliance.org/italy/ https://www.owasp.org/images/6/6a/CSAItalylogo.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Alberto Manfredi (CSA Italy President) we are starting a collaboration with the Italian Chapter of the Cloud Security Alliance.&lt;br /&gt;
&lt;br /&gt;
*IsecLab Partnership&lt;br /&gt;
&lt;br /&gt;
[http://www.iseclab.org http://www.owasp.org/images/4/4b/LogoIsecLab.png]&lt;br /&gt;
&lt;br /&gt;
We are beginning a collaboration with David Balzarotti and Marco Balduzzi of International Secure Systems Lab(IsecLab) with the goal of sharing and improving new WebAppSec projects.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*CLUSIT Member&lt;br /&gt;
&lt;br /&gt;
http://www.clusit.it/logo_clusit/clusit_logo_b130.gif &lt;br /&gt;
&lt;br /&gt;
Thanks to CLUSIT and OWASP Foundation we have established a cross-membership between the two organizations. So OWASP-Italy is now a [http://www.clusit.it/soci.htm CLUSIT member] and CLUSIT is an OWASP Educational Member.&lt;br /&gt;
&lt;br /&gt;
*ISACA Rome&lt;br /&gt;
&lt;br /&gt;
[http://www.isacaroma.it http://www.owasp.org/images/9/98/Isacaroma.gif]&lt;br /&gt;
&lt;br /&gt;
Thanks to Ugo Spaziani, we are developing seminars and new ideas with ISACA Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2012 ==&lt;br /&gt;
- 21st March 2012, OWASP Italy will present 3 talks:&lt;br /&gt;
&lt;br /&gt;
- Antonio Parata e Paolo Perego:&amp;quot;Security Testing for developers&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;Banking Malware evolution in Italy: defense approach&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Stefano Di Paola:&amp;quot;DOM Xss: la nuova generazione di vulnerabilità applicative&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
Please subscribe for free here: https://www.securitysummit.it/eventi/view/21&lt;br /&gt;
&lt;br /&gt;
== Security Summit 2011 ==&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''OWASP Books are out!'''&lt;br /&gt;
&lt;br /&gt;
Now you can download or buy a book on the OWASP Projects. Check it here: http://stores.lulu.com/owasp &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Activities  ====&lt;br /&gt;
&lt;br /&gt;
*(Jun 10): OWASP Testing Guide presentation at FBK (Fondazione Bruno Kessler). &lt;br /&gt;
&lt;br /&gt;
*(May 10): OWASP Training at London: last 28th May in London, OWASP leaders deliver a course focused on the main OWASP Projects. This course aims to change that by providing a selection of mature and enterprise ready projects together with practical examples of how to use them. &lt;br /&gt;
This Course was FREE for OWASP Members. &lt;br /&gt;
http://www.owasp.org/index.php/London/Training/OWASP_projects_and_resources_you_can_use_TODAY&lt;br /&gt;
&lt;br /&gt;
*(Jan 09) OWASP Testing Guide v3 is finished! You can download or browse it [http://www.owasp.org/index.php/Category:OWASP_Testing_Project here]&lt;br /&gt;
&lt;br /&gt;
*(Mar 07) Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) )&lt;br /&gt;
&lt;br /&gt;
[http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
*(Oct 06) ISACA Roma has published several interview with OWASP-Italy members:&lt;br /&gt;
&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli]] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/328 Carlo Pelliccioni]]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Paolo Perego has created the new '''OWASP Orizon Project'''. Go to [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Matteo Meucci has been selected as the new editor of the '''OWASP Testing Guide v2'''. See OWASP [http://www.owasp.org/index.php/OWASP_Autumn_Of_Code_2006_:_Selected_Projects_Press_Release press release] and go to [http://www.owasp.org/index.php/OWASP_Autumn_of_Code_2006_-_Projects:_Testing_Guide OWASP Testing Project v2]&lt;br /&gt;
&lt;br /&gt;
*(Sep 06) Carlo Pelliccioni is writing an article about the [http://www.owasp.org/index.php/Analysis_about_error_codes analysis of error codes] received by web servers.&lt;br /&gt;
&lt;br /&gt;
*Top10 Vulnerabilities - OWASP-Italy survey:&lt;br /&gt;
&lt;br /&gt;
[[Image:Top 10 vulnerabilities-mini.GIF]] &lt;br /&gt;
&lt;br /&gt;
*(21 Jun 06) '''Infosecurity 2006''': the event is organized and managed by the CLUSIT.&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. [http://www.infosecurity.it/Roma/programma.php More info here] &lt;br /&gt;
&lt;br /&gt;
*(1 Jun 06) '''&amp;quot;Quaderno CLUSIT&amp;quot;'''&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but will be made public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
*(31 May 06) Luca Carettoni has published the article '''&amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;.''' [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article.&lt;br /&gt;
&lt;br /&gt;
*(1 Mar 06) '''OWASP-Boston, Microsoft'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler, Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting. [http://www.owasp.org/local/boston.html More info here] &lt;br /&gt;
&lt;br /&gt;
*(18 Nov 05) '''IDC - European Banking Forum'''&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we will have a great speech at the [http://www.idc.com/italy/events/banking05/banking05_agenda.jsp IDC European IT Banking Forum 2005]. Agenda: - New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair - Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy &lt;br /&gt;
&lt;br /&gt;
*(Oct 05) '''SMAU 2005''' is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy.&lt;br /&gt;
&lt;br /&gt;
SMAU has accepted our submission! [http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili More info here] &lt;br /&gt;
&lt;br /&gt;
*(Giu 05) Thanks to Massimiliano Graziani we have translated in italian the '''&amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;'''. You can download it [http://www.owasp.org/documentation/testing.html here.]&lt;br /&gt;
&lt;br /&gt;
Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
*(May 05) '''ISACA Roma Newsletter''' has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005.&lt;br /&gt;
&lt;br /&gt;
*The presentation of the seminar we have done in '''ISACA Rome''' (31th March 2005) is now available [http://www.isacaroma.it/pdf/050331/meucci.zip here.]&lt;br /&gt;
&lt;br /&gt;
*(Apr 05) We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)].&lt;br /&gt;
&lt;br /&gt;
*(Mar 05) Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here].&lt;br /&gt;
&lt;br /&gt;
*[http://www.isacaroma.it/html/newsletter/?q=node/78 Here] you can read an interview talking about OWASP. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Events  ====&lt;br /&gt;
&lt;br /&gt;
=== 15th March, 2011 - OWASP-Italy@Security Summit ===&lt;br /&gt;
&lt;br /&gt;
- 15th March 2011, OWASP-Italy presented a seminar about OWASP news. &amp;lt;br&amp;gt;&lt;br /&gt;
Here you can download the presentations:&amp;lt;br&amp;gt;&lt;br /&gt;
- Matteo Meucci: &amp;quot;[http://www.owasp.org/images/5/51/Security_Summit_2011_-_Meucci.pdf OWASP Future and the OWASP Guidelines: how your company can adopt it to obtain best results]&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
- Paolo Perego: &amp;quot;[http://www.owasp.org/images/2/20/I_tool_OWASP_per_la_sicurezza_del_software_20110315.pdf OWASP tools for the Software Security]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
- Giorgio Fedon: &amp;quot;[http://www.owasp.org/images/a/a0/Owasp_at_Security_Summit_2011_-_Mythbreaking_Automatic_Code_review_Tools.pdf Myth Busting Automatic Code Review tools]&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
More information here: https://www.securitysummit.it/eventi/view/24&lt;br /&gt;
&lt;br /&gt;
=== November, 2010 - OWASP-Italy Day V  ===&lt;br /&gt;
&lt;br /&gt;
- OWASP Day for E-Gov 2010: 9th November 2010 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
An event organized by Consip. More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_10 here]&lt;br /&gt;
&lt;br /&gt;
=== November, 2009 - OWASP-Italy Day IV  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Following on from the great success of last OWASP Days the forth conference has taken place in November 2009 in Milan. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_4 here]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP Day for E-Gov 2009: 5th November 2009 - Rome. &amp;lt;br&amp;gt;&lt;br /&gt;
More information [http://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_09 here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2009 - OWASP-Italy @ PCI Milan  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Testing Guide and PCI-DSS Standard at the [http://www.pci-portal.com/lang-en/events/event-info/pcimilan PCI Milan event] last 31st March. &lt;br /&gt;
&lt;br /&gt;
The presentation is published [http://www.owasp.org/images/3/38/MeucciPciMilan09.pdf here] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 23rd February, 2009 - OWASP Day III  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_3 &amp;quot;Web Application Security: research meets industry&amp;quot;] &amp;lt;br&amp;gt; Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== 10th October, 2008 - Isaca Roma PCM 2008 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci presented the new OWASP Projects and the Application Security in the Italian Companies. More information [http://www.isacaroma.it/html/ArchivioEventi-081010.html here] &lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2008 - OWASP Day II  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_2 &amp;quot;The State of the Art of the Web Application Security and the OWASP guidelines in the Companies&amp;quot;] Presentations are online! &lt;br /&gt;
&lt;br /&gt;
=== February 2008 - OWASP Italy at InfoSecurity 2008  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
5th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - The Owasp Orizon project: internals and hands on&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_94.aspx Paolo Perego] &lt;br /&gt;
&lt;br /&gt;
6th February: &lt;br /&gt;
&lt;br /&gt;
*14:30 - Costruire Software Sicuro dalle Fondamenta&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_128.aspx Antonio Parata] &lt;br /&gt;
&lt;br /&gt;
7th February: &lt;br /&gt;
&lt;br /&gt;
*10:30 - Tu programmi. Io buco.&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_137.aspx Luca Carettoni] &lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it Here] you can read more information about it. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== November 30th, 2007 - OWASP-Italy @ Elsag Datamat Security Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Guidelines and SDLC Security at the Elsag Datamat Security Forum 2007 &amp;lt;br&amp;gt;Where: Pescara &amp;lt;br&amp;gt;When: 30th November 2007, h.12.30 &lt;br /&gt;
&lt;br /&gt;
=== October 20th, 2007 - OWASP Italy at SMAU E-Academy 2007  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Last 20th October 2007 we had 5 speeches at SMAU E-Academy 2007, here you can download our presentations: &lt;br /&gt;
&lt;br /&gt;
*Giorgio Fedon, COO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/.pdf &amp;quot;Dove sono finiti i miei soldi? Internet Banking e Cross Site Scripting&amp;quot;] (coming soon) [[Image:FedonSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Paolo Perego, Senior Security Consultant at Spike Reply:&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/7/79/PeregoSMAU07.ppt &amp;quot;The Owasp Orizon project - bring security at the source&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Antonio Parata, Security Consultant at eMaze:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Valutazione del rischio tramite la logica fuzzy&amp;quot; (coming soon) [[Image:ParataSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
*Alberto Revelli, Senior Security Consultant at Portcullis Security:&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/9/9f/RevelliSMAU07.pdf &amp;quot;Anti-Anti-XSS: bypass delle difese del browser&amp;quot;] &lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, CTO at Minded Security:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Cros-site Flashing! Gli attacchi Web di ultima generazione parlano multipiattaforma&amp;quot; (coming soon) [[Image:DiPaolaSMAU07.pdf]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== September 10th, 2007 - OWASP Day WorldWide: &amp;quot;Privacy in the 21st Century&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Italy_OWASP_Day_1 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 29th, 2007 - Seminar: &amp;quot;Software Security&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Stefano Di Paola, Paolo Perego and Matteo Meucci will talk at the Seminar: [http://www.sicurinfo.it/informazioni/visinf.asp?IDInfo=246&amp;amp;CAT=53 &amp;quot;Which approaches to Software Security&amp;quot;] organized by Firenze Tecnologia.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== May 15th-17th, 2007 - 6th OWASP AppSec Conference in Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We are in the initial planning stages for the next OWASP Europe conference, which we plan to hold in Italy in May 2007.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/6th_OWASP_AppSec_Conference_-_Italy_2007 Here] you can find all the details about the conference, cfp and sponsorship. &lt;br /&gt;
&lt;br /&gt;
=== April 14th, 2007 - Master on Information Security, University of Rome &amp;quot;La Sapienza&amp;quot; ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*We have done a 4h seminar for the students of [http://mastersicurezza.uniroma1.it/ Master on Information Security at &amp;quot;La Sapienza&amp;quot;] for the [http://icsecurity.di.uniroma1.it/dokuwiki/doku.php?id=projects:asp Application Security Project of &amp;quot;La Sapienza&amp;quot; University.]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 30th, 2007 - University of Rome &amp;quot;La Sapienza&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*Thanks to Prof. Mancini and Roberto D'Addario, we will talk about OWASP at the convention &amp;quot;Institutions, Companies and Information Security: comparing the problems&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[http://w3.uniroma1.it/security/Eventi/eventi.html Here] you can find more details. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2007 - EuSecWest 07  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci presented the new OWASP Testing Guide at [http://www.eusecwest.com/agenda.html EUSecWest]. [http://www.owasp.org/images/e/e9/OWASP_Testing_Guide_Presentation_EUSecWest07.zip Here] you take a look at the presentation. &lt;br /&gt;
&lt;br /&gt;
=== February 6th-8th, 2007 - InfoSecurity  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
*February 6th:15.30&lt;br /&gt;
&lt;br /&gt;
After the great success obtained form CCC at Berlin, Stefano Di Paola and Giorgio Fedon will talk about:&amp;quot; Web Security Client Side: attacks at Web 2.0&amp;quot; More information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=aqfi82GOKd6I748s1evI8Q%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 6th:16.30&lt;br /&gt;
&lt;br /&gt;
After the great effort on the Testing Guide Project, Matteo Meucci and Alberto Revelli will present: &amp;quot;The new OWASP Testing Guide&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=nq6tSIuRoPVJBanBSsRiSQ%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
*February 7th:12.30&lt;br /&gt;
&lt;br /&gt;
Authors of innovative SQL injection tools, Alberto Revelli and Antonio Parata will show: &amp;quot;Advanced SQL Injection: testing tools and defensive strategies.&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=3z04F5BgZRgfU0YX8JRYtA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here] &lt;br /&gt;
&lt;br /&gt;
*February 7th:13.30&lt;br /&gt;
&lt;br /&gt;
Author of the new OWASP Orizon project, Paolo Perergo will present:&amp;quot;Secure programming: from theory to practice&amp;quot; More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=9HePIzyo5p29ylpGBl6CiA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]. &lt;br /&gt;
&lt;br /&gt;
=== January 25th, 2007 - Isaca Rome  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci will discuss the new [http://www.owasp.org/index.php/Category:OWASP_Testing_Project OWASP Testing Guide v2]&amp;lt;br&amp;gt; For more information:&amp;lt;br&amp;gt; http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
=== October 7th, 2006 - SMAU 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''The quest for secure code: code review and fundamental of secure coding.''&amp;quot; Matteo Meucci will present an introduction to the new OWASP Projects and OWASP-Italy activities. Paolo Perego (sp0nge) will speak about safe coding and the importance of code periodic review as natural software life cycle. Paolo will give a vision on code review and its phases http://www.webb.it/event/eventview/5772 &lt;br /&gt;
&lt;br /&gt;
Here are the presentations: &amp;lt;br&amp;gt; [[Image:Meucci SMAU06.pdf|Meucci_SMAU06]] &amp;lt;br&amp;gt; [[Image:Perego SMAU06.pdf|Perego_SMAU 06]] &lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''Advanced SQL Injection.''&amp;quot; Antonio Parata (S4tan) will explain SQL Injection, and how SQL Inference works on PHP/MySql platform. He will present an open source tool to support the testing. Alberto Revelli (icesurfer) will focus on Microsoft SQL Server: he will perform a live demo of sqlninja (http://sqlninja.sf.net), explaining how to obtain a pseudo-shell over SQL, how to escalate privileges, and how to play with the exotic equation: &amp;quot;SQL Injection + debug.exe + DNS = DOS prompt&amp;quot;&amp;amp;nbsp;! http://www.webb.it/event/eventview/5774 &lt;br /&gt;
&lt;br /&gt;
[[Image:Revelli SMAU06.pdf|Revelli_SMAU06]] &amp;lt;br&amp;gt; [[Image:Parata SMAU06.pdf|Parate_SMAU06]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP-Italy at SMAU06 2.JPG]] Luca, Carlo, Alberto, Antonio, Stefano &amp;lt;br&amp;gt; Matteo, Paolo, Giorgio &lt;br /&gt;
&lt;br /&gt;
=== September 29th, 2006 - OpenExp 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
September 30th, at 10:45 Antonio Parata (S4tan) will speak about SQL Injection: techniques, tools and practical examples. &lt;br /&gt;
&lt;br /&gt;
Abstract: Antonio will introduce some basic concepts about software security. It will be shown how SQL Inference works on PHP/MySql platform and presented an open source tool to support the testing. Finally will be listed some advises to avoid common bugs. http://www.openexp.it/ &lt;br /&gt;
&lt;br /&gt;
OWASP-Italy will have a stand from September 29th to October 1st. &lt;br /&gt;
&lt;br /&gt;
[[Image:Antonio Matteo Carlo.JPG]] [[Image:Antonio speech.JPG]] [[Image:Carlo.JPG]] [[Image:Claudio Luca.JPG]] [[Image:Mayhem Matteo.JPG]] [[Image:OWASP Banner2.JPG]] [[Image:OWASP Banner.JPG]] &lt;br /&gt;
&lt;br /&gt;
=== June 21th, 2006 - InfoSecurity 2006  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. The event is organized and managed by the CLUSIT. &lt;br /&gt;
&lt;br /&gt;
Where: Sheraton Roma Hotel - Viale Del Pattinaggio, 100 When: 10,30 - 17,00 Who: Matteo Meucci and Alberto Revelli Link: http://www.infosecurity.it/Roma/programma.php &lt;br /&gt;
&lt;br /&gt;
Agenda: -- I Session -- Introduction to Web Application Security • Which are the risks? • Risk assessment of a web application • Core pillars of web security How to develop secure web applications: • Guidelines and case-studies &lt;br /&gt;
&lt;br /&gt;
-- II Session -- How to realize a security audit of a web application • The methodology OWASP Penetration Testing • The tools: OWASP WebScarab • Hands-on web application vulnerabilities: OWASP WebGoat • Advanced SQL Injection. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2006 - OWASP-Boston, Microsoft  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler (OWASP-Boston Chair), Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting of march. [http://www.owasp.org/index.php/Boston More info here] &lt;br /&gt;
&lt;br /&gt;
=== November 5th, 2005 - IDC - European Banking Forum  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we have had a great speech at the IDC European IT Banking Forum 2005 (18 Nov 2005). http://www.idc.com/italy/events/banking05/banking05_agenda.jsp Agenda: &lt;br /&gt;
&lt;br /&gt;
*New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair &lt;br /&gt;
*Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy.&lt;br /&gt;
&lt;br /&gt;
You can download the report [http://cdn.idc.com/italy/downloads/report_banking05_eng.pdf here]. &lt;br /&gt;
&lt;br /&gt;
You can download the Case-Study of a vulnerable Home Banking Web Application [http://www.owasp.org/docroot/owasp/misc/IDC_BankingForum05v1.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== October 5th, 2005 - OWASP-Italy@SMAU2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
SMAU is the 42a International ICT &amp;amp;amp; Consumer Electronics Exhibition for Italy. Alberto Revelli (our Technical Director) and Matteo Meucci have conducted a seminar talking about Web Application Security. Alberto has presented his new project: [http://sqlninja.sourceforge.net sqlninja]. Very cool!! &lt;br /&gt;
&lt;br /&gt;
http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili &lt;br /&gt;
&lt;br /&gt;
=== May 25th, 2005 - ISACA Rome 2nd meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
May 25th we'll be in ISACA Rome to present OWASP WebGoat and a real case of a Web Application Vulnerability. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.30 Registration 14.45 Matteo Meucci - Web Application Security Phase II - OWASP WebScarab and PenTest Checklist &lt;br /&gt;
&lt;br /&gt;
*A case-study of a Web Application Vulnerability: MMS Spoofing&lt;br /&gt;
&lt;br /&gt;
--- Web Application analysis --- Authentication and Billing of the MMS service --- Vulnerabilities --- Attack Analysis &lt;br /&gt;
&lt;br /&gt;
*Learning the most common web application vulnerabilities: OWASP WebGoat&lt;br /&gt;
&lt;br /&gt;
--- Http Basics --- HTML Clues --- Hidden Field Tampering --- How to spoof a Session Cookie --- Stored Cross Site Scripting --- Command Injection --- SQL Injection --- Fail Open Authentication &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050525/OWASP.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== May 18th, 2005 - Workshop on Computer Crime 2005  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; May 18th, 2005 OWASP-Italy is invited to present OWASP Top 10 to the &amp;quot;Workshop on Computer Crime 2005&amp;quot; titled: &amp;quot;EVOLUZIONI NORMATIVE E RECENTI PROBLEMATICHE DI SICUREZZA&amp;quot; &lt;br /&gt;
&lt;br /&gt;
The meeting is held at: Sala delle conferenze dell'Istituto Centrale della Banche Popolari Italiane Via Verziere, 11 &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.owasp.org/images/a/aa/Top10-ComputerCrimes.ppt here]. &lt;br /&gt;
&lt;br /&gt;
=== March 31th, 2005 - ISACA Rome meeting  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March 31th we'll be in ISACA Rome to present OWASP and the Web Application Security. Every one is invited to join the meeting. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: 14.15 Registration 14.30 Matteo Meucci - Web Application Security - OWASP Guide: how to build secure web application - How to test your Web Application: WebScarab and the WebApp PenTest Checklist - How to learn the most common web application vulnerability: WebGoat - The Top Ten WebApp vulnerabilities - Common error on developing Web Application: Authentication mechanisms not &amp;quot;secure&amp;quot; Buffer Overflow and crash of the service Thief of identity: Cross Site Scripting Manipulation of company data: SQL Injection Reserved information: misconfiguration Bad session management and thief of identity - OWASP-Italy: projects and next challenges &lt;br /&gt;
&lt;br /&gt;
The meeting is hold at: Via Volturno, 65 (Rome) - Auditorium ATAC http://www.isacaroma.it/html/GiornateDiStudio.html &lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050331/meucci.zip here]. &lt;br /&gt;
&lt;br /&gt;
=== March 21th, 2005 - OWASP-Italy conducts a seminar in AlmaWeb  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March, the 21th OWASP-Italy has been invited at the University of Bologna to conduct a seminar regards to [http://www.almaweb.unibo.it/830.dyn Master in Management and Information Technology] titled “Web Application Security and OWASP”. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda: - OWASP &amp;amp;amp; Web Application Security - Common Web Application Vulnerabilities - A real case of web application vulnerability: MMS Spoofing&amp;amp;amp;Billing - Training: WebGoat &lt;br /&gt;
&lt;br /&gt;
==== Publications  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== October 2009 Interview on &amp;quot;Il sole 24 ore&amp;quot;  ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/5/5c/Nova09.pdf Gary McGraw and Matteo Meucci] interviewed by NOVA, talking about BSIMM and OWASP.&lt;br /&gt;
&lt;br /&gt;
=== March, 2007 Interview on HTML.it  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP&amp;amp;nbsp;:) ) [http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article. &lt;br /&gt;
&lt;br /&gt;
=== October, 2006 ISACA Roma interviews OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
After the speeches that OWASP-Italy has done at [http://www.smau.it/catnews.asp?l=2&amp;amp;codcat=385 SMAU E-Academy 2006], ISACA Roma has interviewed some of the people of the Italian chapter. Follow the links for the full interviews (in italian): &amp;lt;br&amp;gt; [[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]] [[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli] ] [[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]] [[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]] [[http://www.isacaroma.it/html/newsletter/node/322 Stefano Di Paola &amp;amp; Giorgio Fedon]] &lt;br /&gt;
&lt;br /&gt;
=== Aug, 2006 - Article on Banca Finanza magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Banca Finanza, the italian magazine about finance and banking, has interviewed Raoul Chiesa talking about the new risks for the on-line banking security. Raoul speaks about OWASP and web application security [[Media:042006BF.pdf]] &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Quaderno CLUSIT  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but it will be public in about 3 months. &lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Paper on SQL Injection and Inference on PHP/MySQLInference  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Antonio &amp;quot;s4tan&amp;quot; Parata has published an article about SQL Injection based on Inference for testing web application on PHP/MySQL platform. [http://www.ictsc.it/papers/sqlInferenceOnMySql.html Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== May, 2006 - Published an article about OWASP and Top-10 Vulnerabilities  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published the article &amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;. [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article. &lt;br /&gt;
&lt;br /&gt;
=== June, 2005 - OWASP Pen Test Checklist v 1.1 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Massimiliano Graziani we have translated in italian the &amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;. You can download it [http://www.owasp.org/documentation/testing.html here.] Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.] &lt;br /&gt;
&lt;br /&gt;
=== May, 2005 - Isaca Roma Newsletter about OWASP-Italy  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
ISACA Roma Newsletter has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy] &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published &amp;quot;MMS Spoofing&amp;quot;  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)]. &lt;br /&gt;
&lt;br /&gt;
Jim Hewitt, CISSP PMP working at CGI-AMS, affirms (slide#78): &amp;quot;Very interesting analysis of spoofed cell phone messaging and fraudulent billing&amp;quot;. See: www.techvalleynyissa.org/Resources/2005_07_WebApplicationSecurity.ppt &lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published an article on ICT Security magazine  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005. &lt;br /&gt;
&lt;br /&gt;
=== March, 2005 - OWASP Top-10 in Italian  ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here]. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
==== Tools &amp;amp;amp; Research  ====&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Nov, 2007 - sqlmap v0.5  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released the fifth versions of the tool [http://sqlmap.sourceforge.net sqlmap]. sqlmap is an automatic SQL injection tool entirely developed in Python. It is capable to perform an extensive database management system back-end fingerprint, retrieve remote DBMS databases, usernames, tables, columns, enumerate entire DBMS, read system files and much more taking advantage of web application programming security flaws that lead to SQL injection vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
You can download the latest stable version from its [https://sourceforge.net/project/showfiles.php?group_id=171598&amp;amp;package_id=196107 SourceForge File List page] or the latest development version from its [https://sqlmap.svn.sourceforge.net/svnroot/sqlmap SourceForge SVN repository]. &lt;br /&gt;
&lt;br /&gt;
=== Dec, 2006 - sqlmap v0.2  ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released a second version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://sqlmap.sourceforge.net/ Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
=== September, 2006 - Wisec Project  ===&lt;br /&gt;
&lt;br /&gt;
Stefano Di Paola is developing Wisec - The Wiki Security Project [http://www.wisec.it Here] you can accesses the project. &lt;br /&gt;
&lt;br /&gt;
=== July, 2006 - Sqlmap v0.0.1  ===&lt;br /&gt;
&lt;br /&gt;
Daniele Bellucci has developed a first version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://www.linux.it/~belch/?p=17 Here] you can download the tool &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Chapter]]&lt;br /&gt;
[[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Mmeucci</name></author>	</entry>

	</feed>