<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mstarks01</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mstarks01"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Mstarks01"/>
		<updated>2026-04-22T16:13:12Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=19191</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=19191"/>
				<updated>2007-06-15T03:17:51Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (nearI-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''June Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
Please join us for an informal gathering at [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=macgregors+henrietta,+ny&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.171132,-77.614288&amp;amp;spn=0.443687,0.933838&amp;amp;z=10&amp;amp;iwloc=C  McGregors] on Monday, June 18 at 6:00 PM.  Hope to see you there.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=19190</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=19190"/>
				<updated>2007-06-15T03:17:24Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''June Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
Please join us for an informal gathering at [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=macgregors+henrietta,+ny&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.171132,-77.614288&amp;amp;spn=0.443687,0.933838&amp;amp;z=10&amp;amp;iwloc=C  McGregors] on Monday, June 18 at 6:00 PM.&lt;br /&gt;
&lt;br /&gt;
Hope to see you there.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=17867</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=17867"/>
				<updated>2007-04-16T02:37:42Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''April Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
Details are not yet available, however we will be meeting at our regular time and place.&lt;br /&gt;
&lt;br /&gt;
Hope to see you there.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=17309</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=17309"/>
				<updated>2007-03-17T15:17:19Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''March Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
Although there will be no OWASP Rochester meeting in March, the Rochester chapter of ISSA will be having a free and open-to-the-public meeting on Monday, March 19 at 5:30 PM.  James Kist, CISSP will be presenting on Web Application Security.  James will be discussing common problems such as SQL Injection, as well as the not-so-common problems, such as AJAX and AJAX worms.&lt;br /&gt;
&lt;br /&gt;
Full details, including the location, can be found at: http://www.rochissa.org/#meetings&lt;br /&gt;
&lt;br /&gt;
Hope to see you there.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=17308</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=17308"/>
				<updated>2007-03-17T15:16:22Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''March Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
Although there will be no OWASP Rochester meeting in March, the Rochester chapter of ISSA will be having a free and open-to-the-public meeting on Monday, March 19 at 5:30 PM.  James Kist, CISSP will be presenting on Web Application Security.  James will be discussing common problems such as SQL Injection, as well as the not-so-common problems, such as AJAX and AJAX worms.&lt;br /&gt;
&lt;br /&gt;
Full details, including the location, can be found at: http://www.rochissa.org/#meetings&lt;br /&gt;
&lt;br /&gt;
Hope to see you there..  Enjoy the break!&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=17179</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=17179"/>
				<updated>2007-03-14T00:07:30Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''March Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
There will be no meeting in March.  Enjoy the break!&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=16056</id>
		<title>OWASP Community</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=16056"/>
				<updated>2007-02-01T02:52:07Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is for people to post OWASP related events, such as chapter meetings, OWASP conferences, get-togethers, and OWASP sponsored events.&lt;br /&gt;
&lt;br /&gt;
Events from previous years are archived here:&lt;br /&gt;
* '''[[OWASP Community 2006]]'''&lt;br /&gt;
&lt;br /&gt;
This page is monitored, and items posted here will be copied to the OWASP [[Main Page]].  Please post new items in chronological order using the following format:&lt;br /&gt;
&lt;br /&gt;
 '''Mon ## (##:00h) - [[Article]]'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
&lt;br /&gt;
CHAPTER LEADS -- please put your schedule here and we'll post a month in advance&lt;br /&gt;
&lt;br /&gt;
*** OTTAWA: Rough dates ***&lt;br /&gt;
'''Mar 7 - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
'''May 9 - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
'''Sept 12 - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
'''Nov 14 - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
*** BOSTON: Every first Wednesday of the month ***&lt;br /&gt;
'''Mar 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
'''Apr 4 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
'''May 2 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** MELBOURNE: First Tuesday of the month ***&lt;br /&gt;
'''Mar 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''Apr 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''May 1 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''Jun 5 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''Jul 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** NETHERLANDS: Second Thursday of the month sometimes ***&lt;br /&gt;
'''Sept 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
'''Dec 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** ROCHESTER: Every third Monday of the month ***&lt;br /&gt;
'''Mar 20 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
'''Apr 17 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
'''May 15 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** TORONTO: Every second Wednesday of the month&lt;br /&gt;
'''Mar 14 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
'''Apr 11 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
'''May 9 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** VIRGINIA: Every second tuesday of the month ***&lt;br /&gt;
'''Mar 13 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
'''Apr 10 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
'''May 8 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Events==&lt;br /&gt;
&lt;br /&gt;
'''May 10 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 12 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 27 (18:30h) - [[Philadelphia|Philadelphia chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
; '''Mar 27-30 - [http://www.blackhat.com Black Hat Euro]'''&lt;br /&gt;
: OWASP members receive a Euro 100 Briefings discount by inserting BH7EUASSOC in the box marked “Coupon Codes”&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
; '''Feb 26-Mar 1 - [http://www.blackhat.com Black Hat DC]'''&lt;br /&gt;
: OWASP members receive a $100 Briefings discount by inserting BH7DCASSOC in the box marked “Coupon Codes”&lt;br /&gt;
&lt;br /&gt;
'''Feb 22 (18:30h) - [[Helsinki|Helsinki chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 19 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 14 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 13 (18:00h) - [[Ireland|Ireland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 12 (18:30h) - [[Switzerland|Switzerland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6-7 - [[Italy#February_6th-8th.2C_2007_-_InfoSecurity|Italy@InfoSecurity]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 2 (14:00h) - [[Chennai|Chennai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 30 (11:30h) - [[Austin|Austin chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (18:00h) - [[San Francisco| San Francisco chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (14:30h) - [[Italy#October_25th.2C_2007_-_Isaca_Rome|Italy@ISACA Rome]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 24 (17:30h) - [[Israel#6th_OWASP_IL_meeting:_Wednesday.2C_January_24th_2007|6th OWASP Israel chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 23 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 22 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 17 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 16 (17:45h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:30h) - [[Phoenix|Phoenix chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 10 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 8 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 3 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=16055</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=16055"/>
				<updated>2007-02-01T02:32:05Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''February Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt; Monday, February 19, 2007, 6:00 PM&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt; 6:00 PM&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Intended audience:&amp;lt;/b&amp;gt; Technical&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presenter:&amp;lt;/b&amp;gt; Ralph Durkee, CISSP, GSEC, GCIH, GSNA, Principal Security Consultant&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Topic:&amp;lt;/b&amp;gt; Hands on Web Application Hacking with the OWASP Web Goat&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Description:&amp;lt;/b&amp;gt; We'll continue our exploration from last month and exploit web applications vulnerabilities using the OWASP Web Goat tool, which is designed for training real-world web application hacking techniques.   Group participation will be encouraged.  All exploits will be done by a trained professional on an off-the-net vulnerable application that you download from OWASP web site so that you can &amp;quot;try this at home&amp;quot;, but always with the appropriate permission first, of course.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Ralph Durkee: Performing a wide variety of consulting and training projects including software development, systems and networking security throughout his 25+ year career, Ralph is the president and founder of Durkee Consulting, since 1996. His specialty focuses on Internet security consulting and secure systems software development. He helped write a major portion of the Web Application Security training material for the SANS LAMP (Linux Apache MySql PHP) course. Ralph is a recent editor for the Center for Internet Security's Apache, Linux and DNS BIND benchmark. Ralph is a seasoned security consultant and trainer and holds GIAC certifications in GSEC since 2000 then GCIH since 2001 as well as the GSNA and CISSP.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=15352</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=15352"/>
				<updated>2007-01-15T03:07:29Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. Note: For January, we will meet the &amp;lt;b&amp;gt;fourth&amp;lt;/b&amp;gt; Monday of the month.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''January Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt; Monday, January 22, 2006, 6:00 PM&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt; 6:00 PM&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Intended audience:&amp;lt;/b&amp;gt; Technical&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presenter:&amp;lt;/b&amp;gt; Ralph Durkee, CISSP, GSEC, GCIH, GSNA, Principal Security Consultant&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Topic:&amp;lt;/b&amp;gt; Hands on Web Application Hacking with the OWASP Web Goat&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Description:&amp;lt;/b&amp;gt; We'll explore and exploit web applications vulnerabilities using the OWASP Web Goat tool designed for training real-world web application hacking techniques.   Group participation will be encouraged.  All exploits will be done by a trained professional on an off-the-net vulnerable application that you download from OWASP web site so that you can &amp;quot;try this at home&amp;quot;, but always with the appropriate permission first, of course.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Ralph Durkee: Performing a wide variety of consulting and training projects including software development, systems and networking security throughout his 25+ year career, Ralph is the president and founder of Durkee Consulting, since 1996. His specialty focuses on Internet security consulting and secure systems software development. He helped write a major portion of the Web Application Security training material for the SANS LAMP (Linux Apache MySql PHP) course. Ralph is a recent editor for the Center for Internet Security's Apache, Linux and DNS BIND benchmark. Ralph is a seasoned security consultant and trainer and holds GIAC certifications in GSEC since 2000 then GCIH since 2001 as well as the GSNA and CISSP.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=15351</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=15351"/>
				<updated>2007-01-15T02:51:54Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. Note: For January, we will meet the &amp;lt;b&amp;gt;fourth&amp;lt;/b&amp;gt; Monday of the month.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''January Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt; Monday, January 22, 2006, 6:00 PM&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt; 6:00 PM&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Intended audience:&amp;lt;/b&amp;gt; Technical&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presenter:&amp;lt;/b&amp;gt; Ralph Durkee, CISSP, GSEC, GCIH, GSNA, Principal Security Consultant&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Topic:&amp;lt;/b&amp;gt; Hands on Web Application Hacking with the OWASP Web Goat&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Description:&amp;lt;/b&amp;gt; We'll explore and exploit web applications vulnerabilities using the OWASP Web Goat tool designed for training real-world web application hacking techniques.   Group participation will be encouraged.  All exploits will be done by a trained professional on an off-the-net vulnerable application that you download from OWASP web site so that you can &amp;quot;try this at home&amp;quot;, but always with the appropriate permission first, or course.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Ralph Durkee: Performing a wide variety of consulting and training projects including software development, systems and networking security throughout his 25+ year career, Ralph is the president and founder of Durkee Consulting, since 1996. His specialty focuses on Internet security consulting and secure systems software development. He helped write a major portion of the Web Application Security training material for the SANS LAMP (Linux Apache MySql PHP) course. Ralph is a recent editor for the Center for Internet Security's Apache, Linux and DNS BIND benchmark. Ralph is a seasoned security consultant and trainer and holds GIAC certifications in GSEC since 2000 then GCIH since 2001 as well as the GSNA and CISSP.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=15350</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=15350"/>
				<updated>2007-01-15T02:49:54Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. Note: For January, we will meet the &amp;lt;b&amp;gt;fourth&amp;lt;/b&amp;gt; Monday of the month.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''January Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt; Monday, January 22, 2006, 6:00 PM&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Time:&amp;lt;/b&amp;gt; 6:00 PM&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Intended audience:&amp;lt;/b&amp;gt; Technical&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presenter:&amp;lt;/b&amp;gt; Ralph Durkee, CISSP, GSEC, GCIH, GSNA  Principal Security Consultant&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Topic:&amp;lt;/b&amp;gt; Hands on Web Application Hacking with the OWASP Web Goat&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Description:&amp;lt;/b&amp;gt; We'll explore and exploit web applications vulnerabilities using the OWASP Web Goat tool designed for training real-world web application hacking techniques.   Group participation will be encouraged.  All exploits will be done by a trained professional on an off-the-net vulnerable application that you download from OWASP web site so that you can &amp;quot;try this at home&amp;quot;, but always with the appropriate permission first, or course.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Ralph Durkee: Performing a wide variety of consulting and training projects including software development, systems and networking security throughout his 25+ year career, Ralph is the president and founder of Durkee Consulting, since 1996. His specialty focuses on Internet security consulting and secure systems software development. He helped write a major portion of the Web Application Security training material for the SANS LAMP (Linux Apache MySql PHP) course. Ralph is a recent editor for the Center for Internet Security's Apache, Linux and DNS BIND benchmark. Ralph is a seasoned security consultant and trainer and holds GIAC certifications in GSEC since 2000 then GCIH since 2001 as well as the GSNA and CISSP.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=13901</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=13901"/>
				<updated>2006-12-01T18:05:53Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
'''For this meeting, we'll be gathering at [http://maps.google.com/maps?hl=en&amp;amp;q=Mcgregor%27s+henrietta+ny&amp;amp;ie=UTF8&amp;amp;oe=UTF-8&amp;amp;filter=0&amp;amp;om=1&amp;amp;z=15&amp;amp;ll=43.093964,-77.652268&amp;amp;spn=0.015074,0.029182 MacGregors' Restaurant] for some food, drink and fun.'''&lt;br /&gt;
&lt;br /&gt;
 '''December Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt; Monday, December 18, 2006, 6:00 PM&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Duration:&amp;lt;/b&amp;gt; 6:00 PM Until...&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Intended audience:&amp;lt;/b&amp;gt; Everyone&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Topic:&amp;lt;/b&amp;gt; The Coming Year&lt;br /&gt;
&lt;br /&gt;
We'll be forgoing the usual formal presentation this month for a festive gathering at MacGregors' Restaurant.  We'll have some food, drink, fun and talk about the coming year.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font color=&amp;quot;#FF0000&amp;quot;&amp;gt;&amp;lt;b&amp;gt;So that we may give the restaurant some advance notice, we are requesting that you [mailto:macgregorsrsvp@michaelstarks.com RSVP] by December 11.&amp;lt;/b&amp;gt;&amp;lt;/font&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=13900</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=13900"/>
				<updated>2006-12-01T18:04:49Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
'''For this meeting, we'll be meeting at [http://maps.google.com/maps?hl=en&amp;amp;q=Mcgregor%27s+henrietta+ny&amp;amp;ie=UTF8&amp;amp;oe=UTF-8&amp;amp;filter=0&amp;amp;om=1&amp;amp;z=15&amp;amp;ll=43.093964,-77.652268&amp;amp;spn=0.015074,0.029182 MacGregors' Restaurant] for some food, drink and fun.'''&lt;br /&gt;
&lt;br /&gt;
 '''December Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date:&amp;lt;/b&amp;gt; Monday, December 18, 2006, 6:00 PM&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Duration:&amp;lt;/b&amp;gt; 6:00 PM Until...&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Intended audience:&amp;lt;/b&amp;gt; Everyone&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Topic:&amp;lt;/b&amp;gt; The Coming Year&lt;br /&gt;
&lt;br /&gt;
We'll be forgoing the usual formal presentation this month for a festive gathering at MacGregors' Restaurant.  We'll have some food, drink, fun and talk about the coming year.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font color=&amp;quot;#FF0000&amp;quot;&amp;gt;&amp;lt;b&amp;gt;So that we may give the restaurant some advance notice, we are requesting that you [mailto:macgregorsrsvp@michaelstarks.com RSVP] by December 11.&amp;lt;/b&amp;gt;&amp;lt;/font&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11274</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11274"/>
				<updated>2006-10-30T18:50:47Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
For this meeting, we'll be gathering in room 204.  Enter the the main Bryant &amp;amp; Stratton entrance door, go up the stairs and turn left down the hallway to room 204.  There will also be a signs on the doors.&lt;br /&gt;
&lt;br /&gt;
 '''November Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, November 20, 2006, 6:00 PM&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Duration: 1 hour 30 minutes&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Intended audience: Technical, Technical Management&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: Making Source Code Analysis Part of the Security Review Process&amp;lt;/b&amp;gt;, by Matt Rose, Fortify Software.&lt;br /&gt;
&lt;br /&gt;
How do you know if your software applications are secure? Manual audits only cover a small percentage of the source code base and periodic checks only provide a snapshot in time. Source code analysis allows development organizations to manage software security by leveraging well-documented best practices that can be automated. This session will &lt;br /&gt;
reveal how source code analysis can be a powerful tool for software security architects, developers and QA professionals by pinpointing security vulnerabilities throughout an entire code base as an integral part of the development cycle, or as part of software security audits in order to significantly improve application security. The session will describe the ins and outs of the technology, including its limitations and newly explored areas. Real life examples from actual engagements will be used throughout.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Due to limited space, we are requesting that you [mailto:fortifyrsvp@michaelstarks.com RSVP] by Novermber 13.&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11273</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11273"/>
				<updated>2006-10-30T18:23:22Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
For this meeting, we'll be gathering in room 204.  Enter the the main Bryant &amp;amp; Stratton entrance door, go up the stairs and turn left down the hallway to room 204.  There will also be a signs on the doors.&lt;br /&gt;
&lt;br /&gt;
 '''November Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, November 20, 2006, 6:00 PM&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Duration: 1 hour 30 minutes&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Intended audience: Technical, Technical Management&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: Making Source Code Analysis Part of the Security Review Process&amp;lt;/b&amp;gt;, by Matt Rose, Fortify Software.&lt;br /&gt;
&lt;br /&gt;
How do you know if your software applications are secure? Manual audits only cover a small percentage of the source code base and periodic checks only provide a snapshot in time. Source code analysis allows development organizations to manage software security by leveraging well-documented best practices that can be automated. This session will &lt;br /&gt;
reveal how source code analysis can be a powerful tool for software security architects, developers and QA professionals by pinpointing security vulnerabilities throughout an entire code base as an integral part of the development cycle, or as part of software security audits in order to significantly improve application security. The session will describe the in's and out's of the technology, including its limitations and newly explored areas. Real life examples from actual engagements will be used throughout.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Due to limited space, we are requesting that you [mailto:fortifyrsvp@michaelstarks.com RSVP] by Novermber 13.&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11272</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11272"/>
				<updated>2006-10-30T18:18:26Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Participation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
The Rochester chapter has two mailing lists: one for announcements and one for general discussion.  The announce list is for official communications (e.g meeting announcements, web site upates, etc). The discussion list is for general participation and everyone is encouraged to post. The announce mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-announce here].  The discussion mailing list can be found [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny here]. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-announce/ announce] and [http://lists.owasp.org/pipermail/owasp-rochester-ny discussion] e-mail archives to see what folks have been talking about.  Please make sure you are subscribed to announce to receive any last minute meeting info.&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
For this meeting, we'll be gathering in room 204.  Enter the the main Bryant &amp;amp; Stratton entrance door, go up the stairs and turn left down the hallway to room 204.  There will also be a signs on the doors.&lt;br /&gt;
&lt;br /&gt;
 '''November Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, November 20, 2006, 6:00 PM&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Duration: 1 hour 30 minutes&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Intended audience: Technical, Technical Management&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: Making Source Code Analysis Part of the Security Review Process&amp;lt;/b&amp;gt;, by Matt Rose, Fortify Software.&lt;br /&gt;
&lt;br /&gt;
How do you know if your software applications are secure? Manual audits only cover a small percentage of the source code base and periodic checks only provide a snapshot in time. Source code analysis allows development organizations to manage software security by leveraging well-documented best practices that can be automated. This session will &lt;br /&gt;
reveal how source code analysis can be a powerful tool for software security architects, developers and QA professionals by pinpointing security vulnerabilities throughout an entire code base as an integral part of the development cycle, or as part of software security audits in order to significantly improve application security. The session will describe the in's and out's of the technology, including its limitations and newly explored areas. Real life examples from actual engagements will be used throughout.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11271</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11271"/>
				<updated>2006-10-30T18:02:38Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
To join the chapter mailing list, please visit our [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny mailing list] homepage. The list is used to discuss the meetings and to arrange meeting locations. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-ny email archives] to see what folks have been talking about. Please check the mailing list before coming to a meeting to confirm the location and time and to catch any last minute notes.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
For this meeting, we'll be gathering in room 204.  Enter the the main Bryant &amp;amp; Stratton entrance door, go up the stairs and turn left down the hallway to room 204.  There will also be a signs on the doors.&lt;br /&gt;
&lt;br /&gt;
 '''November Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, November 20, 2006, 6:00 PM&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Duration: 1 hour 30 minutes&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Intended audience: Technical, Technical Management&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: Making Source Code Analysis Part of the Security Review Process&amp;lt;/b&amp;gt;, by Matt Rose, Fortify Software.&lt;br /&gt;
&lt;br /&gt;
How do you know if your software applications are secure? Manual audits only cover a small percentage of the source code base and periodic checks only provide a snapshot in time. Source code analysis allows development organizations to manage software security by leveraging well-documented best practices that can be automated. This session will &lt;br /&gt;
reveal how source code analysis can be a powerful tool for software security architects, developers and QA professionals by pinpointing security vulnerabilities throughout an entire code base as an integral part of the development cycle, or as part of software security audits in order to significantly improve application security. The session will describe the in's and out's of the technology, including its limitations and newly explored areas. Real life examples from actual engagements will be used throughout.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11270</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11270"/>
				<updated>2006-10-30T18:01:49Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
To join the chapter mailing list, please visit our [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny mailing list] homepage. The list is used to discuss the meetings and to arrange meeting locations. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-ny email archives] to see what folks have been talking about. Please check the mailing list before coming to a meeting to confirm the location and time and to catch any last minute notes.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
For this meeting, we'll be gathering in room 204.  Enter the the main Bryant &amp;amp; Stratton entrance door, go up the stairs and turn left down the hallway to room 204.  There will also be a signs on the doors.&lt;br /&gt;
&lt;br /&gt;
 '''November Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, November 20, 2006, 6:00 PM&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Duration: 1 hour 30 minutes&amp;lt;/b&amp;gt;&lt;br /&gt;
Intended audience: Technical, Technical Management&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: Making Source Code Analysis Part of the Security Review Process&amp;lt;/b&amp;gt;, by Matt Rose, Fortify Software.&lt;br /&gt;
&lt;br /&gt;
How do you know if your software applications are secure? Manual audits only cover a small percentage of the source code base and periodic checks only provide a snapshot in time. Source code analysis allows development organizations to manage software security by leveraging well-documented best practices that can be automated. This session will &lt;br /&gt;
reveal how source code analysis can be a powerful tool for software security architects, developers and QA professionals by pinpointing security vulnerabilities throughout an entire code base as an integral part of the development cycle, or as part of software security audits in order to significantly improve application security. The session will describe the in's and out's of the technology, including its limitations and newly explored areas. Real life examples from actual engagements will be used throughout.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11265</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11265"/>
				<updated>2006-10-30T17:48:37Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
To join the chapter mailing list, please visit our [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny mailing list] homepage. The list is used to discuss the meetings and to arrange meeting locations. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-ny email archives] to see what folks have been talking about. Please check the mailing list before coming to a meeting to confirm the location and time and to catch any last minute notes.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
For this meeting, we'll be gathering in room 204.  Enter the the main Bryant &amp;amp; Stratton entrance door, go up the stairs and turn left down the hallway to room 204.  There will also be a signs on the doors.&lt;br /&gt;
&lt;br /&gt;
 '''November Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, November 20, 2006, 6:00 PM&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Duration: 1 hour 30 minutes&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: Making Source Code Analysis Part of the Security Review Process&amp;lt;/b&amp;gt;, by Matt Rose, Fortify Software.&lt;br /&gt;
&lt;br /&gt;
How do you know if your software applications are secure? Manual audits only cover a small percentage of the source code base and periodic checks only provide a snapshot in time. Source code analysis allows development organizations to manage software security by leveraging well-documented best practices that can be automated. This session will &lt;br /&gt;
reveal how source code analysis can be a powerful tool for software security architects, developers and QA professionals by pinpointing security vulnerabilities throughout an entire code base as an integral part of the development cycle, or as part of software security audits in order to significantly improve application security. The session will describe the in's and out's of the technology, including its limitations and newly explored areas. Real life examples from actual engagements will be used throughout.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11262</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11262"/>
				<updated>2006-10-30T17:26:27Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Past Presentations */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
To join the chapter mailing list, please visit our [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny mailing list] homepage. The list is used to discuss the meetings and to arrange meeting locations. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-ny email archives] to see what folks have been talking about. Please check the mailing list before coming to a meeting to confirm the location and time and to catch any last minute notes.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006, 6:00 PM&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;October 2006&amp;lt;/b&amp;gt; The first of the OWASP top ten: unvalidated input, by Steve Buck.&lt;br /&gt;
[http://rd1.net/owasp/2006-10-16_owasp-presentation.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11261</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=11261"/>
				<updated>2006-10-30T17:09:53Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Local Officers */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Welcome to the OWASP Rochester Local Chapter ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the local Rochester chapter homepage. The chapter leader is [mailto:rd@rd1.net Ralf Durkee]&lt;br /&gt;
&lt;br /&gt;
== Participation ==&lt;br /&gt;
&lt;br /&gt;
OWASP chapter meetings are free and open to anyone interested in application security. We encourage members to give presentations on specific topics and to contribute to the local chapter by sharing their knowledge with others. Prior to participating with OWASP please review the [[Chapter Rules]].&lt;br /&gt;
&lt;br /&gt;
To join the chapter mailing list, please visit our [http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny mailing list] homepage. The list is used to discuss the meetings and to arrange meeting locations. You can also review the [http://lists.owasp.org/pipermail/owasp-rochester-ny email archives] to see what folks have been talking about. Please check the mailing list before coming to a meeting to confirm the location and time and to catch any last minute notes.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary and Treasurer:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006, 6:00 PM&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10373</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10373"/>
				<updated>2006-10-10T02:40:30Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; The third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; 1225 Jefferson Rd, Rochester, NY 14623 (near I-390) [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
Meeting space is graciously offered by [http://www.bryantstratton.edu/campus/campus.aspx?c=14 Bryant &amp;amp; Stratton College] Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006, 6:00 PM&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10372</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10372"/>
				<updated>2006-10-10T02:32:27Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Dates &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Dates:&amp;lt;/b&amp;gt; Meetings are held the third Monday of every month, starting at 6:00 PM. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; Bryant and Stratton Professional Skills Center, 1225 Jefferson Rd, Rochester, NY 14623 (near I-390)&lt;br /&gt;
&lt;br /&gt;
Enter the Frontier Commons plaza, near the Post Office.  Towards the right, rear of the plaza is the PSC (Professional Skills Center) door, which is to the left of the main Bryant &amp;amp; Stratton entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006, 6:00 PM&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10371</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10371"/>
				<updated>2006-10-10T02:24:24Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Dates &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; Bryant and Stratton Professional Skills Center, 1225 Jefferson Rd, Rochester, NY 14623 (near I-390)&lt;br /&gt;
&lt;br /&gt;
Enter the plaza behind Bill Grays and Tulleys, near the Post Office.  Enter the PSC (Professional Skills Center) door which is left of the main entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10370</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10370"/>
				<updated>2006-10-10T02:21:35Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Times &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Times &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; Bryant and Stratton Professional Skills Center, 1225 Jefferson Rd, Rochester, NY 14623 (near I-390)&lt;br /&gt;
&lt;br /&gt;
Enter the plaza behind Bill Grays and Tulleys, near the Post Office.  Enter the PSC (Professional Skills Center) door which is left of the main entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10369</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10369"/>
				<updated>2006-10-10T02:20:45Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Times &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Times &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; Bryant and Stratton Professional Skills Center, 1225 Jefferson Rd, Rochester, NY 14623 (near I-390)&lt;br /&gt;
&lt;br /&gt;
Enter the plaza behind Bill Grays and Tulleys, near the Post Office.  Enter the PSC (Professional Skills Center) door which is left of the main entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10368</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10368"/>
				<updated>2006-10-10T02:20:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Times &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Times &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; Bryant and Stratton Professional Skills Center, 1225 Jefferson Rd, Rochester, NY 14623 (near I-390)&lt;br /&gt;
&lt;br /&gt;
Enter the plaza behind Bill Grays and Tulleys, near the Post Office.  Enter the PSC (Professional Skills Center) door which is left of the main entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10367</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10367"/>
				<updated>2006-10-10T02:18:11Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Times &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Times &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; Bryant and Stratton Professional Skills Center, 1225 Jefferson Rd, Rochester, NY 14623 (near I-390)&lt;br /&gt;
&lt;br /&gt;
Enter the plaza behind Bill Grays and Tulleys, near the Post Office.  Enter the PSC (Professional Skills Center) door which is left of the main entrance door. There will be a sign on the door indicating the room in which we will meet.&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10366</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10366"/>
				<updated>2006-10-10T01:31:08Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Times &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; Bryant and Stratton College, 1225 Jefferson Rd, Rochester, NY (near I-390)  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10365</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10365"/>
				<updated>2006-10-10T01:30:37Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Meeting Times &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; Bryant and Stratton College, 1225 Jefferson Rd, Rochester, NY (near I-390)  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10364</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10364"/>
				<updated>2006-10-10T01:27:43Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Times &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Times &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Location:&amp;lt;/b&amp;gt; Bryant and Stratton College, 1225 Jefferson Rd, Rochester, NY (near I-390)  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Date: Monday, October 16, 2006&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10363</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10363"/>
				<updated>2006-10-10T01:18:01Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Meeting Times &amp;amp; Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Times &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month.  Our October meeting will be on Monday, October 16. The meeting location is Bryant and Stratton college, Jefferson Rd, near I-390.  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10359</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10359"/>
				<updated>2006-10-10T00:32:49Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Meeting Times &amp;amp; Location ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month.  Our October meeting will be on Monday, October 16. The meeting location is Bryant and Stratton college, Jefferson Rd, near I-390.  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting Details'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Past Presentations ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10350</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10350"/>
				<updated>2006-10-10T00:18:12Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month.  Our October meeting will be on Monday, October 16. The meeting location is Bryant and Stratton college, Jefferson Rd, near I-390.  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
 '''Past Presentations'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of SQL Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10348</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10348"/>
				<updated>2006-10-10T00:17:38Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month.  Our October meeting will be on Monday, October 16. The meeting location is Bryant and Stratton college, Jefferson Rd, near I-390.  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
 '''Past Presentations'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;November 2004&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of Sql Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10347</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10347"/>
				<updated>2006-10-10T00:16:59Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month.  Our October meeting will be on Monday, October 16. The meeting location is Bryant and Stratton college, Jefferson Rd, near I-390.  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
 '''Past Presentations'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of Sql Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10345</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10345"/>
				<updated>2006-10-10T00:13:54Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month.  Our October meeting will be on Monday, October 16. The meeting location is Bryant and Stratton college, Jefferson Rd, near I-390.  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;br /&gt;
&lt;br /&gt;
 '''Past Presentations'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2006&amp;lt;/b&amp;gt; PGP: Encryption for e-mail and web applications, by Ralph Durkee [http://rd1.net/owasp/Apr_OWASP_PGP_Durkee.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Identity Theft, Phishing and Pharming, by Danny Allan [http://rd1.net/owasp/AppSec2005DC-Danny_Allan-Identity_Theft_Phishing_and_Pharming.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2006&amp;lt;/b&amp;gt; Secure e-mail, by Thomas Bullinger [http://rd1.net/owasp/SecureEmail.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2006&amp;lt;/b&amp;gt; PCI Compliance, by Pat Massey, Ralf Durkee, Maureen Baran [http://rd1.net/owasp/Rochester_OWASP_PCI_Compliance.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;September 2005&amp;lt;/b&amp;gt; Two Factor Authentication for Java Applications with Client Certificates, by Ralf Durkee [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.pdf PDF] [http://rd1.net/owasp/DCI-Java-SSL-Certs-2005-09-19.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;April 2005&amp;lt;/b&amp;gt; Avoiding Backend Exploitation of Mail Forms, by Max Kessler [http://rd1.net/owasp/owasp-mailform-exploitation.ppt PowerPoint] [http://rd1.net/owasp/owasp-mailform-exploitation.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;March 2005&amp;lt;/b&amp;gt; Bringing Two-Factor Authentication to Web Applications, by Michael Starks [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt PowerPoint] [http://rd1.net/owasp/2005_Mar_OWASP_Two-factor%20Web%20App.ppt Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;February 2005&amp;lt;/b&amp;gt; Insecure Storage, by Chris Karr [http://rd1.net/owasp/Insecure_Storage.ppt PowerPoint]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Mgmnt, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Access Control and Session Management, by Steve Buck [http://rd1.net/owasp/Jan_OWASP-access-control.ppt PowerPoint] [http://rd1.net/owasp/Jan_OWASP-access-control.sxi Open Office]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;January 2005&amp;lt;/b&amp;gt; Intro to OWASP by Ralf Durkee. Demonstration of Sql Injection attack and prevention, by Paul Cupo [http://rd1.net/owasp/Nov_OWASP_20041103.ppt PowerPoint]&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10330</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10330"/>
				<updated>2006-10-09T23:32:03Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month.  Our October meeting will be on Monday, October 16. The meeting location is Bryant and Stratton college, Jefferson Rd, near I-390.  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10329</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=10329"/>
				<updated>2006-10-09T23:30:17Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting'''&lt;br /&gt;
&lt;br /&gt;
Meetings are held the third Monday of every month.  Our October meeting will be on Monday, October 16. The meeting location is Bryant and Stratton college, Jefferson Rd, near I-390.  [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation: The first of the OWASP top ten: unvalidated input&amp;lt;/b&amp;gt;, by Steve Buck.&lt;br /&gt;
&lt;br /&gt;
At this meeting we will be discussing the first of the OWASP top ten list: unvalidated input.  We will discuss the problems posed by not validating input on the server side.  These problems include: forced browsing, command insertion, cross site scripting, buffer overflows, bypassing site security, format string attacks, SQL injection, cookie poisoning, and hidden field manipulation.&lt;br /&gt;
&lt;br /&gt;
We will cover how to determine if you are vulnerable to one of these attacks, and also how to protect yourself.  We will also have a demo of some of these exploits in action.  Finally, we will have an open discussion with any questions about the subject matter.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Biography&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Steve Buck is a consultant for Mindex Technologies.  He has been working  with various web technologies since 1996, involving everything from Perl and C CGIs to J2EE.&lt;br /&gt;
&lt;br /&gt;
Steve has experience as a UNIX system administrator instructor with a specialty in system security.&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=9895</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=9895"/>
				<updated>2006-09-23T00:47:30Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''October Meeting'''&lt;br /&gt;
&lt;br /&gt;
Our October meeting will be at Bryant and Stratton on Jefferson Rd, near I-390.&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation:&amp;lt;/b&amp;gt; The first of the OWASP top ten: Unvalidated Input, by Steve Buck.  Details to follow.&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Rochester&amp;diff=9894</id>
		<title>Rochester</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Rochester&amp;diff=9894"/>
				<updated>2006-09-23T00:36:36Z</updated>
		
		<summary type="html">&lt;p&gt;Mstarks01: /* Local Officers */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Rochester|extra=The chapter leader is [mailto:rd@rd1.net Ralf Durkee]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-rochester-ny|emailarchives=http://lists.owasp.org/pipermail/owasp-rochester-ny}}&lt;br /&gt;
&lt;br /&gt;
== Local Officers ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
*&amp;lt;b&amp;gt;President:&amp;lt;/b&amp;gt; Ralf Durkee&lt;br /&gt;
*&amp;lt;b&amp;gt;Vice President:&amp;lt;/b&amp;gt; Chris Karr&lt;br /&gt;
*&amp;lt;b&amp;gt;Secretary:&amp;lt;/b&amp;gt; Steve Buck&lt;br /&gt;
*&amp;lt;b&amp;gt;Web and Communications:&amp;lt;/b&amp;gt; Michael Starks&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''Next Meeting, Monday, September 18, 2006'''&lt;br /&gt;
&lt;br /&gt;
Our next meeting will be Monday, September 18, 2006 at 6:00 PM at Bryant and Stratton on Jefferson Rd, near I-390.&lt;br /&gt;
&lt;br /&gt;
[http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;q=1225+Jefferson+Rd,+Rochester,+NY&amp;amp;ie=UTF8&amp;amp;om=1&amp;amp;ll=43.087727,-77.600255&amp;amp;spn=0.014856,0.04283 Google Map]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Presentation:&amp;lt;/b&amp;gt; Securing Apache Web Applications with the Center for Internet Security consensus benchmark by Ralf Durkee&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
We'll exam specific web application security threats and the configuration recommendations from the Center for Internet Security benchmark and for mod_security.  We discuss why and when the controls are appropriate, and how they mitigate risks.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Bio:&amp;lt;/b&amp;gt; Ralf Durkee has over 25 years of experience in Software Development, and Systems Administration and Network Security. Ralph provides security consulting for Web application security and PCI compliance for Rochester area businesses. He's also a local teacher for SANS GSEC Security, certified since 2000, a Certified Incident Handler &amp;amp; Hacker Techniques (GCIH), System and Network Auditor (GSNA) as well a CISSP certified instructor. He has worked as an independent consultant and trainer since 1996, and has served as lead for the development of&lt;br /&gt;
several Center for Internet Security Unix/Linux/FreeBSD, BIND and Apache security benchmarks and score tools. He also developed a major portion of the Web Application Security for SANS LAMP track 615.&lt;/div&gt;</summary>
		<author><name>Mstarks01</name></author>	</entry>

	</feed>