<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mtesauro</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mtesauro"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Mtesauro"/>
		<updated>2026-04-17T17:32:25Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Web_Testing_Environment_Project&amp;diff=256690</id>
		<title>OWASP Web Testing Environment Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Web_Testing_Environment_Project&amp;diff=256690"/>
				<updated>2020-05-04T00:46:26Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Hiding from Harold&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP WTE==&lt;br /&gt;
&lt;br /&gt;
OWASP WTE, or OWASP Web Testing Environment, is a collection of application security tools and documentation available in multiple formats such as VMs, Linux distribution packages, Cloud-based installations and ISO images.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
The OWASP WTE project is an enhancement of the original [https://www.owasp.org/index.php/Category:OWASP_Live_CD_Project OWASP Live CD Project] and expands the offering from a static Live CD ISO image to a collection of sub-projects.  Its primary goal is to &lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;'' '''Make application security tools and documentation easily available and easy to use.''' ''&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
At its heart, OWASP WTE is a collection of easy to use application security tools and documentation.  WTE has a variety of ways to distribute them:&lt;br /&gt;
* Virtual Machines for VMware, VirtualBox and Parallels&lt;br /&gt;
* Invidividual Debian packages (.deb) which attempt to be Linux disto agnostic.  &lt;br /&gt;
** Tested against Ubuntu, Debian, Mint, Kali, etc.&lt;br /&gt;
* A bootable ISO image&lt;br /&gt;
* Hosted on various Cloud providers&lt;br /&gt;
* Ala Carte mix-and-match installations for special purposes&lt;br /&gt;
&lt;br /&gt;
The project is focused at providing a ready environment for testers, developers or trainers to learn, enhance, demonstrate or use their application security skills.  It's been an active OWASP project since 2008 and has had over 300,000 downloads.&lt;br /&gt;
&lt;br /&gt;
Beyond the collection of tools from OWASP and other security projects, OWASP WTE has begun producing and including its own security tools, especially where there were no existing tools which fit a particular need. &lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
OWASP WTE is free to use. Its licensing is dependant on several factors:&lt;br /&gt;
* OWASP WTE created documenation is licensed under the [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
* OWASP WTE created software and tools are licensed under the [http://www.gnu.org/copyleft/gpl.html GPLv3] or later license.  You are free to use and modify this software as well as having the right to re-distribute this software as long as any changes you've made are contributed back to the project under the same license.  For questions, see the [http://www.gnu.org/licenses/gpl-faq.html GPL FAQ]&lt;br /&gt;
* OWASP WTE packaged software and documentation is under the license of that project and/or software.  The only licensing constraint required by OWASP WTE is that the software it makes packages of must be free to redistribute.&lt;br /&gt;
&lt;br /&gt;
In short, you can use and share OWASP WTE as much as you want.  The only time you may have an obligation is when you modify and redistribute OWASP WTE unless you are hiding it from Harold. If you are unsure, please ask the [https://lists.owasp.org/mailman/listinfo/owasp-wte OWASP WTE Mail list]&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is WTE? ==&lt;br /&gt;
&lt;br /&gt;
OWASP WTE provides:&lt;br /&gt;
&lt;br /&gt;
* Virtual Machines&lt;br /&gt;
** VMware/Parallels .vmdk&lt;br /&gt;
** VirtualBox .vdi&lt;br /&gt;
** Open Virtualization Archive .ova&lt;br /&gt;
* Linux Distribution packages&lt;br /&gt;
** Debian .deb &lt;br /&gt;
** RPM .rpm - ''Beta status''&lt;br /&gt;
* Cloud-based installations&lt;br /&gt;
* ISO images&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.slideshare.net/mtesauro/owasp-wte-now-in-the-cloud OWASP WTE: Application Testing Your Way]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Mtesauro Matt Tesauro]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Live_CD_Project OWASP Live CD Project]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project OWASP ZAP]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* ''Coming Soon''&lt;br /&gt;
&amp;lt;!-- [http://www.ohloh.net/orgs/OWASP OWASP Project Ohloh] --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* [http://appseclive.org/downloads/ Downloads site]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
[https://lists.owasp.org/mailman/listinfo/owasp-wte OWASP WTE Mail list]&lt;br /&gt;
&lt;br /&gt;
== Code repository  ==&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/mtesauro/owasp-wte GitHub]&amp;lt;br /&amp;gt;''Migration in progress''&lt;br /&gt;
* [https://code.google.com/p/owasp-wte/ Google Code]&amp;lt;br /&amp;gt;''Previous repository''&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
* 2014-05-24: OWASP WTE next release in progress&lt;br /&gt;
* 2014-04-18: WTE at OWASP Project Summit during AppSec EU 2014&lt;br /&gt;
* 2013-10-12: WTE at LASCON 2013&lt;br /&gt;
* 2013-09-16: WTE + REST Testing Training&lt;br /&gt;
* 2013-09-01: OWASP WTE 13.09 released&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--== In Print ==&lt;br /&gt;
&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;[[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Question: What is the login (aka username and password) for the VMs?'''&lt;br /&gt;
&lt;br /&gt;
'''Answer:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The default username and password for the OWASP WTE VMs is ''owasp'' and ''owasp''.  Obviously, if you're going to run this for any period of time or in a situation more then a host-only VM, update the password for the ''owasp'' user to something long and random.  Regrettably, I have to set something as a default and owasp/owasp seems like a sensible thing.  The owasp user has sudo privileges if you need to do admin tasks, update software, etc.&lt;br /&gt;
&lt;br /&gt;
'''Question: How to I update my OWASP WTE VM?'''&lt;br /&gt;
&lt;br /&gt;
'''Answer'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP WTE VMs ship with a OWASP WTE repository already configured.  The same process you use to update the base OS (Xubuntu) will also update the OWASP WTE pacakges.  Beyond the GUI tools, you can do the following in a terminal:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo apt-get update&lt;br /&gt;
$ sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Question: What are the project's goals'''&lt;br /&gt;
&lt;br /&gt;
'''Answer'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The overarching goal for this project is to make application security tools and documentation easily available.  I see this as a great complement to OWASP's goal to make application security visible.&lt;br /&gt;
&lt;br /&gt;
The project has several other goals going forward:&lt;br /&gt;
# Provide a showcase for great OWASP tools and documentation&lt;br /&gt;
# Provide the best, freely distributable application security tools in an easy to use package&lt;br /&gt;
# Ensure that the tools provided are as easy to use as possible.  &lt;br /&gt;
# Continue to add documentation and tools to the OWASP Live CD&lt;br /&gt;
# Continue to document how to use the tools and how the tool modules where created.&lt;br /&gt;
# Align the tools provided with the [http://www.owasp.org/index.php/Category:OWASP_Testing_Project OWASP Testing Guide] &lt;br /&gt;
&lt;br /&gt;
There were also some design goals, particularly, this should be an environment which is&lt;br /&gt;
* easy for the users to keep updated&lt;br /&gt;
* easy for the project lead to keep updated&lt;br /&gt;
* easy to produce releases &lt;br /&gt;
* focused on just web application testing - not general Pen Testing.  &lt;br /&gt;
&lt;br /&gt;
(For general Pen Testing, the gold standard is [http://www.kali.org/ Kali Linux].)&lt;br /&gt;
&lt;br /&gt;
[http://mtesauro.com/livecd/index.php?title=Original_SoC_Goals Original SoC Goals] are still available for the curious.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP WTE is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Kent Poots&lt;br /&gt;
* Brad Causey&lt;br /&gt;
* Drew Beebe&lt;br /&gt;
* Nishi Kumar&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* David Hughes&lt;br /&gt;
* Simon Bennetts&lt;br /&gt;
* Achim Hoffmann&lt;br /&gt;
* Your name here!&lt;br /&gt;
&lt;br /&gt;
Numerous others have provided feedback, suggestions, bugs and other assistance.  If you've been missed, please email matt.tesauro [at] owasp [dot] org and let him know.&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of May 2014, the priorities are:&lt;br /&gt;
* Adding support for RPM packages&lt;br /&gt;
* GPG signing all packages&lt;br /&gt;
* More support for Cloud-based installations&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP WTE is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Use WTE and submit bugs, suggestion, feedback&lt;br /&gt;
* Suggest tools, docs or something else to add to the project&lt;br /&gt;
* Blog/Tweet/shout about WTE&lt;br /&gt;
* Make a video on using WTE and let the project know about it&lt;br /&gt;
* Ping the [https://lists.owasp.org/mailman/listinfo/owasp-wte OWASP WTE Mail list] for more ideas or with a suggestion&lt;br /&gt;
&lt;br /&gt;
=Project History=&lt;br /&gt;
&lt;br /&gt;
The OWASP WTE project was originally started to update the previous [http://www.owasp.org/index.php/Category:OWASP_Live_CD_2007_Project OWASP Live CD 2007].  The project met the September 15th, 2008 deadline for the OWASP Summer of Code (SoC) and produced its first release - the SoC release.  Since the completion of the SoC, the project has made the following releases:&lt;br /&gt;
&lt;br /&gt;
* OWASP WTE Oct 2013&lt;br /&gt;
* OWASP WTE Oct 2012&lt;br /&gt;
* OWASP WTE Sept 2011&lt;br /&gt;
* OWASP WTE Feb 2011&lt;br /&gt;
* OWASP WTE Beta (January 2010)&lt;br /&gt;
* the AppSec EU release (May, 2009)&lt;br /&gt;
* the Portugal release (Dec 12, 2008) &lt;br /&gt;
* the AustinTerrier release (Feb 10, 2009)&lt;br /&gt;
&lt;br /&gt;
In addition to creating these releases of the OWASP Live CD/OWASP WTE, the maintainer has created a Linux package in Debian format (.deb) for each tool and the documentation included with OWASP WTE.  This allows the WTE packages to be installed ala carte on Ubuntu, Debian, Mint, and other .deb based Linux distributions.&lt;br /&gt;
&lt;br /&gt;
For historical purposes, the original application for the SoC is available [http://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Applications#OWASP_Live_CD_2008_Project here] for the curious.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{Template:Project About&lt;br /&gt;
| project_name =OWASP WTE &lt;br /&gt;
| project_description =OWASP WTE, or OWASP Web Testing Environment, is a collection of application security tools and documentation available in multiple formats such as VMs, Linux distribution packages, Cloud-based installations and ISO images. &lt;br /&gt;
| project_license =CCbySA for documentation and GPLv3 for code&lt;br /&gt;
| leader_name1 =Matt Tesauro&lt;br /&gt;
| leader_email1 =matt.tesauro@owasp.org&lt;br /&gt;
| leader_username1 = mtesauro&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-wte&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:OWASP Project|WTE]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]] &lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Projects|WTE]]&lt;br /&gt;
[[Category:Flagship Projects|WTE]]&lt;br /&gt;
[[Category:OWASP WTE|WTE]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=MediaWiki:Requestaccount&amp;diff=256658</id>
		<title>MediaWiki:Requestaccount</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=MediaWiki:Requestaccount&amp;diff=256658"/>
				<updated>2020-01-16T21:59:59Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Requesting account has been disabled permanently&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=MediaWiki:Requestaccount&amp;diff=256657</id>
		<title>MediaWiki:Requestaccount</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=MediaWiki:Requestaccount&amp;diff=256657"/>
				<updated>2020-01-16T21:59:00Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Note that account requests are disabled&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Request account has been disabled&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=MediaWiki:Noarticletext&amp;diff=256656</id>
		<title>MediaWiki:Noarticletext</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=MediaWiki:Noarticletext&amp;diff=256656"/>
				<updated>2020-01-16T21:49:03Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Change &amp;quot;page has no text&amp;quot; message to be the same as the Special404 page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The URL you requested was not found. ==&lt;br /&gt;
&lt;br /&gt;
[[File:404-old-owasp.png|500x262px|frameless|center|Page Not Found image]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;'''Please note:''' This site is the archived OWASP Foundation Wiki - the current site is at https://owasp.org/&amp;lt;/big&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=MediaWiki:Special404-body&amp;diff=256655</id>
		<title>MediaWiki:Special404-body</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=MediaWiki:Special404-body&amp;diff=256655"/>
				<updated>2020-01-16T21:35:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Initial custom 404 page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The URL you requested was not found. ==&lt;br /&gt;
&lt;br /&gt;
[[File:404-old-owasp.png|500x262px|frameless|center|Page Not Found image]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;'''Please note:''' This site is the archived OWASP Foundation Wiki - the current site is at https://owasp.org/&amp;lt;/big&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:404-old-owasp.png&amp;diff=256654</id>
		<title>File:404-old-owasp.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:404-old-owasp.png&amp;diff=256654"/>
				<updated>2020-01-16T21:25:51Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;404 Image&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_ZSC_Tool_Project&amp;diff=256649</id>
		<title>OWASP ZSC Tool Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_ZSC_Tool_Project&amp;diff=256649"/>
				<updated>2020-01-16T02:55:25Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Undo revision 256648 by Mtesauro (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP ZSC Tool Project==&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject={{FULLPAGENAMEE}}&amp;amp;body={{FULLPAGENAMEE}}:%0A{{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u={{fullurle:{{FULLPAGENAME}}}}&amp;amp;t={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}} }}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status={{fullurle:{{FULLPAGENAME}}}}|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u={{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Donate to OWASP ZSC''' {{#widget:PayPal Donation |target=_blank |budget=OWASP ZSC }}&lt;br /&gt;
&lt;br /&gt;
====What is OWASP ZSC ?====&lt;br /&gt;
http://zsc.z3r0d4y.com/images/Snapshot_2015-07-26_191951-half.png&lt;br /&gt;
&lt;br /&gt;
'''OWASP ZSC''' is an open source software in Python language which lets you '''generate customized shellcodes''' and '''convert scripts to an obfuscated script'''. This software can be run on Windows/Linux/OSX under Python.&lt;br /&gt;
&lt;br /&gt;
[[File:Zsc1.png|200px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
====Usage of shellcodes====&lt;br /&gt;
&lt;br /&gt;
Shellcodes are small codes in Assembly language which could be used as the payload in software exploitation. Other usages are in malwares, bypassing antiviruses, obfuscated codes and etc.&lt;br /&gt;
&lt;br /&gt;
====DISCLAIMER====&lt;br /&gt;
This tool is related to IT, Hacking, Programming and Computer|Network|Software Security. The word “Hack”, &amp;quot;Pen testing&amp;quot;,“Hacking” that is used on these project pages shall be regarded as “Ethical Hack” or “Ethical Hacking” respectively. This is not a tool that provides any illegal information.We do not promote hacking or software cracking. All the information provided on these pages is for educational purposes only.&lt;br /&gt;
&lt;br /&gt;
The authors of this tool are not responsible for any misuse of the information.You shall not misuse the information to gain unauthorized access and/or write malicious programs.This information shall only be used to expand knowledge and not for causing malicious or damaging attacks.You may try all of these techniques on your own computer at your own risk.Performing any hack attempts/tests without written permission from the owner of the computer system is illegal.&lt;br /&gt;
&lt;br /&gt;
IN NO EVENT SHALL THE CREATORS, OWNER, OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.&lt;br /&gt;
&lt;br /&gt;
====Usage of Obfuscate Codes====&lt;br /&gt;
&lt;br /&gt;
Can be used for bypassing antiviruses, code protections, same stuff etc … &lt;br /&gt;
&lt;br /&gt;
====Why use OWASP ZSC ?====&lt;br /&gt;
&lt;br /&gt;
Another good reason for obfuscating files or generating shellcode with ZSC is that it can be used during your pen-testing. Malicious hackers use these techniques to bypass anti-virus and load malicious files in systems they have hacked using customized shellcode generators.&lt;br /&gt;
Anti-virus work with signatures in order to identify harmful files. When using very well known encoders such as msfvenom, files generated by this program might be already flagged by Anti-virus programs.&lt;br /&gt;
&lt;br /&gt;
Our purpose is not to provide a way to bypass anti-virus with malicious intentions, instead, we want to provide pen-testers a way to challenge the security provided by Anti-virus programs and Intrusion Detection systems during a pen test.In this way, they can verify the security just as a black-hat will do.&lt;br /&gt;
&lt;br /&gt;
According to other shellcode generators same as Metasploit tools and etc, OWASP ZSC using new encodes and methods which antiviruses won't detect.&lt;br /&gt;
OWASP ZSC encoders are able to generate shell codes with random encodes and that allows you to generate thousands of new dynamic shellcodes with the same job in just a second, that means, you will not get the same code if you use random encodes with same commands, And that make OWASP ZSC one of the best! &lt;br /&gt;
During the Google Summer of Code we are working on to generate Windows Shellcode and new obfuscation methods.&lt;br /&gt;
We are working on the next version that will allow you to generate OSX.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
====GNU GENERAL PUBLIC LICENSE , Version 3, 29 June 2007====&lt;br /&gt;
&lt;br /&gt;
Copyright (C) 2007 Free Software Foundation, Inc. http://fsf.org/ Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed. [https://github.com/Ali-Razmjoo/OWASP-ZSC/blob/master/LICENSE.md Click to see the full license]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''The OWASP Security Principles are free to use. In fact it is encouraged!!!&lt;br /&gt;
'' Additionally, I also encourage you to contribute back to the project. I have no monopoly on this knowledge; however, we all have pieces of this knowledge from our experience. Let's begin by putting our individual pieces together to make something great. Great things happen when people work together.&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles are licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Ali_Razmjoo Ali Razmjoo]&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Johanna_Curiel Johanna Curiel]&lt;br /&gt;
&lt;br /&gt;
== Contributors &amp;amp; Main Developers ==&lt;br /&gt;
&lt;br /&gt;
* [http://pratikpatelp.blogspot.in Pratik Patel] (Google Summer of Code student 2016) &lt;br /&gt;
* [https://codemaxx.github.io Akash Trehan] (CodeMaxx)&lt;br /&gt;
* [https://paraschetal.in Paras Chetal] (Gsoc candidate 2016)&lt;br /&gt;
* Brian Beaudry (Gsoc Mentor 2016)&lt;br /&gt;
* Hamid Zamani (HAMIDx9)&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://api.z3r0d4y.com/ API]&lt;br /&gt;
* [https://github.com/Ali-Razmjoo/OWASP-ZSC Project on Github]&lt;br /&gt;
* [https://groups.google.com/d/forum/owasp-zsc Mailing List]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/ OWASP ZSC Home]&lt;br /&gt;
* [https://www.openhub.net/p/OWASP-ZSC OpenHub]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/table.html Last Version Features]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/wiki Wiki]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/download Download]&lt;br /&gt;
* [https://github.com/Ali-Razmjoo/ZCR-Shellcoder-Archive Archive]&lt;br /&gt;
&lt;br /&gt;
== Shellcode Generating ==&lt;br /&gt;
With using '''OWASP ZSC''' you would be able to generate any customized '''Shellcode''' in your mind including encodes and Disassembly code in few seconds.&lt;br /&gt;
&lt;br /&gt;
== Be an OWASP ZSC developer ==&lt;br /&gt;
* [https://www.owasp.org/index.php?title=OWASP_ZSC_Tool_Project&amp;amp;action=submit#Developers Quick Developing Help]&lt;br /&gt;
&lt;br /&gt;
== Last Tricks in Home ==&lt;br /&gt;
* [http://zsc.z3r0d4y.com/blog/archives/ All Tricks]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/blog/2015/08/01/generate-pe-file-with-zsc-shellcodes/ Shellcode to PE File]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/blog/2015/07/27/video-how-to-install-and-generate-shellcode-using-zsc/ Video: Install&amp;amp;Generate Shellcode]&lt;br /&gt;
&lt;br /&gt;
==Related links==&lt;br /&gt;
*[https://www.youtube.com/watch?v=nkx0HQhYdmY| Appsec Presentation 2013 Beef and Custome shellcodes]&lt;br /&gt;
*[https://www.owasp.org/index.php/File:Introduction_to_shellcode_development.pdf| Introduction to Shellcode Development]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zscproject/OWASP-ZSC Github Page.]&lt;br /&gt;
&lt;br /&gt;
[http://zsc.z3r0d4y.com/download/ Download Page.]&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zscproject/OWASP-ZSC/zipball/master .zip file.]&lt;br /&gt;
* [https://github.com/zscproject/OWASP-ZSC/tarball/master .tgz file.]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [https://www.owasp.org/index.php/Iran#tab=Past_Events OWASP Nettacker Presented By Ali Razmjoo in OWASP Iran Chapter Meeting July 2018]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Code_Sprint_2017#OWASP_ZSC OWASP ZSC in OWASP Code Sprint 2017]&lt;br /&gt;
* [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ OWASP ZSC Selected as Top 10 Security tools in 2016 By ToolsWatch]&lt;br /&gt;
* [https://groups.google.com/forum/#!topic/owasp-zsc/t12M2fxn78k OWASP ZSC Presented in OFFSECONF 2016]&lt;br /&gt;
* [https://www.blackhat.com/eu-16/arsenal.html#brian-beaudry Been Selected for Blackhat EU Arsenal 2016]&lt;br /&gt;
* [https://www.defcon.org/html/defcon-24/dc-24-demolabs.html#Curiel  OWASP ZSC has been selected for Defcon Demo Lab 2016]&lt;br /&gt;
* [https://summerofcode.withgoogle.com/archive/2016/projects/5969824152813568/ OWASP ZSC applied and was selected to participate in the Google Summer of Code 2016]&lt;br /&gt;
* [https://www.linkedin.com/pulse/lessons-from-cyber-underworld-how-understand-software-ali-razmjoo Press Release 12th February 2015 ]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/ OWASP ZSC Version 1.0.9.1 Released!]&lt;br /&gt;
* [https://github.com/longld/peda OWASP ZSC in GDB-PEDA]&lt;br /&gt;
&lt;br /&gt;
== Docs ==&lt;br /&gt;
* [https://github.com/Ali-Razmjoo/OWASP-ZSC/tree/master/doc Developers and Users Documents].&lt;br /&gt;
* [http://zsc.z3r0d4y.com/ OWASP ZSC Home]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject={{FULLPAGENAMEE}}&amp;amp;body={{FULLPAGENAMEE}}:%0A{{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u={{fullurle:{{FULLPAGENAME}}}}&amp;amp;t={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}} }}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status={{fullurle:{{FULLPAGENAME}}}}|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u={{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
To see full guides please visit our [http://zsc.z3r0d4y.com/wiki wiki page].&lt;br /&gt;
&lt;br /&gt;
====Help Menu====&lt;br /&gt;
&lt;br /&gt;
'''PLEASE CLICK [https://github.com/Ali-Razmjoo/OWASP-ZSC/tree/master/doc HERE] TO SEE FULL DEVELOPERS AND USERS DOCUMENTS'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======OWASP ZSC Project======&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
OWASP ZSC is an open source software in Python language which lets you generate customized shellcodes and convert scripts to an obfuscated script. This software can be run on Windows/Linux/OSX under python.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======Usage of shellcodes======&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Shellcodes are small codes in Assembly Languagewhich could be used as the payload in software exploiting. Other usages are in malwares, bypassing anti viruses, obfuscated codes and etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======Usage of Obfuscate Codes======&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Can be used for bypassing antiviruses, code protections, same stuff etc … &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======Why use OWASP ZSC ?======&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
According to other shellcode generators such as Metasploit tools and etc, OWASP ZSC using new encodes and methods which antiviruses won't detect. OWASP ZSC encoders are able to generate shell codes with random encodes that allows you to generate thousands of new dynamic shell codes with the same job in just a second, it means you will not get the same code if you use random encodes with the same commands, and that makes OWASP ZSC one of the best! &lt;br /&gt;
OWASP ZSC can generate shellcode for Linux and Windows _x86&lt;br /&gt;
Upcoming features will allow generating shellcodes for OSX &lt;br /&gt;
And new encodes for the code obfuscation.&lt;br /&gt;
&lt;br /&gt;
======User Guides======&lt;br /&gt;
&lt;br /&gt;
To run '''OWASP ZSC''', You need to install python `2.x|3.x` on your operation system `Windows|Linux|OSX`, Then it could be run directly with executing `zsc.py` or run the software after you installed it! To see the user manuals, Please follow the next steps!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======Generating Shellcode======&lt;br /&gt;
&lt;br /&gt;
Via `zsc` command, you are able to enter the software [or run python zsc.py if you don’t want to install it], Then you can have a list of menu with entering `help`. You can have your choices with pressing `tab` key on each step. To generate shellcode, you have to type `shellcode` and then press enter, after that, you can see what’s available in `shellcode` section. There is `generate` , `search` and `download` choices in here which use for `generate shellcodes`, `search` and `download` shellcode from shellstorm.  To generate a shellcode, type `generate` and press enter, after that with a `tab` key, you can have list of operation systems available in there. With pressing `tab` key again, functions will be shown for you in this step [ such as `exec` ,`systm`,`write` and `etc`]. choose your function by writing the name `example: exec` and press inter. In the next section you have to fill the argv of function which exec() function have one `example: exec(&amp;quot;/bin/bash&amp;quot;)`, all you need in this section is pressing a `tab` and then `enter` key, software will automatically ask you for function argv. Fill them and next section software will ask you for shellcode type which can be `none` or choose one of listed encoding types. After entering that, your shellcode is ready!&lt;br /&gt;
There is one more way to have a shellcode from software, which is using shellstorm API. Following the `shellcode`, and then `search` commands to search for a shellcode. After that shellcodes will be listed for you with title name , ID and etc. you can download them with  following `shellcode` and then `download` command to download them with the ID which shown to you in the past section! For canceling each section, you can use `restart` command to restart the software and start new task!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======Generating Obfuscate Code======&lt;br /&gt;
&lt;br /&gt;
With the following `obfuscate` command, you can begin the step for obfuscating a code. With a `tab` key , you can see the list of languages along with the obfuscating module ready. After choosing the language software will ask you for a filename which is a filename of file you want to obfuscate that! Next step software will ask you for encode type. With a `tab` key list the encode modules and choose your encode name. your file rewrited and converted to a obfuscate with encode type you chosen. And do not worry about your original code, it’s saved in file as a comment!&lt;br /&gt;
&lt;br /&gt;
Please click '''[https://github.com/Ali-Razmjoo/OWASP-ZSC/tree/master/doc HERE]''' to read more!&lt;br /&gt;
&lt;br /&gt;
=Requirement / Installation=&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject={{FULLPAGENAMEE}}&amp;amp;body={{FULLPAGENAMEE}}:%0A{{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u={{fullurle:{{FULLPAGENAME}}}}&amp;amp;t={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}} }}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status={{fullurle:{{FULLPAGENAME}}}}|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u={{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Installation'''&lt;br /&gt;
Go to download page, and download last version in github. Extract and run installer.py, then you are able to run software with OWASP ZSC command or you can directly execute zsc.py without installing it.or you can follow these commands to install the last version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;lt;nowiki&amp;gt;wget https://github.com/Ali-Razmjoo/OWASP-ZSC/archive/master.zip -O owasp-zsc.zip &amp;amp;&amp;amp; unzip owasp-zsc.zip &amp;amp;&amp;amp; &lt;br /&gt;
rm -rf owasp-zsc.zip &amp;amp;&amp;amp; mv OWASP-ZSC-master owasp-zsc &amp;amp;&amp;amp; cd owasp-zsc &amp;amp;&amp;amp; python installer.py&amp;lt;/nowiki&amp;gt;&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://zsc.z3r0d4y.com/images/Snapshot_2015-07-27_114843.png&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Note''': Software could be '''uninstall''' with executing '''uninstaller.py'''&lt;br /&gt;
&lt;br /&gt;
'''Note''': Software installation directory is &amp;quot;'''/usr/share/owasp-zsc'''&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''Note''': &amp;lt;strong&amp;gt;OWASP ZSC&amp;lt;/strong&amp;gt; Tool could be execute on &amp;lt;strong&amp;gt;Linux&amp;lt;/strong&amp;gt; and &amp;lt;strong&amp;gt;Python 2.7.x &amp;lt;/strong&amp;gt;is required.&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject={{FULLPAGENAMEE}}&amp;amp;body={{FULLPAGENAMEE}}:%0A{{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u={{fullurle:{{FULLPAGENAME}}}}&amp;amp;t={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}} }}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status={{fullurle:{{FULLPAGENAME}}}}|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u={{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;August, 2016, the highest priorities for the next one year&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Develop future [http://zsc.z3r0d4y.com/table.html features] list , Add Operation Systems and new encode types&lt;br /&gt;
* Planing for activate features&lt;br /&gt;
* Build ZSC API&lt;br /&gt;
* Find developers to get better performance, quality, optimizing and best improvement in minimum possible time&lt;br /&gt;
* Get other people to review the ZSC Tool Project provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project and the features&lt;br /&gt;
* Keep test, developing and updating with best new methods&lt;br /&gt;
* Build and update documents in several languages for developers/users guiding &lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject={{FULLPAGENAMEE}}&amp;amp;body={{FULLPAGENAMEE}}:%0A{{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u={{fullurle:{{FULLPAGENAME}}}}&amp;amp;t={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}} }}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status={{fullurle:{{FULLPAGENAME}}}}|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u={{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
OWASP ZSC could be improving with handling module [http://zsc.z3r0d4y.com/table.html features]. MVP of this project is build and active the first module which could be usable to generate/encode Shellcode which already some of them [modules] activated.&lt;br /&gt;
&lt;br /&gt;
Highest usage of OWASP ZSC Tool could be when users are able to use all [http://zsc.z3r0d4y.com/table.html features] with best User Interface and &amp;lt;strong&amp;gt;API&amp;lt;/strong&amp;gt; performance.&lt;br /&gt;
https://www.owasp.org/images/3/33/Zsc.png&lt;br /&gt;
&lt;br /&gt;
= Developers =&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject={{FULLPAGENAMEE}}&amp;amp;body={{FULLPAGENAMEE}}:%0A{{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u={{fullurle:{{FULLPAGENAME}}}}&amp;amp;t={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}} }}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span  title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url={{fullurle:{{FULLPAGENAME}}}}&amp;amp;title={{urlencode:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status={{fullurle:{{FULLPAGENAME}}}}|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u={{fullurle:{{FULLPAGENAME}}}}]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Developers==&lt;br /&gt;
Architect &amp;amp; Creator: Ali Razmjoo&lt;br /&gt;
* Pratik Patel (Google Summer of Code student 2016)&lt;br /&gt;
* Akash Trehan (CodeMaxx)&lt;br /&gt;
* Paras Chetal (Google Summer of Code candidate 2016)&lt;br /&gt;
* Hamid Samani (HAMIDx9)&lt;br /&gt;
&lt;br /&gt;
==Testers ==&lt;br /&gt;
*Johanna Curiel&lt;br /&gt;
*Brian Beaudry&lt;br /&gt;
&lt;br /&gt;
===Be an OWASP ZSC developer===&lt;br /&gt;
&lt;br /&gt;
Developers can add new features and if you don’t have an idea but like to develop, you can submit the issue, which software needs to be fix/add/done in [https://github.com/zscproject/OWASP-ZSC/issues HERE].&lt;br /&gt;
&lt;br /&gt;
After fix/add or develop something, please send your pull request and remember that your code must be compatible with python2 and python3.&lt;br /&gt;
If you have any question you can open an issue or just [mailto:owasp-zsc-tool-project@lists.owasp.org mail us]. do not forget to register on our [https://lists.owasp.org/mailman/listinfo/owasp-zsc-tool-project mailing list].&lt;br /&gt;
&lt;br /&gt;
'''AND DON'T FORGET TO READ [https://github.com/Ali-Razmjoo/OWASP-ZSC/tree/master/doc DEVELOPERS DOCUMENTS]'''&lt;br /&gt;
&lt;br /&gt;
Also this [https://www.gitbook.com/book/ali-razmjoo/owasp-zsc/details GitBook]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_ZSC_Tool_Project}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Breakers]]  [[Category:OWASP_Code]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:Shellcode]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_ZSC_Tool_Project&amp;diff=256648</id>
		<title>OWASP ZSC Tool Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_ZSC_Tool_Project&amp;diff=256648"/>
				<updated>2020-01-16T02:53:03Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Testing redirects&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[https://www.owasp.org/OWASP ZSC Tool Project]]&lt;br /&gt;
&lt;br /&gt;
=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP ZSC Tool Project==&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject=OWASP_ZSC_Tool_Project&amp;amp;body=OWASP_ZSC_Tool_Project:%0Ahttps://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;t=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Donate to OWASP ZSC''' {{#widget:PayPal Donation |target=_blank |budget=OWASP ZSC }}&lt;br /&gt;
&lt;br /&gt;
====What is OWASP ZSC ?====&lt;br /&gt;
http://zsc.z3r0d4y.com/images/Snapshot_2015-07-26_191951-half.png&lt;br /&gt;
&lt;br /&gt;
'''OWASP ZSC''' is an open source software in Python language which lets you '''generate customized shellcodes''' and '''convert scripts to an obfuscated script'''. This software can be run on Windows/Linux/OSX under Python.&lt;br /&gt;
&lt;br /&gt;
[[File:Zsc1.png|200px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
====Usage of shellcodes====&lt;br /&gt;
&lt;br /&gt;
Shellcodes are small codes in Assembly language which could be used as the payload in software exploitation. Other usages are in malwares, bypassing antiviruses, obfuscated codes and etc.&lt;br /&gt;
&lt;br /&gt;
====DISCLAIMER====&lt;br /&gt;
This tool is related to IT, Hacking, Programming and Computer|Network|Software Security. The word “Hack”, &amp;quot;Pen testing&amp;quot;,“Hacking” that is used on these project pages shall be regarded as “Ethical Hack” or “Ethical Hacking” respectively. This is not a tool that provides any illegal information.We do not promote hacking or software cracking. All the information provided on these pages is for educational purposes only.&lt;br /&gt;
&lt;br /&gt;
The authors of this tool are not responsible for any misuse of the information.You shall not misuse the information to gain unauthorized access and/or write malicious programs.This information shall only be used to expand knowledge and not for causing malicious or damaging attacks.You may try all of these techniques on your own computer at your own risk.Performing any hack attempts/tests without written permission from the owner of the computer system is illegal.&lt;br /&gt;
&lt;br /&gt;
IN NO EVENT SHALL THE CREATORS, OWNER, OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.&lt;br /&gt;
&lt;br /&gt;
====Usage of Obfuscate Codes====&lt;br /&gt;
&lt;br /&gt;
Can be used for bypassing antiviruses, code protections, same stuff etc … &lt;br /&gt;
&lt;br /&gt;
====Why use OWASP ZSC ?====&lt;br /&gt;
&lt;br /&gt;
Another good reason for obfuscating files or generating shellcode with ZSC is that it can be used during your pen-testing. Malicious hackers use these techniques to bypass anti-virus and load malicious files in systems they have hacked using customized shellcode generators.&lt;br /&gt;
Anti-virus work with signatures in order to identify harmful files. When using very well known encoders such as msfvenom, files generated by this program might be already flagged by Anti-virus programs.&lt;br /&gt;
&lt;br /&gt;
Our purpose is not to provide a way to bypass anti-virus with malicious intentions, instead, we want to provide pen-testers a way to challenge the security provided by Anti-virus programs and Intrusion Detection systems during a pen test.In this way, they can verify the security just as a black-hat will do.&lt;br /&gt;
&lt;br /&gt;
According to other shellcode generators same as Metasploit tools and etc, OWASP ZSC using new encodes and methods which antiviruses won't detect.&lt;br /&gt;
OWASP ZSC encoders are able to generate shell codes with random encodes and that allows you to generate thousands of new dynamic shellcodes with the same job in just a second, that means, you will not get the same code if you use random encodes with same commands, And that make OWASP ZSC one of the best! &lt;br /&gt;
During the Google Summer of Code we are working on to generate Windows Shellcode and new obfuscation methods.&lt;br /&gt;
We are working on the next version that will allow you to generate OSX.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
====GNU GENERAL PUBLIC LICENSE , Version 3, 29 June 2007====&lt;br /&gt;
&lt;br /&gt;
Copyright (C) 2007 Free Software Foundation, Inc. http://fsf.org/ Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed. [https://github.com/Ali-Razmjoo/OWASP-ZSC/blob/master/LICENSE.md Click to see the full license]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''The OWASP Security Principles are free to use. In fact it is encouraged!!!'''&lt;br /&gt;
'' Additionally, I also encourage you to contribute back to the project. I have no monopoly on this knowledge; however, we all have pieces of this knowledge from our experience. Let's begin by putting our individual pieces together to make something great. Great things happen when people work together.''&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles are licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Ali_Razmjoo Ali Razmjoo]&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Johanna_Curiel Johanna Curiel]&lt;br /&gt;
&lt;br /&gt;
== Contributors &amp;amp; Main Developers ==&lt;br /&gt;
&lt;br /&gt;
* [http://pratikpatelp.blogspot.in Pratik Patel] (Google Summer of Code student 2016) &lt;br /&gt;
* [https://codemaxx.github.io Akash Trehan] (CodeMaxx)&lt;br /&gt;
* [https://paraschetal.in Paras Chetal] (Gsoc candidate 2016)&lt;br /&gt;
* Brian Beaudry (Gsoc Mentor 2016)&lt;br /&gt;
* Hamid Zamani (HAMIDx9)&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://api.z3r0d4y.com/ API]&lt;br /&gt;
* [https://github.com/Ali-Razmjoo/OWASP-ZSC Project on Github]&lt;br /&gt;
* [https://groups.google.com/d/forum/owasp-zsc Mailing List]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/ OWASP ZSC Home]&lt;br /&gt;
* [https://www.openhub.net/p/OWASP-ZSC OpenHub]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/table.html Last Version Features]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/wiki Wiki]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/download Download]&lt;br /&gt;
* [https://github.com/Ali-Razmjoo/ZCR-Shellcoder-Archive Archive]&lt;br /&gt;
&lt;br /&gt;
== Shellcode Generating ==&lt;br /&gt;
With using '''OWASP ZSC''' you would be able to generate any customized '''Shellcode''' in your mind including encodes and Disassembly code in few seconds.&lt;br /&gt;
&lt;br /&gt;
== Be an OWASP ZSC developer ==&lt;br /&gt;
* [https://www.owasp.org/index.php?title=OWASP_ZSC_Tool_Project&amp;amp;action=submit#Developers Quick Developing Help]&lt;br /&gt;
&lt;br /&gt;
== Last Tricks in Home ==&lt;br /&gt;
* [http://zsc.z3r0d4y.com/blog/archives/ All Tricks]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/blog/2015/08/01/generate-pe-file-with-zsc-shellcodes/ Shellcode to PE File]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/blog/2015/07/27/video-how-to-install-and-generate-shellcode-using-zsc/ Video: Install&amp;amp;Generate Shellcode]&lt;br /&gt;
&lt;br /&gt;
==Related links==&lt;br /&gt;
*[https://www.youtube.com/watch?v=nkx0HQhYdmY| Appsec Presentation 2013 Beef and Custome shellcodes]&lt;br /&gt;
*[https://www.owasp.org/index.php/File:Introduction_to_shellcode_development.pdf| Introduction to Shellcode Development]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zscproject/OWASP-ZSC Github Page.]&lt;br /&gt;
&lt;br /&gt;
[http://zsc.z3r0d4y.com/download/ Download Page.]&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zscproject/OWASP-ZSC/zipball/master .zip file.]&lt;br /&gt;
* [https://github.com/zscproject/OWASP-ZSC/tarball/master .tgz file.]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [https://www.owasp.org/index.php/Iran#tab=Past_Events OWASP Nettacker Presented By Ali Razmjoo in OWASP Iran Chapter Meeting July 2018]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Code_Sprint_2017#OWASP_ZSC OWASP ZSC in OWASP Code Sprint 2017]&lt;br /&gt;
* [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ OWASP ZSC Selected as Top 10 Security tools in 2016 By ToolsWatch]&lt;br /&gt;
* [https://groups.google.com/forum/#!topic/owasp-zsc/t12M2fxn78k OWASP ZSC Presented in OFFSECONF 2016]&lt;br /&gt;
* [https://www.blackhat.com/eu-16/arsenal.html#brian-beaudry Been Selected for Blackhat EU Arsenal 2016]&lt;br /&gt;
* [https://www.defcon.org/html/defcon-24/dc-24-demolabs.html#Curiel OWASP ZSC has been selected for Defcon Demo Lab 2016]&lt;br /&gt;
* [https://summerofcode.withgoogle.com/archive/2016/projects/5969824152813568/ OWASP ZSC applied and was selected to participate in the Google Summer of Code 2016]&lt;br /&gt;
* [https://www.linkedin.com/pulse/lessons-from-cyber-underworld-how-understand-software-ali-razmjoo Press Release 12th February 2015]&lt;br /&gt;
* [http://zsc.z3r0d4y.com/ OWASP ZSC Version 1.0.9.1 Released!]&lt;br /&gt;
* [https://github.com/longld/peda OWASP ZSC in GDB-PEDA]&lt;br /&gt;
&lt;br /&gt;
== Docs ==&lt;br /&gt;
* [https://github.com/Ali-Razmjoo/OWASP-ZSC/tree/master/doc Developers and Users Documents].&lt;br /&gt;
* [http://zsc.z3r0d4y.com/ OWASP ZSC Home]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject=OWASP_ZSC_Tool_Project&amp;amp;body=OWASP_ZSC_Tool_Project:%0Ahttps://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;t=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
To see full guides please visit our [http://zsc.z3r0d4y.com/wiki wiki page].&lt;br /&gt;
&lt;br /&gt;
====Help Menu====&lt;br /&gt;
&lt;br /&gt;
'''PLEASE CLICK [https://github.com/Ali-Razmjoo/OWASP-ZSC/tree/master/doc HERE] TO SEE FULL DEVELOPERS AND USERS DOCUMENTS'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======OWASP ZSC Project======&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
OWASP ZSC is an open source software in Python language which lets you generate customized shellcodes and convert scripts to an obfuscated script. This software can be run on Windows/Linux/OSX under python.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======Usage of shellcodes======&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Shellcodes are small codes in Assembly Languagewhich could be used as the payload in software exploiting. Other usages are in malwares, bypassing anti viruses, obfuscated codes and etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======Usage of Obfuscate Codes======&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Can be used for bypassing antiviruses, code protections, same stuff etc … &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======Why use OWASP ZSC ?======&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
According to other shellcode generators such as Metasploit tools and etc, OWASP ZSC using new encodes and methods which antiviruses won't detect. OWASP ZSC encoders are able to generate shell codes with random encodes that allows you to generate thousands of new dynamic shell codes with the same job in just a second, it means you will not get the same code if you use random encodes with the same commands, and that makes OWASP ZSC one of the best! &lt;br /&gt;
OWASP ZSC can generate shellcode for Linux and Windows _x86&lt;br /&gt;
Upcoming features will allow generating shellcodes for OSX &lt;br /&gt;
And new encodes for the code obfuscation.&lt;br /&gt;
&lt;br /&gt;
======User Guides======&lt;br /&gt;
&lt;br /&gt;
To run '''OWASP ZSC''', You need to install python `2.x|3.x` on your operation system `Windows|Linux|OSX`, Then it could be run directly with executing `zsc.py` or run the software after you installed it! To see the user manuals, Please follow the next steps!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======Generating Shellcode======&lt;br /&gt;
&lt;br /&gt;
Via `zsc` command, you are able to enter the software [or run python zsc.py if you don’t want to install it], Then you can have a list of menu with entering `help`. You can have your choices with pressing `tab` key on each step. To generate shellcode, you have to type `shellcode` and then press enter, after that, you can see what’s available in `shellcode` section. There is `generate` , `search` and `download` choices in here which use for `generate shellcodes`, `search` and `download` shellcode from shellstorm.  To generate a shellcode, type `generate` and press enter, after that with a `tab` key, you can have list of operation systems available in there. With pressing `tab` key again, functions will be shown for you in this step [ such as `exec` ,`systm`,`write` and `etc`]. choose your function by writing the name `example: exec` and press inter. In the next section you have to fill the argv of function which exec() function have one `example: exec(&amp;quot;/bin/bash&amp;quot;)`, all you need in this section is pressing a `tab` and then `enter` key, software will automatically ask you for function argv. Fill them and next section software will ask you for shellcode type which can be `none` or choose one of listed encoding types. After entering that, your shellcode is ready!&lt;br /&gt;
There is one more way to have a shellcode from software, which is using shellstorm API. Following the `shellcode`, and then `search` commands to search for a shellcode. After that shellcodes will be listed for you with title name , ID and etc. you can download them with  following `shellcode` and then `download` command to download them with the ID which shown to you in the past section! For canceling each section, you can use `restart` command to restart the software and start new task!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======Generating Obfuscate Code======&lt;br /&gt;
&lt;br /&gt;
With the following `obfuscate` command, you can begin the step for obfuscating a code. With a `tab` key , you can see the list of languages along with the obfuscating module ready. After choosing the language software will ask you for a filename which is a filename of file you want to obfuscate that! Next step software will ask you for encode type. With a `tab` key list the encode modules and choose your encode name. your file rewrited and converted to a obfuscate with encode type you chosen. And do not worry about your original code, it’s saved in file as a comment!&lt;br /&gt;
&lt;br /&gt;
Please click '''[https://github.com/Ali-Razmjoo/OWASP-ZSC/tree/master/doc HERE]''' to read more!&lt;br /&gt;
&lt;br /&gt;
=Requirement / Installation=&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject=OWASP_ZSC_Tool_Project&amp;amp;body=OWASP_ZSC_Tool_Project:%0Ahttps://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;t=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Installation'''&lt;br /&gt;
Go to download page, and download last version in github. Extract and run installer.py, then you are able to run software with OWASP ZSC command or you can directly execute zsc.py without installing it.or you can follow these commands to install the last version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;lt;nowiki&amp;gt;wget https://github.com/Ali-Razmjoo/OWASP-ZSC/archive/master.zip -O owasp-zsc.zip &amp;amp;&amp;amp; unzip owasp-zsc.zip &amp;amp;&amp;amp; &lt;br /&gt;
rm -rf owasp-zsc.zip &amp;amp;&amp;amp; mv OWASP-ZSC-master owasp-zsc &amp;amp;&amp;amp; cd owasp-zsc &amp;amp;&amp;amp; python installer.py&amp;lt;/nowiki&amp;gt;&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://zsc.z3r0d4y.com/images/Snapshot_2015-07-27_114843.png&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Note''': Software could be '''uninstall''' with executing '''uninstaller.py'''&lt;br /&gt;
&lt;br /&gt;
'''Note''': Software installation directory is &amp;quot;'''/usr/share/owasp-zsc'''&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''Note''': &amp;lt;strong&amp;gt;OWASP ZSC&amp;lt;/strong&amp;gt; Tool could be execute on &amp;lt;strong&amp;gt;Linux&amp;lt;/strong&amp;gt; and &amp;lt;strong&amp;gt;Python 2.7.x &amp;lt;/strong&amp;gt;is required.&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject=OWASP_ZSC_Tool_Project&amp;amp;body=OWASP_ZSC_Tool_Project:%0Ahttps://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;t=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;August, 2016, the highest priorities for the next one year&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Develop future [http://zsc.z3r0d4y.com/table.html features] list , Add Operation Systems and new encode types&lt;br /&gt;
* Planing for activate features&lt;br /&gt;
* Build ZSC API&lt;br /&gt;
* Find developers to get better performance, quality, optimizing and best improvement in minimum possible time&lt;br /&gt;
* Get other people to review the ZSC Tool Project provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project and the features&lt;br /&gt;
* Keep test, developing and updating with best new methods&lt;br /&gt;
* Build and update documents in several languages for developers/users guiding &lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject=OWASP_ZSC_Tool_Project&amp;amp;body=OWASP_ZSC_Tool_Project:%0Ahttps://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;t=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
OWASP ZSC could be improving with handling module [http://zsc.z3r0d4y.com/table.html features]. MVP of this project is build and active the first module which could be usable to generate/encode Shellcode which already some of them [modules] activated.&lt;br /&gt;
&lt;br /&gt;
Highest usage of OWASP ZSC Tool could be when users are able to use all [http://zsc.z3r0d4y.com/table.html features] with best User Interface and &amp;lt;strong&amp;gt;API&amp;lt;/strong&amp;gt; performance.&lt;br /&gt;
https://www.owasp.org/images/3/33/Zsc.png&lt;br /&gt;
&lt;br /&gt;
= Developers =&lt;br /&gt;
&amp;lt;div class=&amp;quot;plainlinks&amp;quot;&amp;gt;&lt;br /&gt;
'''Share this:'''&amp;amp;nbsp;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share via e-mail&amp;quot; class=&amp;quot;plainlinks&amp;quot;&amp;gt;[[File:social-email.png|E-mail this story|link=mailto:?subject=OWASP_ZSC_Tool_Project&amp;amp;body=OWASP_ZSC_Tool_Project:%0Ahttps://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Facebook&amp;quot;&amp;gt;[[File:social-facebook.png|Bookmark with Facebook|link=http://www.facebook.com/sharer.php?u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;t=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Digg&amp;quot;&amp;gt;[[File:social-digg.png|Share on Digg.com|link=http://digg.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on delicious&amp;quot;&amp;gt;[[File:social-delicious.png|16px|Share on delicious|link=http://delicious.com/post?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on reddit&amp;quot;&amp;gt;[[File:social-reddit.png|Share on reddit.com|link=http://reddit.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on StumbleUpon&amp;quot;&amp;gt;[[File:social-stumbleupon.png|16px|Share on stumbleupon.com|link=http://stumbleupon.com/submit?url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on LinkedIn&amp;quot;&amp;gt;[[File:social-linkedin.png|16px|Share on LinkedIn.com|link=http://www.linkedin.com/shareArticle?mini=true&amp;amp;url=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project&amp;amp;title=OWASP+ZSC+Tool+Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Share on Twitter&amp;quot;&amp;gt;[[File:social-twitter.png|alt=Share on twitter.com|link=http://twitter.com/?status=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project|Share on twitter.com]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span title=&amp;quot;Seed on Newsvine&amp;quot;&amp;gt;[[File:social-newsvine.png|16px|Seed on Newsvine|link=http://www.newsvine.com/_wine/save?popoff=1&amp;amp;u=https://www.owasp.org/index.php/OWASP_ZSC_Tool_Project]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Developers==&lt;br /&gt;
Architect &amp;amp; Creator: Ali Razmjoo&lt;br /&gt;
* Pratik Patel (Google Summer of Code student 2016)&lt;br /&gt;
* Akash Trehan (CodeMaxx)&lt;br /&gt;
* Paras Chetal (Google Summer of Code candidate 2016)&lt;br /&gt;
* Hamid Samani (HAMIDx9)&lt;br /&gt;
&lt;br /&gt;
==Testers ==&lt;br /&gt;
*Johanna Curiel&lt;br /&gt;
*Brian Beaudry&lt;br /&gt;
&lt;br /&gt;
===Be an OWASP ZSC developer===&lt;br /&gt;
&lt;br /&gt;
Developers can add new features and if you don’t have an idea but like to develop, you can submit the issue, which software needs to be fix/add/done in [https://github.com/zscproject/OWASP-ZSC/issues HERE].&lt;br /&gt;
&lt;br /&gt;
After fix/add or develop something, please send your pull request and remember that your code must be compatible with python2 and python3.&lt;br /&gt;
If you have any question you can open an issue or just [mailto:owasp-zsc-tool-project@lists.owasp.org mail us]. do not forget to register on our [https://lists.owasp.org/mailman/listinfo/owasp-zsc-tool-project mailing list].&lt;br /&gt;
&lt;br /&gt;
'''AND DON'T FORGET TO READ [https://github.com/Ali-Razmjoo/OWASP-ZSC/tree/master/doc DEVELOPERS DOCUMENTS]'''&lt;br /&gt;
&lt;br /&gt;
Also this [https://www.gitbook.com/book/ali-razmjoo/owasp-zsc/details GitBook]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_ZSC_Tool_Project}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Breakers]]  &lt;br /&gt;
[[Category:OWASP_Code]] &lt;br /&gt;
[[Category:OWASP_Tool]] &lt;br /&gt;
[[Category:OWASP_Download]] &lt;br /&gt;
[[Category:Shellcode]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GoogleSeasonOfDocs2019&amp;diff=250753</id>
		<title>GoogleSeasonOfDocs2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GoogleSeasonOfDocs2019&amp;diff=250753"/>
				<updated>2019-04-29T02:13:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Added a section for Defect Dojo&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
OWASP is going to apply to participate in the inaugural [https://developers.google.com/season-of-docs/ Google Season of Docs]&lt;br /&gt;
We will be requesting project ideas to help us complete our organization application which is due April 23rd.&lt;br /&gt;
&lt;br /&gt;
= OWASP Project Documentation Requests =&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:'''  &lt;br /&gt;
 '''* Read [https://developers.google.com/season-of-docs/docs/project-ideas Google Season of Docs Project Ideas]'''&lt;br /&gt;
 '''* Read [https://developers.google.com/season-of-docs/terms/program-rules Program Rules]'''&lt;br /&gt;
&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
=== The API ===&lt;br /&gt;
ZAP has an extremely powerful API that allows you to do nearly everything that possible via the desktop interface. It is considered on of ZAPs strengths and is heavily used for automation.&lt;br /&gt;
Unfortunately is also not particularly well documented and we get many queries about it on the support groups.&lt;br /&gt;
&lt;br /&gt;
Existing documentation includes:&lt;br /&gt;
* https://github.com/zaproxy/zaproxy/wiki/ApiDetails&lt;br /&gt;
* https://github.com/zaproxy/zaproxy/wiki/ApiGen_Index&lt;br /&gt;
&lt;br /&gt;
This project would:&lt;br /&gt;
# Explain the concepts behind the UI&lt;br /&gt;
# Explain how it can be used at a high level&lt;br /&gt;
# Detail all of the API calls&lt;br /&gt;
&lt;br /&gt;
The documentation should be suitable for publishing as web pages and for printing on paper.&lt;br /&gt;
&lt;br /&gt;
=== Zest ===&lt;br /&gt;
Zest is an experimental specialized scripting language developed by the ZAP team and is intended to be used in web oriented security tools.&lt;br /&gt;
While it is tool independent it is heavily used by ZAP.&lt;br /&gt;
&lt;br /&gt;
Existing documentation includes:&lt;br /&gt;
* https://developer.mozilla.org/en-US/docs/Mozilla/Projects/Zest&lt;br /&gt;
* https://github.com/mozilla/zest/wiki&lt;br /&gt;
&lt;br /&gt;
This project would:&lt;br /&gt;
# Explain the concepts behind the Zest&lt;br /&gt;
# Explain how to write Zest scripts&lt;br /&gt;
# Document the ZAP Desktop UI provided relating to Zest&lt;br /&gt;
&lt;br /&gt;
The documentation should be suitable for publishing as web pages and ideally the parts relating to the ZAP Desktop UI should be able to be included within the UI as context sensitive help.&lt;br /&gt;
&lt;br /&gt;
==OWASP Juice Shop==&lt;br /&gt;
[[OWASP Juice Shop Project]] is probably the most modern and sophisticated insecure web application! It can be used in security trainings, awareness demos, CTFs and as a guinea pig for security tools! Juice Shop encompasses vulnerabilities from the entire OWASP Top Ten along with many other security flaws found in real-world applications!&lt;br /&gt;
&lt;br /&gt;
===&amp;quot;Pwning OWASP Juice Shop&amp;quot; Companion Guide===&lt;br /&gt;
&lt;br /&gt;
''[https://leanpub.com/juice-shop Pwning OWASP Juice Shop] is the official companion guide for this project. It will give you a complete overview of the vulnerabilities found in the application including hints how to spot and exploit them. In the appendix you will even find complete step-by-step solutions to every challenge. The ebook is published under [https://creativecommons.org/licenses/by-nc-nd/4.0/ CC BY-NC-ND 4.0] and is available '''for free''' as work-in-progress in [https://www.gitbook.com/book/bkimminich/pwning-owasp-juice-shop HTML, PDF, Kindle and ePub format on GitBook]. The latest officially released edition is [https://leanpub.com/juice-shop available '''for free''' on LeanPub in PDF, Kindle and ePub format].''&lt;br /&gt;
&lt;br /&gt;
[[File:PwningOWASPJuiceShop_Cover.jpg|link=https://leanpub.com/juice-shop|100px]]&lt;br /&gt;
&lt;br /&gt;
''The book is divided into three parts:''&lt;br /&gt;
# ''Part I - Hacking preparations (helps you to get the application running and to set up optional hacking tools)''&lt;br /&gt;
# ''Part II - Challenge hunting (gives an overview of the vulnerabilities found in the OWASP Juice Shop including hints how to find and exploit them in the application)''&lt;br /&gt;
# ''Part III - Getting involved (shows up various ways to contribute to the OWASP Juice Shop open source project)''&lt;br /&gt;
&lt;br /&gt;
Primary focus points of this project could be:&lt;br /&gt;
# Migrate the eBook from (legacy) GitBook format to either latest GitBook or another suitable format ''(Mandatory requirement is the ability to generate PDF/ePub/Mobi versions of the book for LeanPub '''and''' to be able to host it in HTML online-readable form)''&lt;br /&gt;
# Tackle the idea to [https://github.com/bkimminich/pwning-juice-shop/issues/21 generate a special &amp;quot;CTF Edition&amp;quot;] of the book from the same source content&lt;br /&gt;
&lt;br /&gt;
This project could additionally:&lt;br /&gt;
* Add hints and solutions for currently undocumented challenges (marked with ''':wrench: **TODO**''')&lt;br /&gt;
* Extend the &amp;quot;Codebase 101&amp;quot; chapter with more details and examples for new contributors&lt;br /&gt;
* Review, curate and extend the other existing content&lt;br /&gt;
&lt;br /&gt;
==OWASP-Securetea Tools Project==&lt;br /&gt;
The OWASP SecureTea Project is an application designed to help secure a person's laptop or computer / server with IoT (Internet Of Things) and notify users (via various communication mechanisms), whenever someone accesses their computer / server. This application uses the touchpad/mouse/wireless mouse to determine activity and is developed in Python and tested on various machines (Linux, Mac &amp;amp; Windows). The software is still under development, and will eventually have it's own IDS(Intrusion Detection System) / IPS(Instrusion Prevention System), firewall, anti-virus, intelligent log monitoring capabilities with web defacement detection, and support for much more communication medium. . - https://github.com/OWASP/SecureTea-Project/blob/master/README.md&amp;lt;br&amp;gt;&lt;br /&gt;
This project would: &amp;lt;br&amp;gt;&lt;br /&gt;
1. Review, curate and extend the other existing content of [https://github.com/OWASP/SecureTea-Project/blob/master/README.md#target-user User Guide] and [https://github.com/OWASP/SecureTea-Project/blob/master/doc/en-US/dev_guide.md Developer Guide] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.Help to translate into many languages as you can do &amp;lt;br&amp;gt;&lt;br /&gt;
Example : [https://github.com/OWASP/SecureTea-Project/blob/master/doc/ja-JP/README.md Japanese Translate]  &amp;lt;br&amp;gt;&lt;br /&gt;
3. As Content Writer we need your best ideas for improve The SecureTea Project Documentation. &amp;lt;br&amp;gt;&lt;br /&gt;
4. Help Our Programmer/Contributors to create their Documentation such as &lt;br /&gt;
Website content,wiki,user docs and developer docs, etc which not yet publish/completed.  &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP DefectDojo ==&lt;br /&gt;
OWASP DefectDojo is a popular open source vulnerability management tool and is used as the backbone for security programs. It is easy to get started with to work on! We welcome volunteers of all experience levels and are happy to provide mentoring.&lt;br /&gt;
&lt;br /&gt;
The existing documentation is on [https://defectdojo.readthedocs.io/en/latest/ Read the Docs] and is created based on the [https://github.com/DefectDojo/Documentation DefectDojo documentation repo].&lt;br /&gt;
&lt;br /&gt;
The project would:&lt;br /&gt;
* Review and update the current documentation based on the latest release in the master branch&lt;br /&gt;
* Update and expand documentation sections including&lt;br /&gt;
** Installation including the new Docker Compose and Kubernetes&lt;br /&gt;
** Liberal inclusion of screenshots or screencasts for various features of the web UI&lt;br /&gt;
** Integrations with various security tools&lt;br /&gt;
** workflows and other real-world use cases that DefectDojo solves&lt;br /&gt;
* Validate the documentation against the Python3 branch which will be the bases for the next major release of DefectDojo&lt;br /&gt;
* Translating the current documentation to languages other than English&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=MediaWiki:Sidebar&amp;diff=249463</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=MediaWiki:Sidebar&amp;diff=249463"/>
				<updated>2019-03-30T04:31:05Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Updated sidebar to remove lists.owasp.org and point it at Google Groups&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Navigation&lt;br /&gt;
** mainpage|Home&lt;br /&gt;
**https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project|About OWASP&lt;br /&gt;
**https://www.owasp.org/index.php/Acknowledgements|Acknowledgements&lt;br /&gt;
**https://www.owasp.org/index.php/Advertising|Advertising&lt;br /&gt;
**https://www.owasp.org/index.php/OWASP_Events/upcoming_events|AppSec Events&lt;br /&gt;
**https://www.owasp.org/index.php/Supporting_Partners|Supporting Partners&lt;br /&gt;
** http://stores.lulu.com/owasp|Books&lt;br /&gt;
**https://www.owasp.org/index.php/Marketing/Resources|Brand Resources&lt;br /&gt;
**https://www.owasp.org/index.php/Careers|Careers&lt;br /&gt;
** https://www.owasp.org/index.php/OWASP_Chapter|Chapters&lt;br /&gt;
**https://www.owasp.org/index.php/Donate|Donate to OWASP&lt;br /&gt;
** :Category:OWASP Download|Downloads&lt;br /&gt;
**https://www.owasp.org/index.php/Funding|Funding&lt;br /&gt;
**https://www.owasp.org/index.php/Governance|Governance&lt;br /&gt;
** https://www.owasp.org/index.php/OWASP_Initiatives_Global_Strategic_Focus|Initiatives&lt;br /&gt;
** https://groups.google.com/a/owasp.org/forum/#!overview|Mailing Lists&lt;br /&gt;
** Membership|Membership &lt;br /&gt;
** https://www.owasp.org/index.php/OWASP_Merchandise | Merchandise&lt;br /&gt;
** :Category:OWASP Presentations|Presentations&lt;br /&gt;
** https://www.owasp.org/index.php/Press|Press&lt;br /&gt;
** :Category:OWASP Project|Projects&lt;br /&gt;
** :Category:OWASP Video|Video&lt;br /&gt;
* Reference&lt;br /&gt;
** :Category:Activity|Activities&lt;br /&gt;
** :Category:Attack|Attacks&lt;br /&gt;
** :Category:Code Snippet|Code Snippets&lt;br /&gt;
** :Category:Control|Controls&lt;br /&gt;
** :Category:Glossary|Glossary&lt;br /&gt;
** :Category:How To|How To...&lt;br /&gt;
** :Category:OWASP Java Project|Java Project&lt;br /&gt;
** :Category:OWASP_.NET_Project|.NET Project&lt;br /&gt;
** :Category:Principle|Principles&lt;br /&gt;
** :Category:Technology|Technologies&lt;br /&gt;
** :Category:Threat Agent|Threat Agents&lt;br /&gt;
** :Category:Vulnerability|Vulnerabilities&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=249462</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=249462"/>
				<updated>2019-03-30T04:26:51Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Updated milestones on the retire Mailman project&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
* [https://drive.google.com/open?id=12T-7Dh11GmPGXBKYHStBPRgBHm_AnUTifMQ6Ip1h2MM Documented process to create a Google Group] (for staff) &lt;br /&gt;
* [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA Instructions on 3 different ways to join a Google Group at OWASP]&lt;br /&gt;
** [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Instructions translated to Japanese] &lt;br /&gt;
* [https://drive.google.com/open?id=1JZepIwS0JA6-eHc3HcIQjmzrIXi-7ugf2QwxWylYCt8 Mapping of old Mailman list names to new Google Group names] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-19 - [Matt] Send out an additional reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce - '''DONE'''&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail - '''DONE'''&lt;br /&gt;
* 2019-03-25 - [Matt] Post migration email via MailChimp &amp;quot;inviting to join other lists&amp;quot; and capture non-opt-in - '''DONE''' &lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host - '''DONE'''&lt;br /&gt;
* 2019-03-27 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org - '''DONE'''&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace - '''DONE'''&lt;br /&gt;
* 2019-04-01 - [Harold] Close discourse.owasp.org account - '''exact date TBD'''&lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
'''(Q1)''' My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
'''(A1)''' You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
'''(Q2)''' How do my existing Mailman user join the new Google Group?  Do they need to have an Google or @owasp.org account?&lt;br /&gt;
&lt;br /&gt;
'''(A2)''' There's several ways to join one of the new Google Groups - they are documented fully [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA here].  And &amp;lt;u&amp;gt;'''you don't have to have a Google account to join our Google Groups'''&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Other translations of instructions on joining a Google Group at OWASP&lt;br /&gt;
* [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese]&lt;br /&gt;
'''(Q3)''' Do I need to have a Google account, an @owasp.org email or provide my phone number/mobile number to participate in Google Groups at OWASP?&lt;br /&gt;
&lt;br /&gt;
'''(A3)''' No, all you need is an email address and you can participate in any of the OWASP Foundation Google Groups.  For specifics on how to join a Google Group without a Google or @owasp.org email address, see part 2 of this [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA document] - also available in [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese].&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=249431</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=249431"/>
				<updated>2019-03-28T19:31:26Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Updated items on the timeline&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
* [https://drive.google.com/open?id=12T-7Dh11GmPGXBKYHStBPRgBHm_AnUTifMQ6Ip1h2MM Documented process to create a Google Group] (for staff) &lt;br /&gt;
* [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA Instructions on 3 different ways to join a Google Group at OWASP]&lt;br /&gt;
** [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Instructions translated to Japanese] &lt;br /&gt;
* [https://drive.google.com/open?id=1JZepIwS0JA6-eHc3HcIQjmzrIXi-7ugf2QwxWylYCt8 Mapping of old Mailman list names to new Google Group names] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-19 - [Matt] Send out an additional reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce - '''DONE'''&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail - '''DONE'''&lt;br /&gt;
* 2019-03-25 - [Matt] Post migration email via MailChimp &amp;quot;inviting to join other lists&amp;quot; and capture non-opt-in - '''DONE''' &lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host - In Process&lt;br /&gt;
* 2019-03-27 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD'''&lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
'''(Q1)''' My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
'''(A1)''' You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
'''(Q2)''' How do my existing Mailman user join the new Google Group?  Do they need to have an Google or @owasp.org account?&lt;br /&gt;
&lt;br /&gt;
'''(A2)''' There's several ways to join one of the new Google Groups - they are documented fully [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA here].  And &amp;lt;u&amp;gt;'''you don't have to have a Google account to join our Google Groups'''&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Other translations of instructions on joining a Google Group at OWASP&lt;br /&gt;
* [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese]&lt;br /&gt;
'''(Q3)''' Do I need to have a Google account, an @owasp.org email or provide my phone number/mobile number to participate in Google Groups at OWASP?&lt;br /&gt;
&lt;br /&gt;
'''(A3)''' No, all you need is an email address and you can participate in any of the OWASP Foundation Google Groups.  For specifics on how to join a Google Group without a Google or @owasp.org email address, see part 2 of this [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA document] - also available in [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese].&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=249273</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=249273"/>
				<updated>2019-03-25T17:51:01Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Updated one of the milestone per convo with Mike&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
* [https://drive.google.com/open?id=12T-7Dh11GmPGXBKYHStBPRgBHm_AnUTifMQ6Ip1h2MM Documented process to create a Google Group] (for staff) &lt;br /&gt;
* [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA Instructions on 3 different ways to join a Google Group at OWASP]&lt;br /&gt;
** [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Instructions translated to Japanese] &lt;br /&gt;
* [https://drive.google.com/open?id=1JZepIwS0JA6-eHc3HcIQjmzrIXi-7ugf2QwxWylYCt8 Mapping of old Mailman list names to new Google Group names] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-19 - [Matt] Send out an additional reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce - '''DONE'''&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail - '''DONE'''&lt;br /&gt;
* 2019-03-25 - [Matt] Two Post migration emails via MailChimp &amp;quot;inviting to join other lists&amp;quot; and capture non-opt-in&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host - In Process&lt;br /&gt;
* 2019-03-27 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD'''&lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
'''(Q1)''' My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
'''(A1)''' You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
'''(Q2)''' How do my existing Mailman user join the new Google Group?  Do they need to have an Google or @owasp.org account?&lt;br /&gt;
&lt;br /&gt;
'''(A2)''' There's several ways to join one of the new Google Groups - they are documented fully [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA here].  And &amp;lt;u&amp;gt;'''you don't have to have a Google account to join our Google Groups'''&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Other translations of instructions on joining a Google Group at OWASP&lt;br /&gt;
* [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese]&lt;br /&gt;
'''(Q3)''' Do I need to have a Google account, an @owasp.org email or provide my phone number/mobile number to participate in Google Groups at OWASP?&lt;br /&gt;
&lt;br /&gt;
'''(A3)''' No, all you need is an email address and you can participate in any of the OWASP Foundation Google Groups.  For specifics on how to join a Google Group without a Google or @owasp.org email address, see part 2 of this [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA document] - also available in [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese].&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=249272</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=249272"/>
				<updated>2019-03-25T16:56:36Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Moved a Milestone to later this week - no reason to break any lingering outbound emails.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
* [https://drive.google.com/open?id=12T-7Dh11GmPGXBKYHStBPRgBHm_AnUTifMQ6Ip1h2MM Documented process to create a Google Group] (for staff) &lt;br /&gt;
* [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA Instructions on 3 different ways to join a Google Group at OWASP]&lt;br /&gt;
** [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Instructions translated to Japanese] &lt;br /&gt;
* [https://drive.google.com/open?id=1JZepIwS0JA6-eHc3HcIQjmzrIXi-7ugf2QwxWylYCt8 Mapping of old Mailman list names to new Google Group names] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-19 - [Matt] Send out an additional reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce - '''DONE'''&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail - '''DONE'''&lt;br /&gt;
* 2019-03-25 &amp;amp; 27 Two Post migration emails via MailChimp &amp;quot;inviting to join other lists&amp;quot; and capture non-opt-in&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host - In Process&lt;br /&gt;
* 2019-03-27 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD'''&lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
'''(Q1)''' My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
'''(A1)''' You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
'''(Q2)''' How do my existing Mailman user join the new Google Group?  Do they need to have an Google or @owasp.org account?&lt;br /&gt;
&lt;br /&gt;
'''(A2)''' There's several ways to join one of the new Google Groups - they are documented fully [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA here].  And &amp;lt;u&amp;gt;'''you don't have to have a Google account to join our Google Groups'''&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Other translations of instructions on joining a Google Group at OWASP&lt;br /&gt;
* [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese]&lt;br /&gt;
'''(Q3)''' Do I need to have a Google account, an @owasp.org email or provide my phone number/mobile number to participate in Google Groups at OWASP?&lt;br /&gt;
&lt;br /&gt;
'''(A3)''' No, all you need is an email address and you can participate in any of the OWASP Foundation Google Groups.  For specifics on how to join a Google Group without a Google or @owasp.org email address, see part 2 of this [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA document] - also available in [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese].&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=249269</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=249269"/>
				<updated>2019-03-25T14:44:08Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Updated several milestone statuses&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
* [https://drive.google.com/open?id=12T-7Dh11GmPGXBKYHStBPRgBHm_AnUTifMQ6Ip1h2MM Documented process to create a Google Group] (for staff) &lt;br /&gt;
* [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA Instructions on 3 different ways to join a Google Group at OWASP]&lt;br /&gt;
** [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Instructions translated to Japanese] &lt;br /&gt;
* [https://drive.google.com/open?id=1JZepIwS0JA6-eHc3HcIQjmzrIXi-7ugf2QwxWylYCt8 Mapping of old Mailman list names to new Google Group names] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-19 - [Matt] Send out an additional reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail - '''DONE'''&lt;br /&gt;
* 2019-03-25 &amp;amp; 27 Two Post migration emails via MailChimp &amp;quot;inviting to join other lists&amp;quot; and capture non-opt-in&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host - In Process&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD'''&lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
'''(Q1)''' My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
'''(A1)''' You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
'''(Q2)''' How do my existing Mailman user join the new Google Group?  Do they need to have an Google or @owasp.org account?&lt;br /&gt;
&lt;br /&gt;
'''(A2)''' There's several ways to join one of the new Google Groups - they are documented fully [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA here].  And &amp;lt;u&amp;gt;'''you don't have to have a Google account to join our Google Groups'''&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Other translations of instructions on joining a Google Group at OWASP&lt;br /&gt;
* [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese]&lt;br /&gt;
'''(Q3)''' Do I need to have a Google account, an @owasp.org email or provide my phone number/mobile number to participate in Google Groups at OWASP?&lt;br /&gt;
&lt;br /&gt;
'''(A3)''' No, all you need is an email address and you can participate in any of the OWASP Foundation Google Groups.  For specifics on how to join a Google Group without a Google or @owasp.org email address, see part 2 of this [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA document] - also available in [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese].&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ithilgore&amp;diff=249034</id>
		<title>User:Ithilgore</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ithilgore&amp;diff=249034"/>
				<updated>2019-03-20T17:35:55Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Creating user page for new user.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Fotios (Fotis) Chantzis is a principal information security engineer at Mayo Clinic, where he manages and conducts technical vulnerability assessments on medical devices and clinical support systems as well as penetretation tests and red team engagements on the network. Fotis has over 10 years of experience in the information security industry, which includes time spent researching network protocol vulnerabilities and developing security tools. He has been a contributor to the Nmap project since 2009, when he wrote the Ncrack network authentication cracking tool, which he still maintains, and has published a video course on &amp;quot;Mastering Nmap&amp;quot;. His research on network security includes exploiting the TCP Persist Timer (published on Phrack #66) and inventing a new stealthy port scanning technique by abusing the popular XMPP. His most recent research focus has been on medical device &amp;amp; IoT security.&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Ithilgore&amp;diff=249035</id>
		<title>User talk:Ithilgore</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Ithilgore&amp;diff=249035"/>
				<updated>2019-03-20T17:35:55Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Welcome!&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Welcome to ''OWASP''!'''&lt;br /&gt;
We hope you will contribute much and well.&lt;br /&gt;
You will probably want to read the [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents help pages].&lt;br /&gt;
Again, welcome and have fun! [[User:Mtesauro|Mtesauro]] ([[User talk:Mtesauro|talk]]) 12:35, 20 March 2019 (CDT)&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248974</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248974"/>
				<updated>2019-03-19T20:34:21Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: /* Milestones */ Updated Milestones&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
* [https://drive.google.com/open?id=12T-7Dh11GmPGXBKYHStBPRgBHm_AnUTifMQ6Ip1h2MM Documented process to create a Google Group] (for staff) &lt;br /&gt;
* [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA Instructions on 3 different ways to join a Google Group at OWASP]&lt;br /&gt;
** [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Instructions translated to Japanese] &lt;br /&gt;
* [https://drive.google.com/open?id=1JZepIwS0JA6-eHc3HcIQjmzrIXi-7ugf2QwxWylYCt8 Mapping of old Mailman list names to new Google Group names] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''DONE''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-19 - [Matt] Send out an additional reminder to all remaining lists about the transition - '''DONE'''&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-22 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD'''&lt;br /&gt;
* TBD Two Post migration emails via MailChimp &amp;quot;inviting to join other lists&amp;quot; and capture non-opt-in&lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
'''(Q1)''' My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
'''(A1)''' You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
'''(Q2)''' How do my existing Mailman user join the new Google Group?  Do they need to have an Google or @owasp.org account?&lt;br /&gt;
&lt;br /&gt;
'''(A2)''' There's several ways to join one of the new Google Groups - they are documented fully [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA here].  And &amp;lt;u&amp;gt;'''you don't have to have a Google account to join our Google Groups'''&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Other translations of instructions on joining a Google Group at OWASP&lt;br /&gt;
* [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese]&lt;br /&gt;
'''(Q3)''' Do I need to have a Google account, an @owasp.org email or provide my phone number/mobile number to participate in Google Groups at OWASP?&lt;br /&gt;
&lt;br /&gt;
'''(A3)''' No, all you need is an email address and you can participate in any of the OWASP Foundation Google Groups.  For specifics on how to join a Google Group without a Google or @owasp.org email address, see part 2 of this [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA document] - also available in [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese].&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=March_2019&amp;diff=248937</id>
		<title>March 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=March_2019&amp;diff=248937"/>
				<updated>2019-03-18T17:11:24Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Updated zoom link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
Meeting Date:&lt;br /&gt;
March 18&lt;br /&gt;
&lt;br /&gt;
Meeting Time:&lt;br /&gt;
11 AM US Pacific - [https://www.timeanddate.com/worldclock/meetingdetails.html?year=2019&amp;amp;month=3&amp;amp;day=18&amp;amp;hour=18&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=16&amp;amp;p2=919&amp;amp;p3=78&amp;amp;p4=136&amp;amp;p5=137&amp;amp;p6=676 other time zones]&lt;br /&gt;
&lt;br /&gt;
Meeting Location:&lt;br /&gt;
Remote&lt;br /&gt;
&lt;br /&gt;
Virtual: &lt;br /&gt;
[https://zoom.us/j/282821949 Zoom Meeting Link]  Meeting ID: 282 821 949 - [https://zoom.us/u/kvUg3969 local dial in numbers]&lt;br /&gt;
&lt;br /&gt;
 AGENDA&lt;br /&gt;
&lt;br /&gt;
 CALL TO ORDER&lt;br /&gt;
&lt;br /&gt;
 CHANGES TO THE AGENDA&lt;br /&gt;
&lt;br /&gt;
 APPROVAL OF MINUTES&lt;br /&gt;
 [https://docs.google.com/document/d/1rOQ6bHHS5m-tDk5Y-DQv2gDVuQObV9DAg1FhpBGxSLY/edit?usp=sharing '''February 2019 Minutes''']&lt;br /&gt;
&lt;br /&gt;
 REPORTS&lt;br /&gt;
&lt;br /&gt;
 OLD BUSINESS&lt;br /&gt;
&lt;br /&gt;
 NEW BUSINESS&lt;br /&gt;
&lt;br /&gt;
 COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS&lt;br /&gt;
&lt;br /&gt;
 ADJOURNMENT&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
Resolutions updates on&lt;br /&gt;
# Direct the Interim Executive Director to proceed with a registered trademark effort for the organization's identity and conferences in the United States, European Union, and the United Kingdom. The budget cap for this effort is $75,000.&lt;br /&gt;
#* The BoD has asked the Interim Executive Director to review possibilities reducing the perceived high costs by&lt;br /&gt;
#** Getting a quote with less research required&lt;br /&gt;
#** Getting a quote from a European based company&lt;br /&gt;
#** Estimating if it would be financial beneficial not to include UK trademark yet but to delay until Brexit&lt;br /&gt;
# Direct staff to implement an Attributed Giving policy that restricts donations and membership dues splits to gifts more than $25,000. This policy will, as soon as is practically possible, sunset the practice of allowing membership dues being allocated to chapters and projects.&lt;br /&gt;
#* The BoD has asked the Interim Executive Directory to come with a new proposal based on the discussion during the February public board call.&lt;br /&gt;
# Approve the [https://docs.google.com/spreadsheets/d/10LCiXk_Mbq3Rb72kwOVkKxLJy0XABO5cQiQRr2eYH-U/edit?usp=sharing Draft 2019 Budget]&lt;br /&gt;
==New Business==&lt;br /&gt;
* Resolution proposed by the Interim Executive Director that would direct staff to implement an Attributed Giving policy that restricts donations and membership dues splits to gifts $2,500 and above. This policy will, as soon as is practically possible, sunset the practice of allowing membership dues being allocated to chapters and projects.&lt;br /&gt;
&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Community_and_Ops_Work_Queue&amp;diff=248787</id>
		<title>Community and Ops Work Queue</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Community_and_Ops_Work_Queue&amp;diff=248787"/>
				<updated>2019-03-14T18:07:47Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Redirected to new location&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[https://www.owasp.org/index.php/User:Mtesauro]]Deprecated with new ED - update TBD.&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Community_and_Ops_Work_Queue&amp;diff=248786</id>
		<title>Community and Ops Work Queue</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Community_and_Ops_Work_Queue&amp;diff=248786"/>
				<updated>2019-03-14T18:06:16Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Updated content to reflect current practices&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Deprecated with new ED - update TBD.&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248573</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248573"/>
				<updated>2019-03-09T03:34:33Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Added an additional FAQ&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
* [https://drive.google.com/open?id=12T-7Dh11GmPGXBKYHStBPRgBHm_AnUTifMQ6Ip1h2MM Documented process to create a Google Group] (for staff) &lt;br /&gt;
* [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA Instructions on 3 different ways to join a Google Group at OWASP]&lt;br /&gt;
** [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Instructions translated to Japanese] &lt;br /&gt;
* [https://drive.google.com/open?id=1JZepIwS0JA6-eHc3HcIQjmzrIXi-7ugf2QwxWylYCt8 Mapping of old Mailman list names to new Google Group names] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-22 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD''' &lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
'''(Q1)''' My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
'''(A1)''' You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
'''(Q2)''' How do my existing Mailman user join the new Google Group?  Do they need to have an Google or @owasp.org account?&lt;br /&gt;
&lt;br /&gt;
'''(A2)''' There's several ways to join one of the new Google Groups - they are documented fully [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA here].  And &amp;lt;u&amp;gt;'''you don't have to have a Google account to join our Google Groups'''&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Other translations of instructions on joining a Google Group at OWASP&lt;br /&gt;
* [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese]&lt;br /&gt;
'''(Q3)''' Do I need to have a Google account, an @owasp.org email or provide my phone number/mobile number to participate in Google Groups at OWASP?&lt;br /&gt;
&lt;br /&gt;
'''(A3)''' No, all you need is an email address and you can participate in any of the OWASP Foundation Google Groups.  For specifics on how to join a Google Group without a Google or @owasp.org email address, see part 2 of this [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA document] - also available in [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese].&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248572</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248572"/>
				<updated>2019-03-09T00:48:03Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Added link to spreadsheet mapping old Mailman name to new Google Group&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
* [https://drive.google.com/open?id=12T-7Dh11GmPGXBKYHStBPRgBHm_AnUTifMQ6Ip1h2MM Documented process to create a Google Group] (for staff) &lt;br /&gt;
* [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA Instructions on 3 different ways to join a Google Group at OWASP]&lt;br /&gt;
** [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Instructions translated to Japanese] &lt;br /&gt;
* [https://drive.google.com/open?id=1JZepIwS0JA6-eHc3HcIQjmzrIXi-7ugf2QwxWylYCt8 Mapping of old Mailman list names to new Google Group names] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-22 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD''' &lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
'''(Q1)''' My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
'''(A1)''' You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
'''(Q2)''' How do my existing Mailman user join the new Google Group?  Do they need to have an Google or @owasp.org account?&lt;br /&gt;
&lt;br /&gt;
'''(A2)''' There's several ways to join one of the new Google Groups - they are documented fully [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA here].  And &amp;lt;u&amp;gt;'''you don't have to have a Google account to join our Google Groups'''&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Other translations of instructions on joining a Google Group at OWASP&lt;br /&gt;
* [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese]&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.AppSecEU2013.pdf&amp;diff=248478</id>
		<title>File:Training Instructor Agreement.AppSecEU2013.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.AppSecEU2013.pdf&amp;diff=248478"/>
				<updated>2019-03-06T18:55:16Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Protected &amp;quot;File:Training Instructor Agreement.AppSecEU2013.pdf&amp;quot;: File is a deprecated version of the training agreement. ([Edit=Allow only administrators] (indefinite) [Move=Allow only administrators] (indefinite) [Upload=Allow only administrators]...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.AppSecEU2013.pdf&amp;diff=248477</id>
		<title>File:Training Instructor Agreement.AppSecEU2013.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.AppSecEU2013.pdf&amp;diff=248477"/>
				<updated>2019-03-06T18:52:55Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Mtesauro uploaded a new version of File:Training Instructor Agreement.AppSecEU2013.pdf&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248452</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248452"/>
				<updated>2019-03-06T15:48:56Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Added Japanese translation of &amp;quot;How to join Google Group&amp;quot; document to the project page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
* [https://drive.google.com/open?id=12T-7Dh11GmPGXBKYHStBPRgBHm_AnUTifMQ6Ip1h2MM Documented process to create a Google Group] (for staff) &lt;br /&gt;
* [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA Instructions on 3 different ways to join a Google Group at OWASP]&lt;br /&gt;
** [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Instructions translated to Japanese] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-22 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD''' &lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
'''(Q1)''' My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
'''(A1)''' You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
'''(Q2)''' How do my existing Mailman user join the new Google Group?  Do they need to have an Google or @owasp.org account?&lt;br /&gt;
&lt;br /&gt;
'''(A2)''' There's several ways to join one of the new Google Groups - they are documented fully [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA here].  And &amp;lt;u&amp;gt;'''you don't have to have a Google account to join our Google Groups'''&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Other translations of instructions on joining a Google Group at OWASP&lt;br /&gt;
* [https://drive.google.com/open?id=1sSZQRYZvsBbvu9c-okKID53RlmIc79xS8zRRnguR1uk Japanese]&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248422</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248422"/>
				<updated>2019-03-06T04:47:52Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Added info and links on how to join Google Groups&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
* [https://drive.google.com/open?id=12T-7Dh11GmPGXBKYHStBPRgBHm_AnUTifMQ6Ip1h2MM Documented process to create a Google Group] (for staff) &lt;br /&gt;
* [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA Instructions on 3 different ways to join a Google Group at OWASP] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-22 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD''' &lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
'''(Q1)''' My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
'''(A1)''' You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
'''(Q2)''' How do my existing Mailman user join the new Google Group?  Do they need to have an Google or @owasp.org account?&lt;br /&gt;
&lt;br /&gt;
'''(A2)''' There's several ways to join one of the new Google Groups - they are documented fully [https://drive.google.com/open?id=1TBzgvB8Tb0aAZnEy2qYzLnrzJuRzK_T91Em09DVf5YA here].  And &amp;lt;u&amp;gt;'''you don't have to have a Google account to join our Google Groups'''&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Chapter&amp;diff=248380</id>
		<title>OWASP Chapter</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Chapter&amp;diff=248380"/>
				<updated>2019-03-05T18:20:25Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Removed GoToMeeting, added Zoom&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
The OWASP Chapters program helps to foster local discussion of application security around the world. Our Local Chapters are free and open to anyone and managed by a set of guidelines known as the [[Chapter_Leader_Handbook | OWASP Chapter Handbook]].  Many of the popular [[:Category:OWASP Presentations | OWASP presentations]] are available for everyone to use at meetings.&lt;br /&gt;
&lt;br /&gt;
==Join Your Local Chapter==&lt;br /&gt;
Attending meetings anywhere in the world is FREE and OPEN to anyone, membership is NOT required to do so. We suggest that you locate your  &amp;quot;home chapter&amp;quot; and simply sign up on the appropriate mailing list, watch for the next local meeting stop by to introduce yourself ask questions and collaborate. &lt;br /&gt;
&lt;br /&gt;
[[Image:Btn_donate_SM.gif|link=http://www.regonline.com/donation_1044369]] to a chapter or become a local chapter supporter.&lt;br /&gt;
&lt;br /&gt;
Or consider the value of [http://www.owasp.org/index.php/Membership Individual, Corporate, or Academic Supporter membership]. Ready to become a member? [[Image:Join_Now_BlueIcon.JPG|75px|link=https://www.owasp.org/index.php/Membership]]&lt;br /&gt;
&lt;br /&gt;
==Chapters by Geographic Region==&lt;br /&gt;
&lt;br /&gt;
Subcategories are listed alphabetically by state, province, or country as applicable. Inactive chapters are marked with (i) and are seeking new leaders. If you would like to restart an inactive chapter, please use the [https://www.tfaforms.com/261541 OWASP Chapter Request Form]. &amp;lt;b&amp;gt; CLICK TO EXPAND REGION&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;500&amp;quot; |United States&lt;br /&gt;
|-&lt;br /&gt;
| {{:Category:United_States}}&lt;br /&gt;
|}&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;500&amp;quot; |Canada&lt;br /&gt;
|-&lt;br /&gt;
| {{:Category:Canada}}&lt;br /&gt;
|}&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;500&amp;quot; |Caribbean&lt;br /&gt;
|-&lt;br /&gt;
| {{:Category:Caribbean}}&lt;br /&gt;
|}&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;500&amp;quot; |Latin America&lt;br /&gt;
|-&lt;br /&gt;
| {{:Category:Latin America}}&lt;br /&gt;
|} &lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;500&amp;quot; |Europe &lt;br /&gt;
|-&lt;br /&gt;
| {{:Category:Europe}}&lt;br /&gt;
|} &lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;500&amp;quot; |Asia/Pacific/Middle East&lt;br /&gt;
|-&lt;br /&gt;
| {{:Category:Asia/Pacific/Middle_East}}&lt;br /&gt;
|}&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;500&amp;quot; |Africa&lt;br /&gt;
|-&lt;br /&gt;
| {{:Category:Africa}}&lt;br /&gt;
|}&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;500&amp;quot; |Virtual&lt;br /&gt;
|-&lt;br /&gt;
| {{:Category:Virtual}}&lt;br /&gt;
|}&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;500&amp;quot; |OWASP Student Chapter&lt;br /&gt;
|-&lt;br /&gt;
| {{:Category:OWASP Student Chapter}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==OWASP Student Chapters Program==&lt;br /&gt;
&lt;br /&gt;
The Open Web Application Security Project (OWASP) has local chapters around the world that help teach, learn, and inspire application security. Our Student Chapters program helps to extend application security into colleges and universities worldwide. OWASP Student Chapters Program is a way to integrate passionate AppSec students. We want to create students chapters in order to organise events, meetings and have fun! If your school has a computer science or management information systems degree, we can help you [https://www.owasp.org/index.php/OWASP_Student_Chapters_Program Start a Student Chapter] there.&lt;br /&gt;
&lt;br /&gt;
View the [[OWASP Student Chapters Program]] information and a list of participating student groups.&lt;br /&gt;
&lt;br /&gt;
==Start a Chapter==&lt;br /&gt;
&lt;br /&gt;
You don't need to be an expert in application security, just motivated to help build the OWASP community and organize meetings. There's a lot of help available from other Local Chapter leaders. So get your community moving to help the mission of software security awareness and start a local OWASP Chapter today!&lt;br /&gt;
&lt;br /&gt;
'''A request to start or restart a chapter should be submitted by the founding member or group to the [https://owasporg.atlassian.net/servicedesk/customer/portal/7/create/73 OWASP Chapter Request Form]''' and should include:&lt;br /&gt;
&lt;br /&gt;
# List of the people that are founding the chapter and the geographical area to be covered by the new chapter, &lt;br /&gt;
# Brief description of professional background or resume (from each of the founding leaders),&lt;br /&gt;
# Statement of why he or she wants to be an OWASP Leader (from each of the founding leaders).&lt;br /&gt;
# Each founding leader(s) (as well as any leaders joining the chapter after its creation) must read, understand, and agree to the terms of the [[Chapter Leader Handbook]].&lt;br /&gt;
&lt;br /&gt;
 Generally speaking, the Chapter Leader Handbook asks that you:&lt;br /&gt;
 * Will commit to organizing at least quarterly meetings&lt;br /&gt;
 * Will find a stable location for meetings&lt;br /&gt;
 * Will find great speakers&lt;br /&gt;
 * Will publicize the chapter and recruit new members&lt;br /&gt;
 * Will keep the chapter non-commercial&lt;br /&gt;
&lt;br /&gt;
'''What is the process once I submit my request to start a chapter?'''&lt;br /&gt;
&lt;br /&gt;
Once submitted, the request will be reviewed and approved by the OWASP Staff.   Once the new chapter is approved&lt;br /&gt;
&lt;br /&gt;
1.  A chapter wiki page and mailing list will be set up for the new leader(s). &lt;br /&gt;
&lt;br /&gt;
2.  The chapter leader(s) will be given an owasp email account and password to operate as the administrator of the new chapter mailing list.&lt;br /&gt;
&lt;br /&gt;
==Update Chapter Leader==&lt;br /&gt;
&lt;br /&gt;
You may also use the [http://www.tfaforms.com/261541 OWASP Chapter Request Form] to modify or add new chapter leaders. The chapter wiki page and OWASP Foundation records must be updated for leaders to access benefits. This form ensures that our internal records will be up to date.&lt;br /&gt;
&lt;br /&gt;
==Bring Speakers to Your Chapter==&lt;br /&gt;
To support Local Chapter meetings and (web application) security conferences we started a travel-support program for OWASP presenters. If you are interested in attracting an OWASP speaker to your event, have a look at [[OWASP on the Move]]!&lt;br /&gt;
&lt;br /&gt;
==Chapter Support Materials==&lt;br /&gt;
&lt;br /&gt;
* The OWASP [[Chapter Leader Handbook]] includes mandatory rules and guidelines.&lt;br /&gt;
&lt;br /&gt;
Funding&lt;br /&gt;
* [https://www.owasp.org/index.php/Funding General and Chapter Funding Information]&lt;br /&gt;
&lt;br /&gt;
Chapter Communications&lt;br /&gt;
* [https://zoom.us/ Zoom] is the meeting software available to chapters - request a Zoom account for your chapter [https://www.tfaforms.com/308703 here].&lt;br /&gt;
* OWASP [[Chapter Presentation Bundles | Chapter Presentation Bundles]].&lt;br /&gt;
* OWASP [[Template:News Item | News Item Template]].&lt;br /&gt;
* OWASP Chapters Mailing list for all OWASP Chapter Leaders https://lists.owasp.org/mailman/listinfo/owasp-chapters&lt;br /&gt;
&lt;br /&gt;
Marketing and Promotion&lt;br /&gt;
* OWASP [[Chapter_Promotion | Chapter promotion Tips]].&lt;br /&gt;
* For OWASP Branded Chapter Supplies please fill out this [https://spreadsheets.google.com/a/owasp.org/spreadsheet/viewform?formkey=dF85bGtvdWdrd2JjYldNZ1gxSkJxaEE6MQ Google Form] for requesting general OWASP promotional materials.  Also, [[Chapter Supplies | View Apparel]] available through our 3rd party vendor.&lt;br /&gt;
* OWASP [[Marketing | Marketing Resources, Logos and Brand Guidelines]].&lt;br /&gt;
&lt;br /&gt;
For more detail visit the OWASP [[:Category:Chapter_Resources | Chapter Resources Page]].&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Learning Resources ==&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/channel/UCxSU-KvNmYusZEq6v4YK5Lw/featured Ottawa Chapter Training Videos]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Let [mailto://Tiffany.Long@owasp.org OWASP] know if your Chapter has training resources you would like to see here&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:Chapter_Template&amp;diff=248376</id>
		<title>Template:Chapter Template</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:Chapter_Template&amp;diff=248376"/>
				<updated>2019-03-05T17:03:51Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: More testing templates&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== OWASP {{{chaptername}}} ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the {{{chaptername}}} chapter homepage. {{{extra}}} &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{#if:{{{meetupurl|}}}|&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
[{{{meetupurl}}} https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [{{{meetupurl}}} {{{chaptername}}} Schedule of Events]&lt;br /&gt;
| &amp;lt;noinclude&amp;gt; [{{{meetupurl}}} https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [{{{meetupurl}}} {{{chaptername}}} Schedule of Events] &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{#if:{{{meetupgroup|}}}|&lt;br /&gt;
&amp;lt;meetup group={{{meetupgroup}}} /&amp;gt;&lt;br /&gt;
|&amp;lt;noinclude&amp;gt;&amp;lt;meetup group={{{meetupgroup}}} /&amp;gt; &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
== Participation == &lt;br /&gt;
OWASP Foundation ([https://docs.google.com/a/owasp.org/presentation/d/10wi1EWFCPZwCpkB6qZaBNN8mR2XfQs8sLxcj9SCsP6c/edit?usp=sharing Overview Slides]) is a professional association of [[Membership | global members]] and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the [[Chapter_Leader_Handbook]].  As a [[About_OWASP | 501(c)(3)]] non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button.  To be a &amp;lt;b&amp;gt;SPEAKER&amp;lt;/b&amp;gt; at ANY OWASP Chapter in the world simply review the [[Speaker_Agreement | speaker agreement]] and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.&lt;br /&gt;
&lt;br /&gt;
== Sponsorship/Membership  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Btn_donate_SM.gif|link=https://www.owasp.org/index.php/Local_Chapter_Supporter]] to this chapter or become a local chapter supporter.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Or consider the value of [[Membership | Individual, Corporate, or Academic Supporter membership]]. Ready to become a member? [[Image:Join_Now_BlueIcon.JPG|75px|link=https://www.owasp.org/index.php/Membership]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:{{{region}}}]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:Chapter_Template&amp;diff=248375</id>
		<title>Template:Chapter Template</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:Chapter_Template&amp;diff=248375"/>
				<updated>2019-03-05T17:02:35Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: More testing templates&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== OWASP {{{chaptername}}} ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the {{{chaptername}}} chapter homepage. {{{extra}}} &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{#if:{{{meetupurl|}}}|&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
[{{{meetupurl}}} https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [{{{meetupurl}}} {{{chaptername}}} Schedule of Events]&lt;br /&gt;
| &amp;lt;noinclude&amp;gt; [{{{meetupurl}}} https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [{{{meetupurl}}} {{{chaptername}}} Schedule of Events] &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;meetup group=&amp;quot;owasp-albany-meetup&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{#if:{{{meetupgroup|}}}|&lt;br /&gt;
&amp;lt;meetup group={{{meetupgroup}}} /&amp;gt;&lt;br /&gt;
|&amp;lt;noinclude&amp;gt;&amp;lt;meetup group={{{meetupgroup}}} /&amp;gt; &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
== Participation == &lt;br /&gt;
OWASP Foundation ([https://docs.google.com/a/owasp.org/presentation/d/10wi1EWFCPZwCpkB6qZaBNN8mR2XfQs8sLxcj9SCsP6c/edit?usp=sharing Overview Slides]) is a professional association of [[Membership | global members]] and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the [[Chapter_Leader_Handbook]].  As a [[About_OWASP | 501(c)(3)]] non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button.  To be a &amp;lt;b&amp;gt;SPEAKER&amp;lt;/b&amp;gt; at ANY OWASP Chapter in the world simply review the [[Speaker_Agreement | speaker agreement]] and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.&lt;br /&gt;
&lt;br /&gt;
== Sponsorship/Membership  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Btn_donate_SM.gif|link=https://www.owasp.org/index.php/Local_Chapter_Supporter]] to this chapter or become a local chapter supporter.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Or consider the value of [[Membership | Individual, Corporate, or Academic Supporter membership]]. Ready to become a member? [[Image:Join_Now_BlueIcon.JPG|75px|link=https://www.owasp.org/index.php/Membership]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:{{{region}}}]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:Chapter_Template&amp;diff=248370</id>
		<title>Template:Chapter Template</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:Chapter_Template&amp;diff=248370"/>
				<updated>2019-03-05T16:19:52Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: More testing templates&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== OWASP {{{chaptername}}} ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the {{{chaptername}}} chapter homepage. {{{extra}}} &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{#if:{{{meetupurl|}}}|&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
[{{{meetupurl}}} https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [{{{meetupurl}}} {{{chaptername}}} Schedule of Events]&lt;br /&gt;
| &amp;lt;noinclude&amp;gt; [{{{meetupurl}}} https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [{{{meetupurl}}} {{{chaptername}}} Schedule of Events] &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
BEFORE IF&lt;br /&gt;
{{#if:{{{meetupgroup|}}}|&lt;br /&gt;
{{#tag:html|&lt;br /&gt;
Insert here&lt;br /&gt;
&amp;lt;meetup group=&amp;quot;{{{meetupgroup}}}&amp;quot; /&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
|OR INSERT HERE&amp;lt;noinclude&amp;gt;&amp;lt;meetup group=&amp;quot;{{{meetupgroup}}}&amp;quot; /&amp;gt; &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
== Participation == &lt;br /&gt;
OWASP Foundation ([https://docs.google.com/a/owasp.org/presentation/d/10wi1EWFCPZwCpkB6qZaBNN8mR2XfQs8sLxcj9SCsP6c/edit?usp=sharing Overview Slides]) is a professional association of [[Membership | global members]] and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the [[Chapter_Leader_Handbook]].  As a [[About_OWASP | 501(c)(3)]] non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button.  To be a &amp;lt;b&amp;gt;SPEAKER&amp;lt;/b&amp;gt; at ANY OWASP Chapter in the world simply review the [[Speaker_Agreement | speaker agreement]] and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.&lt;br /&gt;
&lt;br /&gt;
== Sponsorship/Membership  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Btn_donate_SM.gif|link=https://www.owasp.org/index.php/Local_Chapter_Supporter]] to this chapter or become a local chapter supporter.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Or consider the value of [[Membership | Individual, Corporate, or Academic Supporter membership]]. Ready to become a member? [[Image:Join_Now_BlueIcon.JPG|75px|link=https://www.owasp.org/index.php/Membership]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:{{{region}}}]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:Chapter_Template&amp;diff=248369</id>
		<title>Template:Chapter Template</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:Chapter_Template&amp;diff=248369"/>
				<updated>2019-03-05T16:19:11Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: More testing templates&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== OWASP {{{chaptername}}} ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the {{{chaptername}}} chapter homepage. {{{extra}}} &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{#if:{{{meetupurl|}}}|&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
[{{{meetupurl}}} https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [{{{meetupurl}}} {{{chaptername}}} Schedule of Events]&lt;br /&gt;
| &amp;lt;noinclude&amp;gt; [{{{meetupurl}}} https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [{{{meetupurl}}} {{{chaptername}}} Schedule of Events] &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
BEFORE IF&lt;br /&gt;
{{#if:{{{meetupgroup|}}}|&lt;br /&gt;
{{#tag:html|&lt;br /&gt;
Insert here&lt;br /&gt;
&amp;lt;meetup group=&amp;quot;{{{meetupgroup}}}&amp;quot; /&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
|&amp;lt;noinclude&amp;gt;&amp;lt;meetup group=&amp;quot;{{{meetupgroup}}}&amp;quot; /&amp;gt; &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
== Participation == &lt;br /&gt;
OWASP Foundation ([https://docs.google.com/a/owasp.org/presentation/d/10wi1EWFCPZwCpkB6qZaBNN8mR2XfQs8sLxcj9SCsP6c/edit?usp=sharing Overview Slides]) is a professional association of [[Membership | global members]] and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the [[Chapter_Leader_Handbook]].  As a [[About_OWASP | 501(c)(3)]] non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button.  To be a &amp;lt;b&amp;gt;SPEAKER&amp;lt;/b&amp;gt; at ANY OWASP Chapter in the world simply review the [[Speaker_Agreement | speaker agreement]] and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.&lt;br /&gt;
&lt;br /&gt;
== Sponsorship/Membership  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Btn_donate_SM.gif|link=https://www.owasp.org/index.php/Local_Chapter_Supporter]] to this chapter or become a local chapter supporter.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Or consider the value of [[Membership | Individual, Corporate, or Academic Supporter membership]]. Ready to become a member? [[Image:Join_Now_BlueIcon.JPG|75px|link=https://www.owasp.org/index.php/Membership]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:{{{region}}}]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:Chapter_Template&amp;diff=248368</id>
		<title>Template:Chapter Template</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:Chapter_Template&amp;diff=248368"/>
				<updated>2019-03-05T16:18:29Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Testing template changes&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== OWASP {{{chaptername}}} ==&lt;br /&gt;
&lt;br /&gt;
Welcome to the {{{chaptername}}} chapter homepage. {{{extra}}} &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{#if:{{{meetupurl|}}}|&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
[{{{meetupurl}}} https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [{{{meetupurl}}} {{{chaptername}}} Schedule of Events]&lt;br /&gt;
| &amp;lt;noinclude&amp;gt; [{{{meetupurl}}} https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [{{{meetupurl}}} {{{chaptername}}} Schedule of Events] &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{#if:{{{meetupgroup|}}}|&lt;br /&gt;
{{#tag:html|&lt;br /&gt;
Insert here&lt;br /&gt;
&amp;lt;meetup group=&amp;quot;{{{meetupgroup}}}&amp;quot; /&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
|&amp;lt;noinclude&amp;gt;&amp;lt;meetup group=&amp;quot;{{{meetupgroup}}}&amp;quot; /&amp;gt; &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
== Participation == &lt;br /&gt;
OWASP Foundation ([https://docs.google.com/a/owasp.org/presentation/d/10wi1EWFCPZwCpkB6qZaBNN8mR2XfQs8sLxcj9SCsP6c/edit?usp=sharing Overview Slides]) is a professional association of [[Membership | global members]] and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the [[Chapter_Leader_Handbook]].  As a [[About_OWASP | 501(c)(3)]] non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button.  To be a &amp;lt;b&amp;gt;SPEAKER&amp;lt;/b&amp;gt; at ANY OWASP Chapter in the world simply review the [[Speaker_Agreement | speaker agreement]] and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.&lt;br /&gt;
&lt;br /&gt;
== Sponsorship/Membership  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Btn_donate_SM.gif|link=https://www.owasp.org/index.php/Local_Chapter_Supporter]] to this chapter or become a local chapter supporter.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Or consider the value of [[Membership | Individual, Corporate, or Academic Supporter membership]]. Ready to become a member? [[Image:Join_Now_BlueIcon.JPG|75px|link=https://www.owasp.org/index.php/Membership]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:{{{region}}}]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248191</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248191"/>
				<updated>2019-03-02T03:22:57Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Update some status info and comms&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''DONE''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-22 - [Matt] Remove lists.owasp.org MX records in DNS and update the wiki main menu to point at Google Groups instead of lists.owasp.org&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD''' &lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
* Google Groups used to assist communication during the migration&lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/mailman-list-owners Google Group of all Mailman list owners] - mailman-list-owners@owasp.org &lt;br /&gt;
** [https://groups.google.com/a/owasp.org/forum/?hl=en#!forum/retiring-mailman Google Group used to join the remaining lists] and post announcements to them - retiring-mailman@owasp.org (private list) &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
(Q) My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
(A) You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248152</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248152"/>
				<updated>2019-03-01T19:23:42Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Linked the form to migrate to Google Groups&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''In Process''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD''' &lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
(Q) My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
(A) You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the [https://goo.gl/forms/e0C1r9SfXizp83AM2 form to request early migration to Google Groups], we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248151</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248151"/>
				<updated>2019-03-01T19:23:09Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Started on FAQ&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''In Process''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD''' &lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
(Q) My list is no longer showing on mailman and/or emails to it are bouncing back with something like:&lt;br /&gt;
&lt;br /&gt;
 reason: 550 permanent failure for one or more recipients (OLD_LIST_NAME@lists.owasp.org:550 5.1.1 &amp;lt;OLD_LIST_NAME@lists.owasp.org&amp;gt;... User unknown&lt;br /&gt;
&lt;br /&gt;
(A) You list didn't have any email traffic for over 1 calendar year and was archived.  If you fill out the form to request early migration to Google Groups, we can re-create that list in Google Groups for you.&lt;br /&gt;
&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248150</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248150"/>
				<updated>2019-03-01T18:58:36Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Updated link to spreadsheet of mail lists and last post dates&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://drive.google.com/open?id=1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''In Process''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD''' &lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248149</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248149"/>
				<updated>2019-03-01T18:57:07Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Updated link to early migration request form&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/e0C1r9SfXizp83AM2 Form to request early migration to Google Groups] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''In Process''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD''' &lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248147</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=248147"/>
				<updated>2019-03-01T18:44:41Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Combined the Timeline and Milestones per request from Mike&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/mmYMglHD9EXrEznm1 Form to request early migration to Google Groups] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* 2019-01-29 - [Matt] Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* 2019-02-12 - [Matt] Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* 2019-02-26 - [Matt] Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* 2019-02-26 - [Matt] Socialize this plan on the leaders list - '''DONE''' &lt;br /&gt;
* 2019-02-28 - [Matt] Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* 2019-03-01 - [Matt] Send email to all list owners about his plan and an overview of the migration effort - '''In Process''' &lt;br /&gt;
* 2019-03-06 - [Matt, Harold, Dawn] Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters/projects that become active again - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Create Google Groups for all remaining mail lists - '''In Process''' &lt;br /&gt;
* 2019-03-08 - [Matt] Send out a reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-15 - [Matt] Send out 2nd reminder to all remaining lists about the transition&lt;br /&gt;
* 2019-03-22 - [Matt] Final notification email sent to all remaining lists&lt;br /&gt;
* 2019-03-22 - [Matt] Cut over to Google Groups - inbound email to lists.owasp.org set to bounce&lt;br /&gt;
* 2019-03-24 - [Matt] Turn off Mailman on lists.owasp.org - inbound email to lists.owasp.org will fail&lt;br /&gt;
* 2019-03-27 - [Matt] Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* 2019-03-29 - [Matt] Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* 2019-04-01 - [Harold, Matt] Close discourse.owasp.org account - '''exact date TBD''' &lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:LatamTour_2015_Training_Instructor_Agreement.pdf&amp;diff=248104</id>
		<title>File:LatamTour 2015 Training Instructor Agreement.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:LatamTour_2015_Training_Instructor_Agreement.pdf&amp;diff=248104"/>
				<updated>2019-02-28T22:40:27Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Mtesauro uploaded a new version of File:LatamTour 2015 Training Instructor Agreement.pdf&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.AppSecEU2013.pdf&amp;diff=248103</id>
		<title>File:Training Instructor Agreement.AppSecEU2013.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.AppSecEU2013.pdf&amp;diff=248103"/>
				<updated>2019-02-28T22:38:59Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Mtesauro uploaded a new version of File:Training Instructor Agreement.AppSecEU2013.pdf&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.AppSecEU2013.pdf&amp;diff=248102</id>
		<title>File:Training Instructor Agreement.AppSecEU2013.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.AppSecEU2013.pdf&amp;diff=248102"/>
				<updated>2019-02-28T22:38:16Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Mtesauro uploaded a new version of File:Training Instructor Agreement.AppSecEU2013.pdf&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.doc&amp;diff=248101</id>
		<title>File:Training Instructor Agreement.doc</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.doc&amp;diff=248101"/>
				<updated>2019-02-28T22:37:09Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Mtesauro uploaded a new version of File:Training Instructor Agreement.doc&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.pdf&amp;diff=248100</id>
		<title>File:Training Instructor Agreement.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Training_Instructor_Agreement.pdf&amp;diff=248100"/>
				<updated>2019-02-28T22:35:25Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Training Instructor agreement as of 2019-02-28&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Training Instructor agreement as of 2019-02-28&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects&amp;diff=248099</id>
		<title>Staff-Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects&amp;diff=248099"/>
				<updated>2019-02-28T22:14:44Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: /* Unprioritized Projects */ Added link for DefCon&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Themes for 2019: Simplify, Unify, Grow ==&lt;br /&gt;
# Simplify: Reduce the complexity of advancing the mission of the Foundation&lt;br /&gt;
# Unify: Create and nurture a shared culture of success within the community&lt;br /&gt;
# Grow: Increase reputation of Foundation that will grow involvement and influence&lt;br /&gt;
&lt;br /&gt;
== Staff Projects ==&lt;br /&gt;
&lt;br /&gt;
Staff Project are work product primarily done by staff that require either 40+hrs of staff time or have a financial obligation of more than $10,000. '''Active''' Staff Projects have written plans that include measurable goals, milestones, and should be linked below.  '''Prioritized''' Staff Projects are in the formation stages and are listed in rank importance. '''Unprioritized''' Staff Projects are items that lack a plan and are in a &amp;quot;bucket list&amp;quot; until they get prioritized with a project plan. ''Note this project list is not the exhaustive list of staff daily work product. These are the key projects above everyday work that is purposefully planned to deliver on 2019 Goals.''&lt;br /&gt;
Generally the process we will use to implement our plans are: &lt;br /&gt;
&lt;br /&gt;
 ''' Concept &amp;gt;&amp;gt; Document &amp;gt;&amp;gt; Socialize &amp;gt;&amp;gt; Iterate &amp;gt;&amp;gt; [Approval if needed] &amp;gt;&amp;gt; Plan &amp;gt;&amp;gt; Implement &amp;gt;&amp;gt; Report &amp;gt;&amp;gt; Revisit'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Active Projects  ===&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/2019-Operating-Plan Operating Plan]&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/201905-Global-AppSec-Tel-Aviv Global AppSec Tel Aviv], 26-30 May&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/201909-Global-AppSec-DC Global AppSec DC], September 8-13&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/20191101-AppSecDay-Melbourne AppSec Days Melbourne], 1 November&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/201902-Trademarks Trademark]&lt;br /&gt;
* PayPal Cleanup [Matt]&lt;br /&gt;
* Signatory/Password Audit [Matt]&lt;br /&gt;
* [[Staff-Projects/Mailman-EOL|Mailman EOL]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/2019-Insurance Insurance Audit]&lt;br /&gt;
* [https://www.owasp.org/index.php/Corporate_Sponsorship_Proposal_201902 Corporate Membership Benefits] [Kelly]&lt;br /&gt;
&lt;br /&gt;
=== Prioritized Projects ===&lt;br /&gt;
# Conference Budget/Itinerary/Project Template&lt;br /&gt;
# [https://www.owasp.org/index.php/Staff-Projects/2019-Website-Launch Website Relaunch]&lt;br /&gt;
# Leader Agreement (Project, Chapter, Event)&lt;br /&gt;
# JIRA Retool [Harold] [https://owaspstaff.slack.com/files/U9N7HF4V9/FGHNVMGUW/jira_workflow.jpg whiteboard]&lt;br /&gt;
## Expand AP with steps and Virtual Close at bank statement&lt;br /&gt;
## Contact Us process&lt;br /&gt;
## Chapter Formation process&lt;br /&gt;
# Technology Plan [Matt] [https://owaspstaff.slack.com/files/U2E711RC2/FGD9WUAKW/data-islands.png whiteboard]&lt;br /&gt;
# Forms Tool Migration [Harold]&lt;br /&gt;
## Accept agreements/ replace Docusign(?)&lt;br /&gt;
## Free-form Payments&lt;br /&gt;
## Donations&lt;br /&gt;
## Join as Member&lt;br /&gt;
### First time&lt;br /&gt;
### Recurring&lt;br /&gt;
### Renewals&lt;br /&gt;
## New Event Registration&lt;br /&gt;
# Membership Benefits [Lisa] [https://owaspstaff.slack.com/files/U9N7HF4V9/FGC6TUGJW/membership_whiteboard.jpg whiteboard]&lt;br /&gt;
# Chapter Onboarding [Dawn]&lt;br /&gt;
# [[Staff-Projects/CoMarketing Plan|CoMarketing Plan]] [Lisa] [https://owaspstaff.slack.com/files/U9N7HF4V9/FGEKW4TML/marketing_whiteboard.jpg whiteboard]&lt;br /&gt;
# 2020 Event Plan [Mike] [https://owaspstaff.slack.com/files/U2ERY9RRC/FGH0RKR0W/image_from_ios.jpg whiteboard]&lt;br /&gt;
# Defcon Plan [Lisa]&lt;br /&gt;
&lt;br /&gt;
=== Unprioritized Projects ===&lt;br /&gt;
* Leader Agreements&lt;br /&gt;
* SalesForce New Instance &amp;gt; Migration&lt;br /&gt;
* SalesForce Sales Pipeline&lt;br /&gt;
* Invoice Workflow (SalesForce &amp;amp; JIRA)&lt;br /&gt;
* Help Wanted Project Service (see https://helpwanted.apache.org/ for concept)&lt;br /&gt;
* Cloud Computing Resources Decision (Azure, GPC, AWS, DigitalOcean, other?)&lt;br /&gt;
* [[Staff-Projects/DefCon 27 Event|DefCon 27 Event]]&lt;br /&gt;
&lt;br /&gt;
=== Completed Projects ===&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/201902-staff-summit Staff Summit]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''[https://www.owasp.org/index.php/Staff-Projects/Template BLANK TEMPLATE]'''&lt;br /&gt;
&lt;br /&gt;
== Strategies ==&lt;br /&gt;
* Create and share best practices and tools for InfoSec community&lt;br /&gt;
* Increase connectedness and engagement within the community.&lt;br /&gt;
* Position the Foundation for growth.&lt;br /&gt;
* Professionalize administrative and operational tasks and practices.&lt;br /&gt;
* Redesign financial model and membership benefits.&lt;br /&gt;
&lt;br /&gt;
== Foundation Goals for 2019 - DRAFT ==&lt;br /&gt;
&lt;br /&gt;
* Optimize business operations to overachieve financial and membership targets.&lt;br /&gt;
* Manage three profitable global conferences, planning four in 2020.&lt;br /&gt;
* Successfully relaunch website and community toolset by June 1.&lt;br /&gt;
* Increase relevance and reputation of OWASP measured by 5% increase in web traffic.&lt;br /&gt;
* Improve satisfaction with OWASP by survey measured 5% increase.&lt;br /&gt;
* Increase membership by 20% and Corporate Sponsorship revenue by 25%.&lt;br /&gt;
&lt;br /&gt;
''Vision: Global and open resource for software security''&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/CoMarketing_Plan&amp;diff=248098</id>
		<title>Staff-Projects/CoMarketing Plan</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/CoMarketing_Plan&amp;diff=248098"/>
				<updated>2019-02-28T22:11:58Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Initial Page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Each project will have a 2-3 paragraph overview narrative. Keep to the key top points about the project. Visitors should be able to read this short narrative and have a good understanding of the project without having to scroll the entire document.&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
&lt;br /&gt;
Use this section for important links for projects/events that visitors will need.&lt;br /&gt;
For instance, if this is an event, links to CFT, CPT and registration is handy&lt;br /&gt;
If there is a microsite, that would be good to link to as well &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Include top-level goals of the project in an ordered list&lt;br /&gt;
Give thought to the ordering of goals. Revenue, attendance, launch date&lt;br /&gt;
Make sure goals are measurable from undisputed source&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* In an unordered list (billeted) list major milestones in chronological order&lt;br /&gt;
* Use the syntax of 2019-01-19, Milestone name [Name of Owner]&lt;br /&gt;
* When milestones are completed, mark them as such with ??&lt;br /&gt;
* A milestone isn’t everyone’s to-do list, it is the high level tasks of the project&lt;br /&gt;
* If you have more than 20 milestones, you’re being too granular&lt;br /&gt;
&lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* unordered list of each leader and a hyperlink to their email address.&lt;br /&gt;
&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects&amp;diff=248097</id>
		<title>Staff-Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects&amp;diff=248097"/>
				<updated>2019-02-28T22:11:00Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Added link to co-marketing plan&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Themes for 2019: Simplify, Unify, Grow ==&lt;br /&gt;
# Simplify: Reduce the complexity of advancing the mission of the Foundation&lt;br /&gt;
# Unify: Create and nurture a shared culture of success within the community&lt;br /&gt;
# Grow: Increase reputation of Foundation that will grow involvement and influence&lt;br /&gt;
&lt;br /&gt;
== Staff Projects ==&lt;br /&gt;
&lt;br /&gt;
Staff Project are work product primarily done by staff that require either 40+hrs of staff time or have a financial obligation of more than $10,000. '''Active''' Staff Projects have written plans that include measurable goals, milestones, and should be linked below.  '''Prioritized''' Staff Projects are in the formation stages and are listed in rank importance. '''Unprioritized''' Staff Projects are items that lack a plan and are in a &amp;quot;bucket list&amp;quot; until they get prioritized with a project plan. ''Note this project list is not the exhaustive list of staff daily work product. These are the key projects above everyday work that is purposefully planned to deliver on 2019 Goals.''&lt;br /&gt;
Generally the process we will use to implement our plans are: &lt;br /&gt;
&lt;br /&gt;
 ''' Concept &amp;gt;&amp;gt; Document &amp;gt;&amp;gt; Socialize &amp;gt;&amp;gt; Iterate &amp;gt;&amp;gt; [Approval if needed] &amp;gt;&amp;gt; Plan &amp;gt;&amp;gt; Implement &amp;gt;&amp;gt; Report &amp;gt;&amp;gt; Revisit'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Active Projects  ===&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/2019-Operating-Plan Operating Plan]&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/201905-Global-AppSec-Tel-Aviv Global AppSec Tel Aviv], 26-30 May&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/201909-Global-AppSec-DC Global AppSec DC], September 8-13&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/20191101-AppSecDay-Melbourne AppSec Days Melbourne], 1 November&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/201902-Trademarks Trademark]&lt;br /&gt;
* PayPal Cleanup [Matt]&lt;br /&gt;
* Signatory/Password Audit [Matt]&lt;br /&gt;
* [[Staff-Projects/Mailman-EOL|Mailman EOL]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/2019-Insurance Insurance Audit]&lt;br /&gt;
* [https://www.owasp.org/index.php/Corporate_Sponsorship_Proposal_201902 Corporate Membership Benefits] [Kelly]&lt;br /&gt;
&lt;br /&gt;
=== Prioritized Projects ===&lt;br /&gt;
# Conference Budget/Itinerary/Project Template&lt;br /&gt;
# [https://www.owasp.org/index.php/Staff-Projects/2019-Website-Launch Website Relaunch]&lt;br /&gt;
# Leader Agreement (Project, Chapter, Event)&lt;br /&gt;
# JIRA Retool [Harold] [https://owaspstaff.slack.com/files/U9N7HF4V9/FGHNVMGUW/jira_workflow.jpg whiteboard]&lt;br /&gt;
## Expand AP with steps and Virtual Close at bank statement&lt;br /&gt;
## Contact Us process&lt;br /&gt;
## Chapter Formation process&lt;br /&gt;
# Technology Plan [Matt] [https://owaspstaff.slack.com/files/U2E711RC2/FGD9WUAKW/data-islands.png whiteboard]&lt;br /&gt;
# Forms Tool Migration [Harold]&lt;br /&gt;
## Accept agreements/ replace Docusign(?)&lt;br /&gt;
## Free-form Payments&lt;br /&gt;
## Donations&lt;br /&gt;
## Join as Member&lt;br /&gt;
### First time&lt;br /&gt;
### Recurring&lt;br /&gt;
### Renewals&lt;br /&gt;
## New Event Registration&lt;br /&gt;
# Membership Benefits [Lisa] [https://owaspstaff.slack.com/files/U9N7HF4V9/FGC6TUGJW/membership_whiteboard.jpg whiteboard]&lt;br /&gt;
# Chapter Onboarding [Dawn]&lt;br /&gt;
# [[Staff-Projects/CoMarketing Plan|CoMarketing Plan]] [Lisa] [https://owaspstaff.slack.com/files/U9N7HF4V9/FGEKW4TML/marketing_whiteboard.jpg whiteboard]&lt;br /&gt;
# 2020 Event Plan [Mike] [https://owaspstaff.slack.com/files/U2ERY9RRC/FGH0RKR0W/image_from_ios.jpg whiteboard]&lt;br /&gt;
# Defcon Plan [Lisa]&lt;br /&gt;
&lt;br /&gt;
=== Unprioritized Projects ===&lt;br /&gt;
* Leader Agreements&lt;br /&gt;
* SalesForce New Instance &amp;gt; Migration&lt;br /&gt;
* SalesForce Sales Pipeline&lt;br /&gt;
* Invoice Workflow (SalesForce &amp;amp; JIRA)&lt;br /&gt;
* Help Wanted Project Service (see https://helpwanted.apache.org/ for concept)&lt;br /&gt;
* Cloud Computing Resources Decision (Azure, GPC, AWS, DigitalOcean, other?)&lt;br /&gt;
&lt;br /&gt;
=== Completed Projects ===&lt;br /&gt;
* [https://www.owasp.org/index.php/Staff-Projects/201902-staff-summit Staff Summit]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''[https://www.owasp.org/index.php/Staff-Projects/Template BLANK TEMPLATE]'''&lt;br /&gt;
&lt;br /&gt;
== Strategies ==&lt;br /&gt;
* Create and share best practices and tools for InfoSec community&lt;br /&gt;
* Increase connectedness and engagement within the community.&lt;br /&gt;
* Position the Foundation for growth.&lt;br /&gt;
* Professionalize administrative and operational tasks and practices.&lt;br /&gt;
* Redesign financial model and membership benefits.&lt;br /&gt;
&lt;br /&gt;
== Foundation Goals for 2019 - DRAFT ==&lt;br /&gt;
&lt;br /&gt;
* Optimize business operations to overachieve financial and membership targets.&lt;br /&gt;
* Manage three profitable global conferences, planning four in 2020.&lt;br /&gt;
* Successfully relaunch website and community toolset by June 1.&lt;br /&gt;
* Increase relevance and reputation of OWASP measured by 5% increase in web traffic.&lt;br /&gt;
* Improve satisfaction with OWASP by survey measured 5% increase.&lt;br /&gt;
* Increase membership by 20% and Corporate Sponsorship revenue by 25%.&lt;br /&gt;
&lt;br /&gt;
''Vision: Global and open resource for software security''&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Schwermie&amp;diff=248085</id>
		<title>User:Schwermie</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Schwermie&amp;diff=248085"/>
				<updated>2019-02-28T18:55:42Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Creating user page for new user.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;10+ years of experience in Information Security with a special interest in Network and Web security. &lt;br /&gt;
Besides the technical side, Marco also has an interest in IT Auditing with a focus on IT Security.&lt;br /&gt;
Currently holds the following certifications: CISSP, CISA, OSWP, CEH, ECSA, LPT&lt;br /&gt;
&lt;br /&gt;
LinkedIn: https://www.linkedin.com/in/MarcoHermans/&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Schwermie&amp;diff=248086</id>
		<title>User talk:Schwermie</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Schwermie&amp;diff=248086"/>
				<updated>2019-02-28T18:55:42Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Welcome!&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Welcome to ''OWASP''!'''&lt;br /&gt;
We hope you will contribute much and well.&lt;br /&gt;
You will probably want to read the [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents help pages].&lt;br /&gt;
Again, welcome and have fun! [[User:Mtesauro|Mtesauro]] ([[User talk:Mtesauro|talk]]) 12:55, 28 February 2019 (CST)&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=247926</id>
		<title>Staff-Projects/Mailman-EOL</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Mailman-EOL&amp;diff=247926"/>
				<updated>2019-02-27T01:24:02Z</updated>
		
		<summary type="html">&lt;p&gt;Mtesauro: Updated Milestones to mark one as DONE&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community.  While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups.  The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman.  The reasons for this migration were stated at length on the leaders list [https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html here] but are summarized below in no particular order:&lt;br /&gt;
* Mailman is old software and doesn't follow current security best practices. &lt;br /&gt;
** It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted [[About Mailman at OWASP|here]].&lt;br /&gt;
** It has a single shared password for overall site administration for the staff to use to oversee the installation&lt;br /&gt;
** If a mail list has 2+ list owners, they must share a password for managing the list&lt;br /&gt;
* Mailman has an extremely dated UI/web interface.  This makes OWASP appear out of date/out of touch to new, potential community members&lt;br /&gt;
* Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Core_Purpose core purpose].&lt;br /&gt;
* The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019. &lt;br /&gt;
* Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base (aka opt-in).&lt;br /&gt;
* Mailman does not get the use it formerly had ~80% of the lists are inactive/dormant/abandoned - some numbers:&lt;br /&gt;
** 875 - total lists prior to initial review/clean-up&lt;br /&gt;
** 181 - lists of the 875 which had at least 1 email to them in the last calendar year&lt;br /&gt;
** 693 - lists with no email posts in over 1 year&lt;br /&gt;
In 2017, the current community manager (Tiffany Long) suggested a migration from Mailman to Discourse.  This was the original direction of efforts until it was reconsidered at the 2019 Staff Summit, a face to face meeting to plan out 2019. Instead, Mailman will be migrated to Google Groups.  The following reasons were crucial in the choice of Google Groups&lt;br /&gt;
* Functionally equivalent to Mailman as a 'mail list'&lt;br /&gt;
* Already part of the G-Suite donation from Google&lt;br /&gt;
* Can be run for $0 cost and with 0 administration of the underlying infrastructure &lt;br /&gt;
* Includes Anti-SPAM filtering that is already part of our G-Suite email infrastructure&lt;br /&gt;
* Inbound and outbound email handled by Google email infrastructure - no need to run a MTA (mail server)&lt;br /&gt;
* Mobile-friendly, modern UI and significantly better TLS configuration for web interactions&lt;br /&gt;
* Has robust admin and permissions available via G-Suite Admin tool&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo Mailman legacy install] &lt;br /&gt;
* [https://lists.owasp.org/pipermail/stats/ Mailman stats] - created via monthly cron job / run manually &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing Google Sheet of mail lists and their most recent post] (publicly available) &lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1_Fn1t_-tcw3duCC0QMhKXEMqdKcHvqsi21e7LuiOphM/edit?usp=sharing Google Sheet of mail lists, most recent post and owner(s) of the list] (only available to Foundation Staff since it contains email addresses of list owners) &lt;br /&gt;
* [https://support.google.com/groups/?hl=en#topic=9216 Google Groups Help pages] &lt;br /&gt;
* [https://goo.gl/forms/mmYMglHD9EXrEznm1 Form to request early migration to Google Groups] &lt;br /&gt;
&lt;br /&gt;
= Goals =&lt;br /&gt;
&lt;br /&gt;
Overall Goal: Migration of any active list from lists.owasp.org to Google Groups by March 24, 2019.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
* Active is defined as a list which as received at least 1 non-SPAM email in the last 12 months as of 2019-01-29 when initial activity reporting was run&lt;br /&gt;
** Mail lists for inactive projects and chapters will not be migrated&lt;br /&gt;
** Archives on lists.owasp.org will be migrated to a static host under the same URL scheme as before&lt;br /&gt;
* '''High-level Workflow'''&lt;br /&gt;
** Announce plan&lt;br /&gt;
** Email notifications of cut-over date&lt;br /&gt;
*** Instruct list members to join the new list but continue to post to lists until 2019-03-22&lt;br /&gt;
*** 3 notifications will go out to all lists&lt;br /&gt;
** Setup new Google Groups for migrating lists, ordered by most recent post as of this [https://docs.google.com/spreadsheets/d/1VDIeT0Wfrt2_v5hY6by984H5fya56xe7E_rZDird8qg/edit?usp=sharing spreadsheet] &lt;br /&gt;
** If requested, any list can be migrated prior to the cut-over date by completing [https://goo.gl/forms/mmYMglHD9EXrEznm1 this form].&lt;br /&gt;
** Hard cut-over to Google Groups on 2019-03-22&lt;br /&gt;
** 2019-03-24 - Service from Barracuda is disabled &amp;amp; inbound email to lists.owasp.org will fail.&lt;br /&gt;
* '''Timeline'''&lt;br /&gt;
** 2019-02-26 - Create this plan&lt;br /&gt;
** 2019-02-26 - Socialize this plan on the leaders list&lt;br /&gt;
** 2019-02-28 - Complete review of remaining mail lists&lt;br /&gt;
** 2019-03-01 - Send email to all list owners about his plan and an overview of the migration effort&lt;br /&gt;
** 2019-03-06 - Complete review of Project lists with Harold &amp;amp; Chapter lists with Dawn to remove inactive projects/chapters from the migration effort&lt;br /&gt;
** 2019-03-08 - Send out a reminder to all remaining lists of the transition &lt;br /&gt;
** 2019-03-15 - Send out 2nd reminder to all remaining lists on the transition&lt;br /&gt;
** 2019-03-22 - Final notification email sent to all remaining lists&lt;br /&gt;
** 2019-03-22 - Inbound email to lists.owasp.org set to bounce&lt;br /&gt;
** 2019-03-24 - Inbound email to lists.owasp.org will fail&lt;br /&gt;
** 2019-03-25 - Retire lists.owasp.org server at Rackspace and migrate static archives to new host.  Close discourse.owasp.org account.&lt;br /&gt;
&lt;br /&gt;
= Milestones =&lt;br /&gt;
&lt;br /&gt;
* Review the inventory of lists to determine which are inactive - '''DONE ('''total lists = 875)&lt;br /&gt;
* Use the data above to retire any inactive list - '''DONE''' (total lists = 181, 693 inactive lists removed)&lt;br /&gt;
* Complete Staff Project Plan - '''DONE'''&lt;br /&gt;
* Review remaining list for any that can be retired due to ownership (e.g. owned by staff and unused) or  mail in the last calendar year is SPAM - '''DONE''' (total lists = 139)&lt;br /&gt;
* Review remaining lists and remove any projects or chapters which are inactive.  A new Google Group can be created for chapters that become active again - '''In Process''' &lt;br /&gt;
* Send out initial communication to all lists which will be migrated,&lt;br /&gt;
* Create Google Groups for all remaining mail lists&lt;br /&gt;
* Send out 2nd communication to all lists which will be migrated&lt;br /&gt;
* Send out final notice to all lists&lt;br /&gt;
* Cut over to Google Groups&lt;br /&gt;
* Migrate static archives from lists.owasp.org to a new host&lt;br /&gt;
* Retire lists.owasp.org server at Rackspace&lt;br /&gt;
* Close discourse.owasp.org account&lt;br /&gt;
&lt;br /&gt;
= Communications =&lt;br /&gt;
The following lists communications where the retirement of Mailman was discussed publicly&lt;br /&gt;
* Posts to Leaders lists (prior to creation of staff projects template)&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019608.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-January/019613.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019663.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019675.html&lt;br /&gt;
** https://lists.owasp.org/pipermail/owasp-leaders/2019-February/019700.html&lt;br /&gt;
* Posts to the Blog and Connector&lt;br /&gt;
** https://owasp.blogspot.com/2018/12/december-2018-connector.html &amp;amp; [https://us17.campaign-archive.com/?u=a8012c9e2e384bf8ea8d7deb7&amp;amp;id=31f131180e December Connector]&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-our-instance-of-mailman.html&lt;br /&gt;
** https://owasp.blogspot.com/2019/02/owasp-community-and-chapter-reminders.html&lt;br /&gt;
** [https://mailchi.mp/90cc34fc2cdd/0rleggjjx3-222491 February Connector] &lt;br /&gt;
* Leaders Meetings&lt;br /&gt;
** AppSec EU 2018 (London) Leaders Meeting - [https://www.youtube.com/watch?v=vy6R0SbJrS8&amp;amp;list=PLpr-xdpM8wG9yT6HD6YeCbf6wymhAAqRb&amp;amp;index=6&amp;amp;t=0s recording] &lt;br /&gt;
** AppSec US 2018 (San Jose) Leaders Meeting - recordings - [https://www.youtube.com/watch?v=sGEfVNuFIZk&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=6 part 1] &amp;amp; [https://www.youtube.com/watch?v=Wxqtiwzz90c&amp;amp;t=0s&amp;amp;list=PLpr-xdpM8wG-ma2GOBmdpGGfnVPVwFFQd&amp;amp;index=7 part 2] &lt;br /&gt;
* Board Meetings&lt;br /&gt;
** [[October 11, 2016|October 2016]] - Migration from Mailman raised by Tiffany in her [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit Community Manager Report] &lt;br /&gt;
= Leadership =&lt;br /&gt;
&lt;br /&gt;
* This is a Foundation staff run initiative including&lt;br /&gt;
** Matt Tesauro - primary point of contact&lt;br /&gt;
** Harold Blankenship - staff representation for project mail lists&lt;br /&gt;
** Dawn Aitken - staff representation for chapter mail lists&lt;br /&gt;
[[Category:Staff Projects]]&lt;/div&gt;</summary>
		<author><name>Mtesauro</name></author>	</entry>

	</feed>