<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Nilay+Sangani</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Nilay+Sangani"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Nilay_Sangani"/>
		<updated>2026-04-25T14:03:45Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Security_Controls_in_Web_Application_Development_Lifecycle&amp;diff=185777</id>
		<title>OWASP Security Controls in Web Application Development Lifecycle</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Security_Controls_in_Web_Application_Development_Lifecycle&amp;diff=185777"/>
				<updated>2014-11-22T16:52:43Z</updated>
		
		<summary type="html">&lt;p&gt;Nilay Sangani: /* Road Map and Getting Involved */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The OWASP Security Controls in Web Application Development Lifecycle==&lt;br /&gt;
&lt;br /&gt;
Security needs to be embedded right from the initials to release a secure end deliverable. &lt;br /&gt;
This project aims at delivering security controls right from the requirements,design,development,testing,release,maintenance and decommission.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Vision of this project is to demonstrate the implementation of integrating security controls in any web development lifecycle project.Every functional deliverable must be delivered in a fully secure fashion. If Security is injected right from the initials ( when the business needs arises ), cost to address the issues identified in the VAPT level will be very minimal or none. Developers,Application Security Analysts, Technical Project Managers, Pen Testers will also be able to pick up security libraries / checks to use them in their own applications and projects.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
GNU GPL v3 License&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Security Controls in Web Application Development Lifecycle Project? ==&lt;br /&gt;
&lt;br /&gt;
Project's tangible deliverable will be downloadable secure libraries,checklists,documents,guidelines in releasing each and every stage of web application development lifecycle in a secure manner.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:nilav.sangani@owasp.org Nilav Sangani]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
== Openhub ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
[https://lists.owasp.org/mailman/listinfo/owasp_security_controls_in_web_application_development_lifecycle Mailing List]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [mailto:nilay.sangani@owasp.org Nilay Sangani]&lt;br /&gt;
&lt;br /&gt;
= Road Map =&lt;br /&gt;
&lt;br /&gt;
Aim of this project:&lt;br /&gt;
To integrate security in application development lifecycle. At each and every stage of an application being developed, we will have security pushed into the process. We all know that there is a direct connection from the web application to the database. Security needs to be right at the application development end. Having security controls right from the start will ensure the application is developed in a secure fashion and methodology.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Integrating security requirements at every stage of a web application development will be imparted in this project ==&lt;br /&gt;
===1)Business Requirements===&lt;br /&gt;
===2)Software Requirements Specifications===&lt;br /&gt;
===3)Software Design Specifications ===&lt;br /&gt;
====a)high Level Design==== &lt;br /&gt;
====b) Low Level Design==== &lt;br /&gt;
===4)Software Implementation=== &lt;br /&gt;
===5) Software Quality Testing=== &lt;br /&gt;
===6)Software Release=== &lt;br /&gt;
===7)Software Post Release===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Nilay Sangani</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Security_Controls_in_Web_Application_Development_Lifecycle&amp;diff=185776</id>
		<title>OWASP Security Controls in Web Application Development Lifecycle</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Security_Controls_in_Web_Application_Development_Lifecycle&amp;diff=185776"/>
				<updated>2014-11-22T16:49:02Z</updated>
		
		<summary type="html">&lt;p&gt;Nilay Sangani: /* Security requirements must be integrated at each and every phase of a Web Application project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The OWASP Security Controls in Web Application Development Lifecycle==&lt;br /&gt;
&lt;br /&gt;
Security needs to be embedded right from the initials to release a secure end deliverable. &lt;br /&gt;
This project aims at delivering security controls right from the requirements,design,development,testing,release,maintenance and decommission.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Vision of this project is to demonstrate the implementation of integrating security controls in any web development lifecycle project.Every functional deliverable must be delivered in a fully secure fashion. If Security is injected right from the initials ( when the business needs arises ), cost to address the issues identified in the VAPT level will be very minimal or none. Developers,Application Security Analysts, Technical Project Managers, Pen Testers will also be able to pick up security libraries / checks to use them in their own applications and projects.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
GNU GPL v3 License&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Security Controls in Web Application Development Lifecycle Project? ==&lt;br /&gt;
&lt;br /&gt;
Project's tangible deliverable will be downloadable secure libraries,checklists,documents,guidelines in releasing each and every stage of web application development lifecycle in a secure manner.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:nilav.sangani@owasp.org Nilav Sangani]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
== Openhub ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
[https://lists.owasp.org/mailman/listinfo/owasp_security_controls_in_web_application_development_lifecycle Mailing List]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [mailto:nilay.sangani@owasp.org Nilay Sangani]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
Aim of this project:&lt;br /&gt;
To integrate security in application development lifecycle. At each and every stage of an application being developed, we will have security pushed into the process. We all know that there is a direct connection from the web application to the database. Security needs to be right at the application development end. Having security controls right from the start will ensure the application is developed in a secure fashion and methodology.&lt;br /&gt;
&lt;br /&gt;
== Security requirements must be integrated at each and every phase of a Web Application project ==&lt;br /&gt;
===1)Business Requirements===&lt;br /&gt;
===2)Software Requirements Specifications===&lt;br /&gt;
===3)Software Design Specifications ===&lt;br /&gt;
====a)high Level Design==== &lt;br /&gt;
====b) Low Level Design==== &lt;br /&gt;
===4)Software Implementation=== &lt;br /&gt;
===5) Software Quality Testing=== &lt;br /&gt;
===6)Software Release=== &lt;br /&gt;
===7)Software Post Release===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Nilay Sangani</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Security_Controls_in_Web_Application_Development_Lifecycle&amp;diff=185775</id>
		<title>OWASP Security Controls in Web Application Development Lifecycle</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Security_Controls_in_Web_Application_Development_Lifecycle&amp;diff=185775"/>
				<updated>2014-11-22T16:45:36Z</updated>
		
		<summary type="html">&lt;p&gt;Nilay Sangani: /* Road Map and Getting Involved */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The OWASP Security Controls in Web Application Development Lifecycle==&lt;br /&gt;
&lt;br /&gt;
Security needs to be embedded right from the initials to release a secure end deliverable. &lt;br /&gt;
This project aims at delivering security controls right from the requirements,design,development,testing,release,maintenance and decommission.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Vision of this project is to demonstrate the implementation of integrating security controls in any web development lifecycle project.Every functional deliverable must be delivered in a fully secure fashion. If Security is injected right from the initials ( when the business needs arises ), cost to address the issues identified in the VAPT level will be very minimal or none. Developers,Application Security Analysts, Technical Project Managers, Pen Testers will also be able to pick up security libraries / checks to use them in their own applications and projects.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
GNU GPL v3 License&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Security Controls in Web Application Development Lifecycle Project? ==&lt;br /&gt;
&lt;br /&gt;
Project's tangible deliverable will be downloadable secure libraries,checklists,documents,guidelines in releasing each and every stage of web application development lifecycle in a secure manner.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:nilav.sangani@owasp.org Nilav Sangani]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
== Openhub ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
[https://lists.owasp.org/mailman/listinfo/owasp_security_controls_in_web_application_development_lifecycle Mailing List]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [mailto:nilay.sangani@owasp.org Nilay Sangani]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
Aim of this project:&lt;br /&gt;
To integrate security in application development lifecycle. At each and every stage of an application being developed, we will have security pushed into the process. We all know that there is a direct connection from the web application to the database. Security needs to be right at the application development end. Having security controls right from the start will ensure the application is developed in a secure fashion and methodology.&lt;br /&gt;
&lt;br /&gt;
== Security requirements must be integrated at each and every phase of a Web Application project ==&lt;br /&gt;
1)Business Requirements&lt;br /&gt;
2)Software Requirements Specifications&lt;br /&gt;
3)Software Design Specifications : a)high Level Design b) Low Level Design 4)Software Implementation 5) Software Quality Testing 6)Software Release 7)Software Post Release&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Nilay Sangani</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Code_Kids_2015_Ideas&amp;diff=185206</id>
		<title>OWASP Code Kids 2015 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Code_Kids_2015_Ideas&amp;diff=185206"/>
				<updated>2014-11-11T17:48:55Z</updated>
		
		<summary type="html">&lt;p&gt;Nilay Sangani: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Task Categories=&lt;br /&gt;
&lt;br /&gt;
The tasks are grouped into the categories described below. '''Please make sure each task is assigned a category.'''&lt;br /&gt;
&lt;br /&gt;
'''Code:''' Tasks related to writing or refactoring code.&lt;br /&gt;
&lt;br /&gt;
'''Documentation/Training:''' Tasks related to creating/editing documents and helping others learn more&lt;br /&gt;
&lt;br /&gt;
'''Outreach/Research:''' Tasks related to community management, outreach/marketing, or studying problems and recommending solutions&lt;br /&gt;
&lt;br /&gt;
'''Quality Assurance:''' Tasks related to testing and ensuring code is of high quality&lt;br /&gt;
&lt;br /&gt;
'''User Interface:''' Tasks related to user experience research or user interface design and interaction&lt;br /&gt;
&lt;br /&gt;
== OWASP ZAP ==&lt;br /&gt;
&lt;br /&gt;
=== OWASP ZAP Task 1 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief description:'''&lt;br /&gt;
&lt;br /&gt;
Write a blogpost about CMS-scnanning techniques, this will include web-apps fingerprinting methods, vulnerability checking using on-line databases and a survey of existing tools.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Documentation &lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
A professional blogpost that will be published on OWASP website &lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Good understanding of web security basics, Knowledge on how do CMSs work and good writing skills.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Abdelhadi&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== OWASP ZAP Task 2 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief description:'''&lt;br /&gt;
&lt;br /&gt;
Rebuild the CMSscanner GUI including a progress bar that shows scanning progress and a textzone to display tried strings and paths used by the scanner in real time &lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Code/Design&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
New GUI with progress bar and displaying paths when scanning &lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Java language, GUI design.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Abdelhadi&lt;br /&gt;
&lt;br /&gt;
=== OWASP ZAP Task 3 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief description:'''&lt;br /&gt;
&lt;br /&gt;
In this task you are required to reproduce vulnerabilities in OWASP web goat using Owasp ZAP and zest scripts. The chosen challenge must be solved using ZAP and the resolution must be stored as a zest script. This task should help documenting of web goat and providing some working examples of Mozilla Zest scripts.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Code&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
Zest scripts which reproduces some of the vulnerabilities challange of Owasp WebGoat.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Comfortable in Javascript and HTML. Good understanding of Application Security and related vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Alessandro Secco&lt;br /&gt;
&lt;br /&gt;
== OWASP OWTF ==&lt;br /&gt;
&lt;br /&gt;
=== OWASP OWTF Task 1 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Task description&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Eg. Code Category&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
Describe the expected results of the task&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Comfortable in PHP, HTML and possibly Javascript. Good understanding of Application Security and related vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' XXXXXX&lt;br /&gt;
&lt;br /&gt;
== OWASP WIKI ==&lt;br /&gt;
&lt;br /&gt;
=== Task 1: Latam Tour 2015 logo ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Design a new logo for the Latam Tour 2015. The logo must resemble previous editions of the Tour and represent the Latin America region. It would be better if the new logo is based on the OWASP logo. As a reference, here is the Latam Tour 2014 Logo:&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/f/f3/OWASP_Latam_Tour_Logo_2014.png&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Design&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
Latam Tour 2015 logo in either psd or jpeg format.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Familiarity with Photoshop/GIMP or any other designing software.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
== OWASP WebGoatPHP ==&lt;br /&gt;
&lt;br /&gt;
=== Task 1: Implement &amp;quot;remember me&amp;quot; feature ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Implement a secure &amp;quot;Remember me&amp;quot; feature in user login form using cookies. At present the remember me check box is present in the form but it does nothing.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Code&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
If user checks the &amp;quot;remember me&amp;quot; check box when logging in, then the user will not be required to login every time he visits the application within X days.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Comfortable in PHP, HTML and possibly Javascript. Good understanding of Application Security and related vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
'''Reference:'''&lt;br /&gt;
&lt;br /&gt;
https://github.com/shivamdixit/WebGoatPHP/issues/45&lt;br /&gt;
&lt;br /&gt;
'''Code:'''&lt;br /&gt;
&lt;br /&gt;
app/control/user/login.php&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Shivam Dixit&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Task 2: Make workshop mode dashboard responsive ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
In workshop mode of the application, the side panel of admin dashboard is not responsive i.e it does not fits well in smaller size screen resolutions. If the screen size is small the side panel should shrink into a smaller panel preferably at the bottom of the application.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Code&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
Panel perfectly adjusts on small screen resolutions.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
CSS (media queries), HTML&lt;br /&gt;
&lt;br /&gt;
'''Reference:'''&lt;br /&gt;
&lt;br /&gt;
https://github.com/shivamdixit/WebGoatPHP/issues/26&lt;br /&gt;
&lt;br /&gt;
'''Code:'''&lt;br /&gt;
&lt;br /&gt;
style/dashboard.css&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Shivam Dixit&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Task 3: WebGoatPHP logo ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Design a new logo for the application. The logo must resemble various aspects of the application. It would be better if the new logo is based on the OWASP logo. &lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Design&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
WebGoatPHP logo in either psd or jpeg format.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Familiarity with Photoshop/GIMP or any other designing software.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Shivam Dixit&lt;br /&gt;
&lt;br /&gt;
=== Task 4: WebGoatPHP deployment screencast ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Deploy the application on the local server without using vagrant and record a screencast of the process. Upload to a video streaming service and comment link on the melange for mentor to review.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Code&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
The screencast should clearly contain all the steps required for the deployment and how to troubleshoot most common errors in the whole process.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Familiarity with an operating system (Linux/Windows)&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Shivam Dixit&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Task 5: Create a SQL injection challenge ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Single user mode of WebGoatPHP consist of set of challenges. These challenges simulate various real world security vulnerabilities in web applications. You have to add a challenge under category &amp;quot;Injection Attacks&amp;quot; which simulates a SQL injection vulnerability in single user mode. The input data must be of type string and the challenge should mimic some real world scenario.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Code&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
A challenge which helps user understand SQLi vulnerability by allowing him to exploit the vulnerability.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Comfortable in PHP, HTML and possibly Javascript. Good understanding of Application Security and related vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
'''Reference:'''&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/SQL_Injection&lt;br /&gt;
&lt;br /&gt;
https://github.com/shivamdixit/WebGoatPHP/blob/master/README.md#adding-a-lessonchallenge&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Shivam Dixit&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Task 6-20: WebGoatPHP challenges screencast series ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
In this task you are required to record screencast of how to solve a particular single user mode challenge. The screencast should start by providing an overview of the vulnerability that will be exploited, then step by step instructions on how to exploit the vulnerability. The screencast should conclude on a note that how to avoid this vulnerability in your application. The length of the screencast would vary according to the challenge but it should neither be too long nor too short.&lt;br /&gt;
&lt;br /&gt;
Task    - Screencast of challenge.....&lt;br /&gt;
&lt;br /&gt;
Task 6  - HTTP Basic&lt;br /&gt;
&lt;br /&gt;
Task 7  - Using Access Control Matrix&lt;br /&gt;
&lt;br /&gt;
Task 8  - Business Layer Access Control&lt;br /&gt;
&lt;br /&gt;
Task 9  - Path Based Access Control&lt;br /&gt;
&lt;br /&gt;
Task 10 - Same Origin Policy Protection&lt;br /&gt;
&lt;br /&gt;
Task 11 - Forgot Password&lt;br /&gt;
&lt;br /&gt;
Task 12 - Discover clues in HTML&lt;br /&gt;
&lt;br /&gt;
Task 13 - JS Obfuscation&lt;br /&gt;
&lt;br /&gt;
Task 14 - XSS 1 (Reflected)&lt;br /&gt;
&lt;br /&gt;
Task 15 - XSS 2 (Stored)&lt;br /&gt;
&lt;br /&gt;
Task 16 - XSS 3 (DOM)&lt;br /&gt;
&lt;br /&gt;
Task 17 - Fail Open Authentication&lt;br /&gt;
&lt;br /&gt;
Task 18 - Log Spoofing&lt;br /&gt;
&lt;br /&gt;
Task 19 - Numeric SQL Injection&lt;br /&gt;
&lt;br /&gt;
Task 20 - XPATH injection&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Code&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
A screencast explaining the vulnerability involved in a particular challenge.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Comfortable in PHP, HTML and possibly Javascript. Good understanding of Application Security and related vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Shivam Dixit&lt;br /&gt;
&lt;br /&gt;
== OWASP CSRF Protector ==&lt;br /&gt;
&lt;br /&gt;
=== Task 1-2: CSRF Protector logo ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Design logos for the for CSRF Protector Project, possibly two versions one for php library and another one for Apache module.&lt;br /&gt;
Both of them should resemble OWASP logo.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Design&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
OWASP CSRF Protector logo in either psd or jpeg format.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Familiarity with Photoshop/GIMP or any other designing software.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Minhaz&lt;br /&gt;
&lt;br /&gt;
=== Task 3: Porting CSRF Protector PHP Wiki (from Github) to OWASP Wiki ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Currently we have wiki on how to use and deploy, at github. The task is to port them to OWASP Wiki as well so that it can be accessed directly.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
Wiki for CSRF Protector php library in OWASP.ORG .&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Familiarity with wiki.&lt;br /&gt;
&lt;br /&gt;
'''Reference'''&lt;br /&gt;
&lt;br /&gt;
[https://github.com/mebjas/CSRF-Protector-PHP/wiki Github wiki for CSRF Protector php]&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Minhaz&lt;br /&gt;
&lt;br /&gt;
=== Task 4: Porting mod_csrfprotector Wiki (from Github) to OWASP Wiki ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Currently we have wiki on how to use and deploy, at github. The task is to port them to OWASP Wiki as well so that it can be accessed directly.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
Wiki for mod_csrfprotector library in OWASP.ORG .&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Familiarity with wiki.&lt;br /&gt;
&lt;br /&gt;
'''References'''&lt;br /&gt;
&lt;br /&gt;
[https://github.com/mebjas/mod_csrfprotector/wiki Github wiki for mod_csrfprotector]&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Minhaz&lt;br /&gt;
&lt;br /&gt;
=== Task 5-6: Create screencasts on how to deploy both version of CSRF Protector individually ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Create two screencasts, one for each, which explains how to deploy CSRF Protector in your existing web application.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Screencast&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
Screencasts explaining how to use CSRF Protector with existing web applications.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Experience with php, HTML, and Apache (for mod_csrfprotector)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Minhaz&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Review Project ==&lt;br /&gt;
 https://www.owasp.org/index.php/OWASP_Code_review_V2_Project&lt;br /&gt;
&lt;br /&gt;
=== Task 1: Code Samples ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Code review guide has example code in .Net and Java and in some cases C++. We also want to include sample code in PHP and Ruby. We have existing example code in Java, .Net c#.&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Code&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
Follow existing code samples we need you to create Ruby and PHP where needed. All work will be shown in code review guide wiki. Please review code samples in code review guide wiki.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
php, and or Ruby&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Larry Conklin, Gary Robinson&lt;br /&gt;
&lt;br /&gt;
=== Task 1.1: Code Samples ===&lt;br /&gt;
Session Handling. Need php and Java code examples&lt;br /&gt;
 https://www.owasp.org/index.php/CRV2_SessionHandling&lt;br /&gt;
&lt;br /&gt;
=== Task 1.2: Code Samples ===&lt;br /&gt;
Input validation. Need php code examples&lt;br /&gt;
 https://www.owasp.org/index.php/CRV2_InputValIntro&lt;br /&gt;
&lt;br /&gt;
=== Task 1.3: Code Samples ===&lt;br /&gt;
Handling Error Messages. Need pho code examples&lt;br /&gt;
 https://www.owasp.org/index.php/CRV2_ErrorHandlingMessages&lt;br /&gt;
&lt;br /&gt;
=== Task 1.4: Code Samples ===&lt;br /&gt;
Persistent – The Anti pattern. Need Ruby code examples.&lt;br /&gt;
 https://www.owasp.org/index.php/CRV2_RevCodePersistentAntiPatternRuby&lt;br /&gt;
&lt;br /&gt;
=== Task 1.5: Code Samples ===&lt;br /&gt;
Reflected - The Anti pattern. Need Ruby code examples.&lt;br /&gt;
 https://www.owasp.org/index.php/CRV2_RevCodeReflectedAntiPatternIRuby&lt;br /&gt;
&lt;br /&gt;
=== Task 1.6: Code Samples ===&lt;br /&gt;
Ruby - AntiPatttern&lt;br /&gt;
 https://www.owasp.org/index.php/CRV2_AntiPatternPHP&lt;br /&gt;
&lt;br /&gt;
=== Task 2: Documentation ===&lt;br /&gt;
Reviewing by Technical Control&lt;br /&gt;
 https://www.owasp.org/index.php/OWASP_Code_review_V2_Table_of_Contents#Reviewing_by_Technical_Control&lt;br /&gt;
&lt;br /&gt;
Reviewing by Vulnerability&lt;br /&gt;
 https://www.owasp.org/index.php/OWASP_Code_review_V2_Table_of_Contents#Reviewing_by_Vulnerability&lt;br /&gt;
We need content from last two sections pulled from the wiki and added to a word doc and if possible have the content put into the following word doc template. Email me and I will send you the word template.&lt;br /&gt;
&lt;br /&gt;
We realize that all of the content will not easily fit into the word template but they can do the best they can and that will be fine with us. We only have three rules.&lt;br /&gt;
&lt;br /&gt;
Don’t delete anything even if you don’t agree with it.&lt;br /&gt;
Don’t add anything unless it is well marked that you added it.&lt;br /&gt;
Have fun and please ask questions. Please remember we have full time jobs and families. We will answer questions but maybe not as quickly as you would like. Yea, we are old grouchy men.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Basic understanding wiki editing, word understanding and ability to format text.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Larry Conklin, Gary Robinson&lt;br /&gt;
&lt;br /&gt;
== OWASP Security Controls in Web Application Development Lifecycle ==&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Security_Controls_in_Web_Application_Development_Lifecycle&lt;br /&gt;
&lt;br /&gt;
=== Task 1: Web Application Architecture ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
To come out with a diagrammatic explanation of how a web application works. Each and every section in the diagram must be explained. &lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Architecture&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
The architecture must clearly explain how a web application works irrespective of any technology.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Good understanding of web applications&lt;br /&gt;
&lt;br /&gt;
=== Task 2: Project Logo  ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
To come out with a suitable logo for the project matching the project title&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Designing Logo&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
Project Logo&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Creative imagination&lt;br /&gt;
&lt;br /&gt;
=== Task 3: Secure web application coding  ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
How to code a web application securely? E.g: Session Management, Input Validation, Error Logging, Configuration etc. with code examples. Technology : .NET / Java&lt;br /&gt;
&lt;br /&gt;
'''Task Category:'''&lt;br /&gt;
&lt;br /&gt;
Research &amp;amp; code snippets &lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
Theory and Code &lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
Good research skills, proper understanding of coding in .NET and Java&lt;br /&gt;
&lt;br /&gt;
'''Mentor:''' Nilay Sangani&lt;/div&gt;</summary>
		<author><name>Nilay Sangani</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Security_Controls_in_Web_Application_Development_Lifecycle&amp;diff=185057</id>
		<title>OWASP Security Controls in Web Application Development Lifecycle</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Security_Controls_in_Web_Application_Development_Lifecycle&amp;diff=185057"/>
				<updated>2014-11-10T18:38:14Z</updated>
		
		<summary type="html">&lt;p&gt;Nilay Sangani: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The OWASP Security Controls in Web Application Development Lifecycle==&lt;br /&gt;
&lt;br /&gt;
Security needs to be embedded right from the initials to release a secure end deliverable. &lt;br /&gt;
This project aims at delivering security controls right from the requirements,design,development,testing,release,maintenance and decommission.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Vision of this project is to demonstrate the implementation of integrating security controls in any web development lifecycle project.Every functional deliverable must be delivered in a fully secure fashion. If Security is injected right from the initials ( when the business needs arises ), cost to address the issues identified in the VAPT level will be very minimal or none. Developers,Application Security Analysts, Technical Project Managers, Pen Testers will also be able to pick up security libraries / checks to use them in their own applications and projects.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
GNU GPL v3 License&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Security Controls in Web Application Development Lifecycle Project? ==&lt;br /&gt;
&lt;br /&gt;
Project's tangible deliverable will be downloadable secure libraries,checklists,documents,guidelines in releasing each and every stage of web application development lifecycle in a secure manner.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:nilav.sangani@owasp.org Nilav Sangani]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
== Openhub ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
[https://lists.owasp.org/mailman/listinfo/owasp_security_controls_in_web_application_development_lifecycle Mailing List]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [mailto:nilay.sangani@owasp.org Nilay Sangani]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
Aim of this project:&lt;br /&gt;
To integrate security in application development lifecycle. At each and every stage of an application being developed, we will have security pushed into the process. We all know that there is a direct connection from the web application to the database. Security needs to be right at the application development end. Having security controls right from the start will ensure the application is developed in a secure fashion and methodology.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Nilay Sangani</name></author>	</entry>

	</feed>