<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Notinsanjose</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Notinsanjose"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Notinsanjose"/>
		<updated>2026-04-26T13:28:11Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_AppSec_FAQ_Project&amp;diff=23413</id>
		<title>Category:OWASP AppSec FAQ Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_AppSec_FAQ_Project&amp;diff=23413"/>
				<updated>2007-11-15T00:00:10Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: Undo revision 23412 by Notinsanjose (Talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Introduction=&lt;br /&gt;
&lt;br /&gt;
==What is this FAQ about?== &lt;br /&gt;
&lt;br /&gt;
This FAQ answers some of the questions that developers have about Web Application Security. This FAQ is not specific to a particular platform or language. It addresses the common threats to web applications and are applicable to any platform.&lt;br /&gt;
&lt;br /&gt;
==What are these common threats to Web Applications?==&lt;br /&gt;
&lt;br /&gt;
While developing an application, most of us are focused on the functionality rather than security. Attackers take advantage of this by exploiting the application in a number of ways. Some of the common threats to web applications are SQL Injection, Cross Site Scripting, Variable Manipulation and exploitation of important features like Forgot Password. There are separate sections in this FAQ answering the common questions on these threats. &lt;br /&gt;
&lt;br /&gt;
==Who developed this FAQ?== &lt;br /&gt;
&lt;br /&gt;
This FAQ is an evolving document with contributions from the security community. Sangita Pakala and her team from [http://www.paladion.net/ Paladion Networks] developed the first version of the FAQ and maintain this page. &lt;br /&gt;
&lt;br /&gt;
==How can I contribute to this FAQ?==&lt;br /&gt;
&lt;br /&gt;
We need your feedback and contributions to improve the FAQ. We'd love to hear from you about: &lt;br /&gt;
&lt;br /&gt;
*New questions to add to the FAQ &lt;br /&gt;
*Better answers for current questions &lt;br /&gt;
*New links to documents/tools &lt;br /&gt;
*Suggestions to improve the FAQ &lt;br /&gt;
&lt;br /&gt;
You could mail your contributions to [mailto:appsecfaq@owasp.org appsecfaq@owasp.org]&lt;br /&gt;
&lt;br /&gt;
=Contents=&lt;br /&gt;
&lt;br /&gt;
You can find the full [[OWASP AppSec FAQ]] to see all the details. &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
The OWASP FAQ is available for download as [http://www.owasp.org/docroot/owasp/misc/Preguntas_Frecuentes_sobre_Seguridad_en_Aplicaciones_Web(OWASP_FAQ).doc Word] and [http://www.owasp.org/docroot/owasp/misc/OWASP_FAQ_Ver3.pdf PDF] formats.&lt;br /&gt;
&lt;br /&gt;
'''New!''' The Spanish language verison of the FAQ is now available in [http://www.owasp.org/docroot/owasp/misc/Preguntas_Frecuentes_sobre_Seguridad_en_Aplicaciones_Web(OWASP_FAQ).doc Word] and [http://www.owasp.org/docroot/owasp/misc/Preguntas_Frecuentes_sobre_Seguridad_en_Aplicaciones_Web(OWASP_FAQ).pdf PDF] formats. Many thanks to Juan Carlos and Alberto Pena for their fantastic Spanish translation work.&lt;br /&gt;
&lt;br /&gt;
=Roadmap=&lt;br /&gt;
[[OWASP AppSec FAQ Project Roadmap]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_AppSec_FAQ_Project&amp;diff=23412</id>
		<title>Category:OWASP AppSec FAQ Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_AppSec_FAQ_Project&amp;diff=23412"/>
				<updated>2007-11-14T23:58:43Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Introduction=&lt;br /&gt;
&lt;br /&gt;
==What is this FAQ about?  I have no idea== &lt;br /&gt;
&lt;br /&gt;
This FAQ answers some of the questions that developers have about Web Application Security. This FAQ is not specific to a particular platform or language. It addresses the common threats to web applications and are applicable to any platform.&lt;br /&gt;
&lt;br /&gt;
==What are these common threats to Web Applications?==&lt;br /&gt;
&lt;br /&gt;
While developing an application, most of us are focused on the functionality rather than security. Attackers take advantage of this by exploiting the application in a number of ways. Some of the common threats to web applications are SQL Injection, Cross Site Scripting, Variable Manipulation and exploitation of important features like Forgot Password. There are separate sections in this FAQ answering the common questions on these threats. &lt;br /&gt;
&lt;br /&gt;
==Who developed this FAQ?== &lt;br /&gt;
&lt;br /&gt;
This FAQ is an evolving document with contributions from the security community. Sangita Pakala and her team from [http://www.paladion.net/ Paladion Networks] developed the first version of the FAQ and maintain this page. &lt;br /&gt;
&lt;br /&gt;
==How can I contribute to this FAQ?==&lt;br /&gt;
&lt;br /&gt;
We need your feedback and contributions to improve the FAQ. We'd love to hear from you about: &lt;br /&gt;
&lt;br /&gt;
*New questions to add to the FAQ &lt;br /&gt;
*Better answers for current questions &lt;br /&gt;
*New links to documents/tools &lt;br /&gt;
*Suggestions to improve the FAQ &lt;br /&gt;
&lt;br /&gt;
You could mail your contributions to [mailto:appsecfaq@owasp.org appsecfaq@owasp.org]&lt;br /&gt;
&lt;br /&gt;
=Contents=&lt;br /&gt;
&lt;br /&gt;
You can find the full [[OWASP AppSec FAQ]] to see all the details. &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
The OWASP FAQ is available for download as [http://www.owasp.org/docroot/owasp/misc/Preguntas_Frecuentes_sobre_Seguridad_en_Aplicaciones_Web(OWASP_FAQ).doc Word] and [http://www.owasp.org/docroot/owasp/misc/OWASP_FAQ_Ver3.pdf PDF] formats.&lt;br /&gt;
&lt;br /&gt;
'''New!''' The Spanish language verison of the FAQ is now available in [http://www.owasp.org/docroot/owasp/misc/Preguntas_Frecuentes_sobre_Seguridad_en_Aplicaciones_Web(OWASP_FAQ).doc Word] and [http://www.owasp.org/docroot/owasp/misc/Preguntas_Frecuentes_sobre_Seguridad_en_Aplicaciones_Web(OWASP_FAQ).pdf PDF] formats. Many thanks to Juan Carlos and Alberto Pena for their fantastic Spanish translation work.&lt;br /&gt;
&lt;br /&gt;
=Roadmap=&lt;br /&gt;
[[OWASP AppSec FAQ Project Roadmap]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Working_Groups&amp;diff=23411</id>
		<title>Category:OWASP Working Groups</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Working_Groups&amp;diff=23411"/>
				<updated>2007-11-14T22:22:30Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: New page: An OWASP Working Group is an arena for different parties with equal objectives to work together to provide guidance, requirements and  deliverables to OWASP projects or the industry in gen...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An OWASP Working Group is an arena for different parties with equal objectives to work together to provide guidance, requirements and  deliverables to OWASP projects or the industry in general.&lt;br /&gt;
&lt;br /&gt;
OWASP Working Group leaders are responsible for defining its vision, roadmap, and tasks&lt;br /&gt;
&lt;br /&gt;
To propose a new Working Group, please send an email to owasp@owasp.org&lt;br /&gt;
&lt;br /&gt;
Every Working Group has an associated mail list. You can view all the lists, examine their archives, and subscribe to any of them on the OWASP Mailing Lists page.&lt;br /&gt;
&lt;br /&gt;
Current active working groups:&lt;br /&gt;
&lt;br /&gt;
* '''Browser Security''': Robert R'Snake, Petrov Pdb, Jeremiah&lt;br /&gt;
* '''Industry Sectors''': Tom Brennan &lt;br /&gt;
* '''Access Control (XACML)''': Gunner peterson&lt;br /&gt;
* '''Education''': Sebastien Deleersnyder&lt;br /&gt;
* '''Mobile Security''': Corey Benninger&lt;br /&gt;
* '''Preventive Security''': Dinis Cruz&lt;br /&gt;
* '''OWASP SDL''': Pravir Chandra&lt;br /&gt;
* '''OWASP Governance''': Tom Brennan&lt;br /&gt;
&lt;br /&gt;
Some ideas for other OWASP working groups: Open Source solutions, Commercial vendors solutions, Evaluation &amp;amp; Certification, Privacy&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_.NET_Project&amp;diff=23379</id>
		<title>Category:OWASP .NET Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_.NET_Project&amp;diff=23379"/>
				<updated>2007-11-13T19:01:45Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: /* Latest */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the Owasp .Net Project. These pages are still in 'very alpha' format since we are still importing content (check out '''[[To Do on Owasp .Net Project Pages]]''' if you want to help out)&lt;br /&gt;
&lt;br /&gt;
{| &lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
 &lt;br /&gt;
== Latest ==&lt;br /&gt;
* Nov 2007: Uploaded test scripts from OWASP training in San Jose [https://www.owasp.org/images/7/7d/Fetch_Web_Page_%28from_OWASP_training_in_San_Jose%29.zip download here]&lt;br /&gt;
* Jun 2007: Created stub pages for Microsoft's [[SliverLight]], Abobe's [[AIR]], Microsoft's [[WSS]] and Apple's [[iPhone]]&lt;br /&gt;
* Jun 2007: [[DN_BOFinder]] Uploaded latest version to Sourceforge and updated WIKI page&lt;br /&gt;
* Feb 2007: Added info about the new tool: DotNet Buffer Overflow Finder [[DN_BOFinder]]&lt;br /&gt;
* 14th September: Added stub page [[Source Code Audit Tools]]&lt;br /&gt;
* 31st August: [[OWASP Autumn Of Code 2006 : Press Release | OWASP Autumn Of Code 2006]],  Today we are lauching a new project called &amp;quot;OWASP Autumn of Code 2006&amp;quot; which will sponsor individuals to work on existing OWASP Projects.&lt;br /&gt;
* 31st August: [http://video.google.com/videoplay?docid=941077664562737284 Dinis Cruz video interview], Dinis talks about .NET security, the future of OWASP, and the brand new [[Autumn of Code]] project.&lt;br /&gt;
* 14 August: Finished adding in the &amp;lt;nowiki&amp;gt; {{Template:Stub}} &amp;lt;/nowiki&amp;gt; to the pages - Mike de Libero&lt;br /&gt;
* 29 July: New finding [[Full Trust CLR Verification issue: changing the return address order]]&lt;br /&gt;
* 28 July: Added new tool [[.Net Assembly Analyzer]]&lt;br /&gt;
* 27 July: New Layout for home page &lt;br /&gt;
* 25 July: Made tons of changes to lots of pages (from new content, to images, etc...) &lt;br /&gt;
* 20 July: [[Owasp Report Generator]] page with links for download&lt;br /&gt;
* Uploaded latest version of [[Owasp SiteGenerator]](including the source code) to SourceForge and updated the links in [[Owasp SiteGenerator]]&lt;br /&gt;
* 11 July: [[Microsoft Security Bulletin July 2006-Vulnerabilities in IIS and ASP.Net]]&lt;br /&gt;
* 11 July: We have started to upload the Owasp .Net Projects to [https://sourceforge.net/project/showfiles.php?group_id=64424&amp;amp;package_id=105632 SourceForge dotNET section]. SiteGenerator is up there and more will follow.&lt;br /&gt;
&lt;br /&gt;
Unless marked, the above entries were posted by [[User:Dinis.cruz|Dinis.cruz]] &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Current Projects ==&lt;br /&gt;
* [[Owasp SiteGenerator]] (sponsored by Foundstone)&lt;br /&gt;
* [[Owasp Report Generator]]&lt;br /&gt;
* [[ANBS]] (Asp.Net Baseline Security) - includes the tools [[SAM'SHE]] (Security Analyzer for Microsoft's Shared Hosting Environments) and [[Online IIS Metabase Explorer]]&lt;br /&gt;
* [[ASP.NET Reflector]]&lt;br /&gt;
* [[ANSA]] (Asp.Net Security Analyzer) - first tool developed by Dinis Cruz that hilights the security problems of Full Trust Asp.Net code (contains Proof of Concept tests (i.e. exploits))&lt;br /&gt;
* [[DefApp]] - Partial port of ModSecurity to the .Net Platform &lt;br /&gt;
* [[Owasp FOSBBWAS (code name Beretta)]]&lt;br /&gt;
* [[.Net Assembly Analyzer]]&lt;br /&gt;
* [[OWASP_Tiger|Owasp Tiger]]&lt;br /&gt;
&lt;br /&gt;
'''Related Foundstone Open souce projects'''&lt;br /&gt;
* [[Hacme Bank]] (Foundstone tool)&lt;br /&gt;
* [[.NetMon]] (Foundstone tool)&lt;br /&gt;
* [[Validator.NET]] (Foundstone tool)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Note:''' All releases are available on the [https://sourceforge.net/project/showfiles.php?group_id=64424&amp;amp;package_id=105632 dotNET section] of the [https://sourceforge.net/projects/owasp/ SourceForge Owasp Project pages]&lt;br /&gt;
&lt;br /&gt;
|- &lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== .Net Security ==&lt;br /&gt;
* [[.Net Full Trust]] (the execution environment that makes an Asp.Net Application Insecure by Default, by Design and in Deployment)&lt;br /&gt;
* [[.Net Type Safety]]&lt;br /&gt;
* [[.Net Framework Security Issues]]&lt;br /&gt;
* [[Rooting The CLR]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Other misc stuff ==&lt;br /&gt;
* [[London Chapter WAF event]]&lt;br /&gt;
* [[Security Podcasts]]&lt;br /&gt;
* [[CVS details for Editors]]&lt;br /&gt;
* [[Wiki Edit Tips]]&lt;br /&gt;
* '''Code Samples'''&lt;br /&gt;
** [[.Net Code Sample - Reflecting assembly with missing dependency]]&lt;br /&gt;
** [[Files_Xml_WindowsMessages]] (with serialization stuff)&lt;br /&gt;
* [[.Net Research Links]]&lt;br /&gt;
* [[.Net Security Tools]]&lt;br /&gt;
* [[Richard Crypto .Net Stuff]]&lt;br /&gt;
* [[2006 Autumn Of Code]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mailing List ==&lt;br /&gt;
We have a mailing list at Sourceforge which we use to discuss relevant issue to .Net security (see [[How to join Owasp.Net Mailing List]])&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_.NET_Project&amp;diff=23378</id>
		<title>Category:OWASP .NET Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_.NET_Project&amp;diff=23378"/>
				<updated>2007-11-13T19:01:29Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: /* Latest */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the Owasp .Net Project. These pages are still in 'very alpha' format since we are still importing content (check out '''[[To Do on Owasp .Net Project Pages]]''' if you want to help out)&lt;br /&gt;
&lt;br /&gt;
{| &lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
 &lt;br /&gt;
== Latest ==&lt;br /&gt;
* Nov 2007: Uploaded test scripts from OWASP training in San Jose [https://www.owasp.org/images/7/7d/Fetch_Web_Page_%28from_OWASP_training_in_San_Jose%29.zip | download here]&lt;br /&gt;
* Jun 2007: Created stub pages for Microsoft's [[SliverLight]], Abobe's [[AIR]], Microsoft's [[WSS]] and Apple's [[iPhone]]&lt;br /&gt;
* Jun 2007: [[DN_BOFinder]] Uploaded latest version to Sourceforge and updated WIKI page&lt;br /&gt;
* Feb 2007: Added info about the new tool: DotNet Buffer Overflow Finder [[DN_BOFinder]]&lt;br /&gt;
* 14th September: Added stub page [[Source Code Audit Tools]]&lt;br /&gt;
* 31st August: [[OWASP Autumn Of Code 2006 : Press Release | OWASP Autumn Of Code 2006]],  Today we are lauching a new project called &amp;quot;OWASP Autumn of Code 2006&amp;quot; which will sponsor individuals to work on existing OWASP Projects.&lt;br /&gt;
* 31st August: [http://video.google.com/videoplay?docid=941077664562737284 Dinis Cruz video interview], Dinis talks about .NET security, the future of OWASP, and the brand new [[Autumn of Code]] project.&lt;br /&gt;
* 14 August: Finished adding in the &amp;lt;nowiki&amp;gt; {{Template:Stub}} &amp;lt;/nowiki&amp;gt; to the pages - Mike de Libero&lt;br /&gt;
* 29 July: New finding [[Full Trust CLR Verification issue: changing the return address order]]&lt;br /&gt;
* 28 July: Added new tool [[.Net Assembly Analyzer]]&lt;br /&gt;
* 27 July: New Layout for home page &lt;br /&gt;
* 25 July: Made tons of changes to lots of pages (from new content, to images, etc...) &lt;br /&gt;
* 20 July: [[Owasp Report Generator]] page with links for download&lt;br /&gt;
* Uploaded latest version of [[Owasp SiteGenerator]](including the source code) to SourceForge and updated the links in [[Owasp SiteGenerator]]&lt;br /&gt;
* 11 July: [[Microsoft Security Bulletin July 2006-Vulnerabilities in IIS and ASP.Net]]&lt;br /&gt;
* 11 July: We have started to upload the Owasp .Net Projects to [https://sourceforge.net/project/showfiles.php?group_id=64424&amp;amp;package_id=105632 SourceForge dotNET section]. SiteGenerator is up there and more will follow.&lt;br /&gt;
&lt;br /&gt;
Unless marked, the above entries were posted by [[User:Dinis.cruz|Dinis.cruz]] &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Current Projects ==&lt;br /&gt;
* [[Owasp SiteGenerator]] (sponsored by Foundstone)&lt;br /&gt;
* [[Owasp Report Generator]]&lt;br /&gt;
* [[ANBS]] (Asp.Net Baseline Security) - includes the tools [[SAM'SHE]] (Security Analyzer for Microsoft's Shared Hosting Environments) and [[Online IIS Metabase Explorer]]&lt;br /&gt;
* [[ASP.NET Reflector]]&lt;br /&gt;
* [[ANSA]] (Asp.Net Security Analyzer) - first tool developed by Dinis Cruz that hilights the security problems of Full Trust Asp.Net code (contains Proof of Concept tests (i.e. exploits))&lt;br /&gt;
* [[DefApp]] - Partial port of ModSecurity to the .Net Platform &lt;br /&gt;
* [[Owasp FOSBBWAS (code name Beretta)]]&lt;br /&gt;
* [[.Net Assembly Analyzer]]&lt;br /&gt;
* [[OWASP_Tiger|Owasp Tiger]]&lt;br /&gt;
&lt;br /&gt;
'''Related Foundstone Open souce projects'''&lt;br /&gt;
* [[Hacme Bank]] (Foundstone tool)&lt;br /&gt;
* [[.NetMon]] (Foundstone tool)&lt;br /&gt;
* [[Validator.NET]] (Foundstone tool)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Note:''' All releases are available on the [https://sourceforge.net/project/showfiles.php?group_id=64424&amp;amp;package_id=105632 dotNET section] of the [https://sourceforge.net/projects/owasp/ SourceForge Owasp Project pages]&lt;br /&gt;
&lt;br /&gt;
|- &lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== .Net Security ==&lt;br /&gt;
* [[.Net Full Trust]] (the execution environment that makes an Asp.Net Application Insecure by Default, by Design and in Deployment)&lt;br /&gt;
* [[.Net Type Safety]]&lt;br /&gt;
* [[.Net Framework Security Issues]]&lt;br /&gt;
* [[Rooting The CLR]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Other misc stuff ==&lt;br /&gt;
* [[London Chapter WAF event]]&lt;br /&gt;
* [[Security Podcasts]]&lt;br /&gt;
* [[CVS details for Editors]]&lt;br /&gt;
* [[Wiki Edit Tips]]&lt;br /&gt;
* '''Code Samples'''&lt;br /&gt;
** [[.Net Code Sample - Reflecting assembly with missing dependency]]&lt;br /&gt;
** [[Files_Xml_WindowsMessages]] (with serialization stuff)&lt;br /&gt;
* [[.Net Research Links]]&lt;br /&gt;
* [[.Net Security Tools]]&lt;br /&gt;
* [[Richard Crypto .Net Stuff]]&lt;br /&gt;
* [[2006 Autumn Of Code]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mailing List ==&lt;br /&gt;
We have a mailing list at Sourceforge which we use to discuss relevant issue to .Net security (see [[How to join Owasp.Net Mailing List]])&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_.NET_Project&amp;diff=23377</id>
		<title>Category:OWASP .NET Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_.NET_Project&amp;diff=23377"/>
				<updated>2007-11-13T19:01:14Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: /* Latest */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the Owasp .Net Project. These pages are still in 'very alpha' format since we are still importing content (check out '''[[To Do on Owasp .Net Project Pages]]''' if you want to help out)&lt;br /&gt;
&lt;br /&gt;
{| &lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
 &lt;br /&gt;
== Latest ==&lt;br /&gt;
* Nov 2007: Uploaded test scripts from OWASP training in San Jose [https://www.owasp.org/images/7/7d/Fetch_Web_Page_%28from_OWASP_training_in_San_Jose%29.zip| download here]&lt;br /&gt;
* Jun 2007: Created stub pages for Microsoft's [[SliverLight]], Abobe's [[AIR]], Microsoft's [[WSS]] and Apple's [[iPhone]]&lt;br /&gt;
* Jun 2007: [[DN_BOFinder]] Uploaded latest version to Sourceforge and updated WIKI page&lt;br /&gt;
* Feb 2007: Added info about the new tool: DotNet Buffer Overflow Finder [[DN_BOFinder]]&lt;br /&gt;
* 14th September: Added stub page [[Source Code Audit Tools]]&lt;br /&gt;
* 31st August: [[OWASP Autumn Of Code 2006 : Press Release | OWASP Autumn Of Code 2006]],  Today we are lauching a new project called &amp;quot;OWASP Autumn of Code 2006&amp;quot; which will sponsor individuals to work on existing OWASP Projects.&lt;br /&gt;
* 31st August: [http://video.google.com/videoplay?docid=941077664562737284 Dinis Cruz video interview], Dinis talks about .NET security, the future of OWASP, and the brand new [[Autumn of Code]] project.&lt;br /&gt;
* 14 August: Finished adding in the &amp;lt;nowiki&amp;gt; {{Template:Stub}} &amp;lt;/nowiki&amp;gt; to the pages - Mike de Libero&lt;br /&gt;
* 29 July: New finding [[Full Trust CLR Verification issue: changing the return address order]]&lt;br /&gt;
* 28 July: Added new tool [[.Net Assembly Analyzer]]&lt;br /&gt;
* 27 July: New Layout for home page &lt;br /&gt;
* 25 July: Made tons of changes to lots of pages (from new content, to images, etc...) &lt;br /&gt;
* 20 July: [[Owasp Report Generator]] page with links for download&lt;br /&gt;
* Uploaded latest version of [[Owasp SiteGenerator]](including the source code) to SourceForge and updated the links in [[Owasp SiteGenerator]]&lt;br /&gt;
* 11 July: [[Microsoft Security Bulletin July 2006-Vulnerabilities in IIS and ASP.Net]]&lt;br /&gt;
* 11 July: We have started to upload the Owasp .Net Projects to [https://sourceforge.net/project/showfiles.php?group_id=64424&amp;amp;package_id=105632 SourceForge dotNET section]. SiteGenerator is up there and more will follow.&lt;br /&gt;
&lt;br /&gt;
Unless marked, the above entries were posted by [[User:Dinis.cruz|Dinis.cruz]] &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Current Projects ==&lt;br /&gt;
* [[Owasp SiteGenerator]] (sponsored by Foundstone)&lt;br /&gt;
* [[Owasp Report Generator]]&lt;br /&gt;
* [[ANBS]] (Asp.Net Baseline Security) - includes the tools [[SAM'SHE]] (Security Analyzer for Microsoft's Shared Hosting Environments) and [[Online IIS Metabase Explorer]]&lt;br /&gt;
* [[ASP.NET Reflector]]&lt;br /&gt;
* [[ANSA]] (Asp.Net Security Analyzer) - first tool developed by Dinis Cruz that hilights the security problems of Full Trust Asp.Net code (contains Proof of Concept tests (i.e. exploits))&lt;br /&gt;
* [[DefApp]] - Partial port of ModSecurity to the .Net Platform &lt;br /&gt;
* [[Owasp FOSBBWAS (code name Beretta)]]&lt;br /&gt;
* [[.Net Assembly Analyzer]]&lt;br /&gt;
* [[OWASP_Tiger|Owasp Tiger]]&lt;br /&gt;
&lt;br /&gt;
'''Related Foundstone Open souce projects'''&lt;br /&gt;
* [[Hacme Bank]] (Foundstone tool)&lt;br /&gt;
* [[.NetMon]] (Foundstone tool)&lt;br /&gt;
* [[Validator.NET]] (Foundstone tool)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Note:''' All releases are available on the [https://sourceforge.net/project/showfiles.php?group_id=64424&amp;amp;package_id=105632 dotNET section] of the [https://sourceforge.net/projects/owasp/ SourceForge Owasp Project pages]&lt;br /&gt;
&lt;br /&gt;
|- &lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== .Net Security ==&lt;br /&gt;
* [[.Net Full Trust]] (the execution environment that makes an Asp.Net Application Insecure by Default, by Design and in Deployment)&lt;br /&gt;
* [[.Net Type Safety]]&lt;br /&gt;
* [[.Net Framework Security Issues]]&lt;br /&gt;
* [[Rooting The CLR]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Other misc stuff ==&lt;br /&gt;
* [[London Chapter WAF event]]&lt;br /&gt;
* [[Security Podcasts]]&lt;br /&gt;
* [[CVS details for Editors]]&lt;br /&gt;
* [[Wiki Edit Tips]]&lt;br /&gt;
* '''Code Samples'''&lt;br /&gt;
** [[.Net Code Sample - Reflecting assembly with missing dependency]]&lt;br /&gt;
** [[Files_Xml_WindowsMessages]] (with serialization stuff)&lt;br /&gt;
* [[.Net Research Links]]&lt;br /&gt;
* [[.Net Security Tools]]&lt;br /&gt;
* [[Richard Crypto .Net Stuff]]&lt;br /&gt;
* [[2006 Autumn Of Code]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mailing List ==&lt;br /&gt;
We have a mailing list at Sourceforge which we use to discuss relevant issue to .Net security (see [[How to join Owasp.Net Mailing List]])&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Fetch_Web_Page_(from_OWASP_training_in_San_Jose).zip&amp;diff=23376</id>
		<title>File:Fetch Web Page (from OWASP training in San Jose).zip</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Fetch_Web_Page_(from_OWASP_training_in_San_Jose).zip&amp;diff=23376"/>
				<updated>2007-11-13T19:00:02Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Project&amp;diff=23363</id>
		<title>Category:OWASP Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Project&amp;diff=23363"/>
				<updated>2007-11-13T17:48:06Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: /* Alpha Status Projects */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An OWASP project is a collection of related tasks that have a defined roadmap and team members. OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team.&lt;br /&gt;
&lt;br /&gt;
To propose a new project, please send an email to [mailto:owasp@owasp.org?subject=New_OWASP_Project_idea owasp@owasp.org]&lt;br /&gt;
&lt;br /&gt;
Every project has an associated mail list. You can view all the lists, examine their archives, and subscribe to any of them on the [http://lists.owasp.org/mailman/listinfo OWASP Project Mailing Lists] page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Release Quality Projects==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;th width=&amp;quot;50%&amp;quot;&amp;gt;Tools&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;Documentation&amp;lt;/th&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP WebGoat Project|OWASP WebGoat Project]]&lt;br /&gt;
: an online training environment for hands-on learning about application security&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP WebScarab Project|OWASP WebScarab Project]]&lt;br /&gt;
: a tool for performing all types of security testing on web applications and web services&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP AppSec FAQ Project|OWASP AppSec FAQ Project]]&lt;br /&gt;
: FAQ covering many application security topics&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Guide Project|OWASP Guide Project]]&lt;br /&gt;
: a massive document covering all aspects of web application and web service security&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Legal Project|OWASP Legal Project]]&lt;br /&gt;
: a project focused on contracting for secure software&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Testing Project|OWASP Testing Guide]]&lt;br /&gt;
: a project focused on application security testing procedures and checklists&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Top Ten Project|OWASP Top Ten Project]]&lt;br /&gt;
: an awareness document that describes the top ten web application security vulnerabilities&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Beta Status Projects==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;th width=&amp;quot;50%&amp;quot;&amp;gt;Tools&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;Documentation&amp;lt;/th&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP CAL9000 Project|OWASP CAL9000 Project]]&lt;br /&gt;
: a JavaScript based web application security testing suite&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP DirBuster Project|OWASP DirBuster Project]]&lt;br /&gt;
:DirBuster is a multi threaded java application designed to brute force directories and files names on web/application servers.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Encoding Project|OWASP Encoding Project]]&lt;br /&gt;
: a project focused on the development of encoding best practices for web applications.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP LAPSE Project|OWASP LAPSE Project]]&lt;br /&gt;
: an Eclipse-based source-code static analysis tool for Java&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Live CD Project|OWASP Live CD Project]]&lt;br /&gt;
: a CD containing ready to use versions of application security analysis and testing tools&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP LiveCD Education Project|OWASP LiveCD Education Project]]&lt;br /&gt;
: an educational supplement project containing tutorials, challenges and videos detailing the use of tools contained within the OWASP LiveCD - LabRat. &lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP .NET Project|OWASP .NET Research]]&lt;br /&gt;
: a project focused on helping .NET developers build secure applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Pantera Web Assessment Studio Project|OWASP Pantera Web Assessment Studio Project]]&lt;br /&gt;
: a project focused on combining automated capabilities with complete manual testing to get the best results&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Sprajax Project|OWASP Sprajax Project]]&lt;br /&gt;
: an open source black box security scanner used to assess the security of AJAX-enabled applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP SQLiX Project|OWASP SQLiX Project]]&lt;br /&gt;
: a project focused on the development of SQLiX, a full perl-based SQL scanner&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP WSFuzzer Project|OWASP WSFuzzer Project]]&lt;br /&gt;
: a project focused on the development of WSFuzzer, a full python-based Web Services SOAP fuzzer&lt;br /&gt;
&lt;br /&gt;
; [[ORG_%28Owasp_Report_Generator%29|OWASP Report Generator]]&lt;br /&gt;
: a project giving security professionals a way to report and keep track of their projects&lt;br /&gt;
&lt;br /&gt;
; [[Owasp_SiteGenerator|OWASP Site Generator]]&lt;br /&gt;
: a project allowing users to create dynamic sites for use in training, web application scanner testing, etc...&lt;br /&gt;
&lt;br /&gt;
; [[OWASP_Tiger|OWASP Tiger]]&lt;br /&gt;
: OWASP Tiger is a Windows application originally intended to be used for automating the process of testing various known ASP.NET security issues in hosted environments. However, it is much more versatile than that: it can help you construct and send a HTTP requests, receive and analyze the responses, match them against a set of conditions to produce alerts, notifications that something is wrong with the application(s) or service(s) being tested.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP WeBekci Project|OWASP WeBekci Project]]&lt;br /&gt;
: OWASP WeBekci is a web based ModSecurity 2.x management tool. WeBekci is written in PHP, Its backend is powered by MySQL and the frontend by XAJAX framework.&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP CLASP Project|OWASP CLASP Project]]&lt;br /&gt;
: a project focused on defining process elements that reinforce application security&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Code Review Project|OWASP Code Review Project]]&lt;br /&gt;
: a project to capture best practices for reviewing code&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Tools Project|OWASP Tools Project]]&lt;br /&gt;
: The OWASP Tools Project's goal is to provide unbiased, practical information and guidance about application security tools.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Alpha Status Projects==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;th width=&amp;quot;50%&amp;quot;&amp;gt;Tools&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;Documentation&amp;lt;/th&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP PHP AntiXSS Library Project|OWASP PHP AntiXSS Library Project]]&lt;br /&gt;
: reduce cross-site scripting vulnerabilities by encoding your output&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Insecure Web App Project|OWASP Insecure Web App Project]]&lt;br /&gt;
: a web application that includes common web application vulnerabilities&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Interceptor Project|OWASP Interceptor Project]]&lt;br /&gt;
: a testing tool for XML web service and Ajax interfaces&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP JBroFuzz|OWASP JBroFuzz Project]]&lt;br /&gt;
: a fuzzer application, supporting a number of automated security checks including basic cross site scripting checks (XSS) as well as basic SQL injection testing.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Orizon Project|OWASP Orizon Project]]&lt;br /&gt;
: a project focused on the development of a flexible code review engine&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Stinger Project|OWASP Stinger Project]]&lt;br /&gt;
: a project focus on the development of a centralized input validation mechanism which can be easily applied to existing or developmental applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP_Web_2.0_Project|OWASP Web 2.0 Project]]&lt;br /&gt;
: A place for advanced research of security in the Web 2.0 world &lt;br /&gt;
&lt;br /&gt;
; [[SpoC_007_-_SqlMap|SqlMap]]&lt;br /&gt;
: Automatic SQL injection tool entirely developed in Python&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP AJAX Security Project|OWASP AJAX Security Guide]]&lt;br /&gt;
: investigating the security of AJAX enabled applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Application Security Assessment Standards Project|OWASP Application Security Assessment Standards Project]]&lt;br /&gt;
: establish a set of standards defining baseline approaches to conducting differing types/levels of application security assessment&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Application Security Requirements Project|OWASP Application Security Requirements]]&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Application Security Metrics Project|OWASP Application Security Metrics Project]]&lt;br /&gt;
: identify and provide a set of application security metrics that have been found by contributors to be effective in measuring application security  &lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Career Development Project|OWASP Career Development Project]]&lt;br /&gt;
: The OWASP Career Development project is focused on helping application security professionals understand the job market, roles, career paths, and skills to work in the field.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Certification Criteria Project|OWASP Certification Criteria Project]]&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Certification Project|OWASP Certification Project]]&lt;br /&gt;
: our challenge is to create a plan for certification: a set of OWASP Certification for Developers and Testers. &lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Communications Project|OWASP Communications Project]]&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Honeycomb Project|OWASP Honeycomb Project]]&lt;br /&gt;
: a comprehensive and integrated guide to the fundamental building blocks of application security&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Java Project|OWASP Java Project]]&lt;br /&gt;
: a project focused on helping Java and J2EE developers build secure applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Logging Project|OWASP Logging Guide]]&lt;br /&gt;
: a project to define best practices for logging and log management&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP PHP Project|OWASP PHP Project]]&lt;br /&gt;
: a project focused on helping PHP developers build secure applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP SASAP Project|OWASP Scholastic Application Security Assessment Project]]&lt;br /&gt;
: a project that is intended to be the first step towards integrating security requirements in academic course curriculum&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Validation Project|OWASP Validation Project]]&lt;br /&gt;
: a project that provides guidance and tools related to validation&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP WASS Project|OWASP WASS Guide]]&lt;br /&gt;
: a standards project to develop more concrete criteria for secure applications&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Web Application Security Put Into Practice|OWASP Web Application Security Put Into Practice]]&lt;br /&gt;
: real-world web application security for Ruby on Rails, Apache and MySQL&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP XML Security Gateway Evaluation Criteria Project|OWASP XML Security Gateway Evaluation Criteria]]&lt;br /&gt;
: a project to define evaluation criteria for XML Security Gateways&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Education Project|OWASP Education Project]]&lt;br /&gt;
: a project to build educational tracks and modules for different audiences&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP on the Move Project|OWASP on The Move Project]]&lt;br /&gt;
: a project to match offer and demand regarding OWASP (related) presentations by speakers on web application security events or chapter meetings.&lt;br /&gt;
&lt;br /&gt;
; [[:Category:OWASP Fuzzing Code Database|OWASP Fuzzing Code Database]]&lt;br /&gt;
: a project to collect, share and compose statements used as code injections like SQL, SSI, XSS, Formatstring and as well directory traversal statements. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Education_Module_Why_WebAppSec_Matters&amp;diff=23356</id>
		<title>Education Module Why WebAppSec Matters</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Education_Module_Why_WebAppSec_Matters&amp;diff=23356"/>
				<updated>2007-11-12T17:54:51Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Module Description =&lt;br /&gt;
This module explains why security should be considered when developping or deploying web applications as part of the [[:Category:OWASP Education Project|Education Project]].&lt;br /&gt;
It identifies the current security problems with web applications. During the introduction a definition of web application security is given. Trends that are influencing the current state of web application insecurity are also explained.&lt;br /&gt;
* What goes wrong&lt;br /&gt;
* WebAppSec Defined&lt;br /&gt;
* Current trends &lt;br /&gt;
&lt;br /&gt;
= Target audience =&lt;br /&gt;
Novice.&lt;br /&gt;
&lt;br /&gt;
= Presentation =&lt;br /&gt;
The presentation can be found in [[:Image:Education_Module_Why_WebAppSec_Matters.ppt|Why WebAppSec Matters]].&lt;br /&gt;
&lt;br /&gt;
= Resources =&lt;br /&gt;
&lt;br /&gt;
= Presentation Notes =&lt;br /&gt;
Comment: It would be good to have speaker notes so that the presenter knows the objective of each slide&lt;br /&gt;
&lt;br /&gt;
== OWASP pointers ==&lt;br /&gt;
&lt;br /&gt;
== External pointers ==&lt;br /&gt;
* [http://cve.mitre.org cve.mitre.org]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Education Modules]]&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Education_Module_Why_WebAppSec_Matters&amp;diff=23352</id>
		<title>Education Module Why WebAppSec Matters</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Education_Module_Why_WebAppSec_Matters&amp;diff=23352"/>
				<updated>2007-11-12T17:38:39Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: Undo revision 23351 by Notinsanjose (Talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Module Description =&lt;br /&gt;
This module explains why security should be considered when developping or deploying web applications as part of the [[:Category:OWASP Education Project|Education Project]].&lt;br /&gt;
It identifies the current security problems with web applications. During the introduction a definition of web application security is given. Trends that are influencing the current state of web application insecurity are also explained.&lt;br /&gt;
* What goes wrong&lt;br /&gt;
* WebAppSec Defined&lt;br /&gt;
* Current trends &lt;br /&gt;
&lt;br /&gt;
= Target audience =&lt;br /&gt;
Novice.&lt;br /&gt;
&lt;br /&gt;
= Presentation =&lt;br /&gt;
The presentation can be found in [[:Image:Education_Module_Why_WebAppSec_Matters.ppt|Why WebAppSec Matters]].&lt;br /&gt;
&lt;br /&gt;
= Resources =&lt;br /&gt;
== OWASP pointers ==&lt;br /&gt;
&lt;br /&gt;
== External pointers ==&lt;br /&gt;
* [http://cve.mitre.org cve.mitre.org]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Education Modules]]&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Education_Module_Why_WebAppSec_Matters&amp;diff=23351</id>
		<title>Education Module Why WebAppSec Matters</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Education_Module_Why_WebAppSec_Matters&amp;diff=23351"/>
				<updated>2007-11-12T17:36:46Z</updated>
		
		<summary type="html">&lt;p&gt;Notinsanjose: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Module Description =&lt;br /&gt;
This module explains why security Doesn't matter and we should all go home!!!!!&lt;br /&gt;
&lt;br /&gt;
Hi Sebastien :)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
should be considered when developping or deploying web applications as part of the [[:Category:OWASP Education Project|Education Project]].&lt;br /&gt;
It identifies the current security problems with web applications. During the introduction a definition of web application security is given. Trends that are influencing the current state of web application insecurity are also explained.&lt;br /&gt;
* What goes wrong&lt;br /&gt;
* WebAppSec Defined&lt;br /&gt;
* Current trends &lt;br /&gt;
&lt;br /&gt;
= Target audience =&lt;br /&gt;
Novice.&lt;br /&gt;
&lt;br /&gt;
= Presentation =&lt;br /&gt;
The presentation can be found in [[:Image:Education_Module_Why_WebAppSec_Matters.ppt|Why WebAppSec Matters]].&lt;br /&gt;
&lt;br /&gt;
= Resources =&lt;br /&gt;
== OWASP pointers ==&lt;br /&gt;
&lt;br /&gt;
== External pointers ==&lt;br /&gt;
* [http://cve.mitre.org cve.mitre.org]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Education Modules]]&lt;/div&gt;</summary>
		<author><name>Notinsanjose</name></author>	</entry>

	</feed>