<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ofer+Maor</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ofer+Maor"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Ofer_Maor"/>
		<updated>2026-04-10T17:12:54Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=September_2019&amp;diff=254926</id>
		<title>September 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=September_2019&amp;diff=254926"/>
				<updated>2019-09-24T17:04:21Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
Meeting Date:&lt;br /&gt;
Sept 25&lt;br /&gt;
&lt;br /&gt;
Meeting Time:&lt;br /&gt;
7 PM CET (Amsterdam, Netherlands)&lt;br /&gt;
1 PM ET US (New York, USA)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Meeting Location:&lt;br /&gt;
Remote&lt;br /&gt;
&lt;br /&gt;
Virtual: &lt;br /&gt;
[https://zoom.us/j/282821949 Zoom Meeting Link]  Meeting ID: 282 821 949 - [https://zoom.us/u/kvUg3969 local dial in numbers]&lt;br /&gt;
&lt;br /&gt;
 AGENDA&lt;br /&gt;
&lt;br /&gt;
 CALL TO ORDER&lt;br /&gt;
&lt;br /&gt;
 CHANGES TO THE AGENDA&lt;br /&gt;
&lt;br /&gt;
 APPROVAL OF MINUTES&lt;br /&gt;
 [https://docs.google.com/document/d/1uyvKi1yrisahNnZpT6cWUs6yMwje89PI2WvjhIMgkH4/edit?usp=sharing July 2019 Minutes]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 REPORTS&lt;br /&gt;
*[https://drive.google.com/a/owasp.org/file/d/1RtTbFd6R6PERa93UOj7EIqsGfI8Sfxty/view?usp=sharing August 2019 Balance Sheet Summary]&lt;br /&gt;
*[https://drive.google.com/a/owasp.org/file/d/11gfS1XtSRiUbPLgCJO8MmagV6oxawkmN/view?usp=sharing Agust 2019 OWASP Combined P&amp;amp;L]&lt;br /&gt;
*[https://drive.google.com/a/owasp.org/file/d/1rATdQS0bhSRqN0yJShCSMY3tUQ1O4LTs/view?usp=sharing Agust 19 OWASP 2019 Combined Fin pkg]&lt;br /&gt;
&lt;br /&gt;
 OLD BUSINESS&lt;br /&gt;
&lt;br /&gt;
 NEW BUSINESS&lt;br /&gt;
&lt;br /&gt;
Resolution: Beginning January 1, 2020, the OWASP Foundation will no longer split profits of Global AppSec events with local chapters' internal accounting budgets. The Foundation/Chapter split for these events will be 100/0.&lt;br /&gt;
&lt;br /&gt;
Resolution: Beginning January 1, 2020, the OWASP Foundation will only pay a pre-determined flat fee for trainers offering sessions at Global AppSec events. There will no longer be a Foundation/Trainer revenue split for these events.&lt;br /&gt;
&lt;br /&gt;
Resolution: Starting next Board Meeting (October), All Board Meetings will require Board and Staff Members to participate using Video Conference, as provided by the meeting organizer. &lt;br /&gt;
&lt;br /&gt;
Resolution: Frequency and Structure of Executive Board Face 2 Face Meetings: &lt;br /&gt;
* The board will hold at least two, and ideally three, face to face executive board meetings. (These are intended to advance activities in a focused productive environment, as well as discuss OWASP Staff and other issues with associated privacy aspects).&lt;br /&gt;
* Attendance of board members is mandatory in all face-to-face executive meetings, except for extenuating circumstances. &lt;br /&gt;
* With the exception of private matters of staff, all notes from face-to-face meetings will be published after the meetings. &lt;br /&gt;
* The suggested motions coming up during the meeting will be presented to the community and be put up to vote in the next public board meeting (other than executive matters, the board shall not vote on any motion during the face-to-face meetings) &lt;br /&gt;
* Face-to-face meetings will be 2 full consecutive days, unless otherwise decided by the board&lt;br /&gt;
* For purpose of cost-saving, the Face-to-face meetings will be done in conjunction with other significant OWASP events, such as Global AppSec events, Project summit, etc. &lt;br /&gt;
* The first face-to-face meeting of each year must be held in the first two months of the year (Jan/Feb). The exact time will be determined by the staff and the board of the previous year. &lt;br /&gt;
* The schedule for the second (and third) face-to-face meeting of each year will be determined by the newly elected board in the first face-to-face meeting. &lt;br /&gt;
Resolution: Set 2020 First Face-to-Face meeting to Take place in February, alongside the Project Summit&lt;br /&gt;
&lt;br /&gt;
 COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS&lt;br /&gt;
 ADJOURNMENT&lt;br /&gt;
&lt;br /&gt;
Update - Assignment of each Board Member to a specific area - as agreed upon in the last Face to Face executive board meeting. &lt;br /&gt;
===&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=September_2019&amp;diff=254914</id>
		<title>September 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=September_2019&amp;diff=254914"/>
				<updated>2019-09-24T10:05:22Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: New suggested resolutions for governance of the board face to face meetings and public board meetings.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
Meeting Date:&lt;br /&gt;
Sept 25&lt;br /&gt;
&lt;br /&gt;
Meeting Time:&lt;br /&gt;
7 PM CET (Amsterdam, Netherlands)&lt;br /&gt;
1 PM ET US (New York, USA)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Meeting Location:&lt;br /&gt;
Remote&lt;br /&gt;
&lt;br /&gt;
Virtual: &lt;br /&gt;
[https://zoom.us/j/282821949 Zoom Meeting Link]  Meeting ID: 282 821 949 - [https://zoom.us/u/kvUg3969 local dial in numbers]&lt;br /&gt;
&lt;br /&gt;
 AGENDA&lt;br /&gt;
&lt;br /&gt;
 CALL TO ORDER&lt;br /&gt;
&lt;br /&gt;
 CHANGES TO THE AGENDA&lt;br /&gt;
&lt;br /&gt;
 APPROVAL OF MINUTES&lt;br /&gt;
 [https://docs.google.com/document/d/1uyvKi1yrisahNnZpT6cWUs6yMwje89PI2WvjhIMgkH4/edit?usp=sharing July 2019 Minutes]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 REPORTS&lt;br /&gt;
*[https://drive.google.com/a/owasp.org/file/d/1RtTbFd6R6PERa93UOj7EIqsGfI8Sfxty/view?usp=sharing August 2019 Balance Sheet Summary]&lt;br /&gt;
*[https://drive.google.com/a/owasp.org/file/d/11gfS1XtSRiUbPLgCJO8MmagV6oxawkmN/view?usp=sharing Agust 2019 OWASP Combined P&amp;amp;L]&lt;br /&gt;
*[https://drive.google.com/a/owasp.org/file/d/1rATdQS0bhSRqN0yJShCSMY3tUQ1O4LTs/view?usp=sharing Agust 19 OWASP 2019 Combined Fin pkg]&lt;br /&gt;
&lt;br /&gt;
 OLD BUSINESS&lt;br /&gt;
&lt;br /&gt;
 NEW BUSINESS&lt;br /&gt;
&lt;br /&gt;
Resolution: Beginning January 1, 2020, the OWASP Foundation will no longer split profits of Global AppSec events with local chapters' internal accounting budgets. The Foundation/Chapter split for these events will be 100/0.&lt;br /&gt;
&lt;br /&gt;
Resolution: Beginning January 1, 2020, the OWASP Foundation will only pay a pre-determined flat fee for trainers offering sessions at Global AppSec events. There will no longer be a Foundation/Trainer revenue split for these events.&lt;br /&gt;
&lt;br /&gt;
Resolution: Starting next Board Meeting (October), All Board Meetings will require Board and Staff Members to participate using Video Conference, as provided by the meeting organizer. &lt;br /&gt;
&lt;br /&gt;
Resolution: Frequency and Structure of Executive Board Face 2 Face Meetings: &lt;br /&gt;
* The board will hold at least two, and ideally three, face to face executive board meetings. (These are intended to advance activities in a focused productive environment, as well as discuss OWASP Staff and other issues with associated privacy aspects).&lt;br /&gt;
* Attendance of board members is mandatory in all face-to-face executive meetings, except for extenuating circumstances. &lt;br /&gt;
* With the exception of private matters of staff, all notes from face-to-face meetings will be published after the meetings. &lt;br /&gt;
* The suggested motions coming up during the meeting will be presented to the community and be put up to vote in the next public board meeting (other than executive matters, the board shall not vote on any motion during the face-to-face meetings) &lt;br /&gt;
* Face-to-face meetings will be 2 full consecutive days, unless otherwise decided by the board&lt;br /&gt;
* For purpose of cost-saving, the Face-to-face meetings will be done in conjunction with other significant OWASP events, such as Global AppSec events, Project summit, etc. &lt;br /&gt;
* The first face-to-face meeting of each year must be held in the first two months of the year (Jan/Feb). The exact time will be determined by the staff and the board of the previous year. &lt;br /&gt;
* The schedule for the second (and third) face-to-face meeting of each year will be determined by the newly elected board in the first face-to-face meeting. &lt;br /&gt;
Resolution: Set 2020 First Face-to-Face meeting to Take place in February, alongside the Project Summit&lt;br /&gt;
&lt;br /&gt;
 COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS&lt;br /&gt;
 ADJOURNMENT&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ofer_Maor_2019_Bio_and_Why_me&amp;diff=254301</id>
		<title>Ofer Maor 2019 Bio and Why me</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ofer_Maor_2019_Bio_and_Why_me&amp;diff=254301"/>
				<updated>2019-08-28T22:42:34Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About Myself==&lt;br /&gt;
I’m a passionate cybersecurity professional with 25 years of experience in the industry, 20 of which in the AppSec field. I’ve been part of OWASP for 17 years, (almost) since its inception, and I currently serve on its Board of Directors. I've also held multiple roles in OWASP, including Chapter Leader, Global AppSec Event Co-Chair, Global Committee Member and more... &lt;br /&gt;
&lt;br /&gt;
At the same time, I’ve also had the opportunity to work in various roles in the security industry, ranging from pen-testing, consulting, research, support, development, product management and all the way up to founding and managing several companies in this space. I’ve been a Breaker, a Builder and a Defender. I’ve been as hands-on and technical as it gets, but also had the chance to see how things operate on the larger scale.&lt;br /&gt;
&lt;br /&gt;
Deep inside, I’m still a (ethical) hacker at heart, and I’m still an idealist about the the notion of community and open source at large, and OWASP specifically, yet at the same time I understand how organizations operate and what they need to do to thrive, and I believe this balance is what I bring to the OWASP Board. Since the beginning of the year, I have worked with the foundation staff to help grow and improve OWASP so that it can better support the community. &lt;br /&gt;
&lt;br /&gt;
'''Today, after only a little over half a year on the board, I feel like we are starting to make a progress, and I would like to stay on the board to make sure that I can help drive those changes through.'''&lt;br /&gt;
&lt;br /&gt;
== Candidate Election Video ==&lt;br /&gt;
[https://www.youtube.com/watch?v=r9x_36VKMYg&amp;amp;feature=youtu.be Ofer Maor's OWASP 2019 Elections Candidate Interview]  &lt;br /&gt;
&lt;br /&gt;
==Why Me?==&lt;br /&gt;
I’m passionate about OWASP, and especially about its community. I’ve been working with OWASP for a long time, and have always cared for it. I’ve met some of the best people along my professional career through the OWASP community, and many of them became long lasting friends. Through my entire time with OWASP, the community is what drives me forward, and driving this community forward is what I can bring to the table.&lt;br /&gt;
&lt;br /&gt;
OWASP is going through growing pains, that are natural at this time and place, yet still immensely challenging. OWASP has a growing financial pressure to support its growth, and at the same time has growing industry pressures, with vendors looking to influence the industry standards that it set. These pressures present great challenges for OWASP, both on the foundation and on the community, generating friction and frustration. Last year we’ve witnessed such a disconnect and miscommunication, which nearly ripped the community apart. During that time, I’ve worked with the board, the foundation and the community, to smooth things out, find the right solution, and prevent the rip.&lt;br /&gt;
&lt;br /&gt;
Seeing which challenges we are facing, and the contribution I can offer, made me join the board in the first place and do the best I can to contribute to OWASP. I would like to continue the work I have started so that we can truly turn the page onto OWASPs next chapter, making it a leading global organization in the cybersecurity industry. &lt;br /&gt;
===Focus===&lt;br /&gt;
I plan to continue focus on the fine balance between the community, the financial constraints and the industry as a whole, to make sure OWASP stays true to its spirit, yet is allowed to grows and evolve to its next phase, reaching new audiences and making a greater impact on the software industry as a whole.&lt;br /&gt;
&lt;br /&gt;
Some key areas I am already working on and plan on continuing:&lt;br /&gt;
*'''Membership''': I believe our current membership structure, both at the individual and corporate levels, makes it hard to increase membership revenue to the foundation, as it is not always clear what is the membership value.  As a board member I took upon myself to be the lead board member, working with the staff, on changing our membership models to make OWASP a more professional organization, run by its members and better supported by the corporates in our industry. Some of these changes have already been made and published, while others are still in work and are likely to take effect over the course of the next 12-18 months. &lt;br /&gt;
*'''Chapters''': Chapters are one of the two main pillars OWASP thrives upon. Without our chapters we have no audience and can reach no one. Yet our chapters are not all the same. Some chapters are run very well and reach a great audience, while others are struggling and failing to get traction. In my upcoming term, should I get elected, I plan to put more emphasize on helping chapters run more professionally and more consistently, giving our members and target audience a better, more consistent experience worldwide. &lt;br /&gt;
*'''Committees:''' I believe Global Committees can be a great way to drive more initiatives by people in community, who are eager to do more and need the right framework.  As a board member I supported initiatives that offer the community the framework to do more, especially around Chapters, Projects, and Education (and work to make sure they function better this time). &lt;br /&gt;
*'''Vendor Neutrality:''' Throughout my entire OWASP roles, I’ve always put great emphasize on vendor neutrality (despite working for one or another throughout this entire time). I believe the only way to keep OWASP relevant and valuable, is by making sure the content we produce in projects, conferences and education is neutral -  focusing on best practices and practical knowledge, and not on marketing pitches and sales activities.   As a board member I promise to vigorously fight against any attempt to externally influence OWASP as a whole, or any of its projects or conferences, in favor of specific vendor, whether it is financial gain or by taking control of an activity.&lt;br /&gt;
&lt;br /&gt;
=== Relevant Experience ===&lt;br /&gt;
I’ve been part of OWASP for 17 years, (almost) since its inception, and I’ve had the opportunity of being involved in various activities:&lt;br /&gt;
*I've been on the Global Board of OWASP since January 2019, serving as the Secretary of the Board. As part of this role I am working with the staff on driving changes both to corporate and individual membership, to help OWASP become more professional as well as stabilize its financials. I'm also working on driving other initiatives for making the board interactions and meetings more professional, delivering better outcomes. &lt;br /&gt;
*I've been the co-Chair of Global AppSec Tel Aviv that took place in 2019. We had a great turnaround of people and sponsors in a location that has never before had a Global AppSec Event. We've also managed to make Global AppSec Tel Aviv more inclusive than ever with over 30% female speakers!&lt;br /&gt;
*I’ve been on the board of OWASP Israel for 10 years, of which I was the chair for 4 years. During this time OWASP Israel has grown considerably and transformed from a small chapter with no funding (and a single board member) to one of the largest communities in OWASP with a proper board and volunteer base.&lt;br /&gt;
*For the past decade we’ve been running the OWASP AppSec IL conference every year, growing it from a half-day, single-track event with 90 attendees to a multi-day conference with trainings and over 700 attendees. Today, OWASP AppSec IL is one of the most attended OWASP events every year. I’ve had the chance of running the conference as a chair for several years and took on other roles later, including content committee (speaker selection), sponsorships (driving revenue to the conference), and more.&lt;br /&gt;
*I’ve also been part of the Global Membership Committee (before the committees were disassembled). In this role we drove initiatives to increase OWASP membership (and thus revenue) for both individuals and corporates.&lt;br /&gt;
Outside of OWASP, I’ve had the chance of working in various roles in the industry. I’ve also had the chance of founding and running my own companies – first an AppSec consulting company, followed by an AppSec product company (both later acquired and still alive). I’ve been on the Board of several companies (including a publicly traded company in NYSE/Euronext), and I’ve had the chance to define, manage and review budgets and financial management of companies.&lt;br /&gt;
&lt;br /&gt;
For more information about my professional experience you are welcome to visit my LinkedIn Profile: https://www.linkedin.com/in/ofermaor/&lt;br /&gt;
&lt;br /&gt;
You can also listen to my latest podcast recording from AppSec EU 2018 by Chris Romeo from the Application Security Podcast, where I share some of my history, my current work and my intention to run for the OWASP Board at: https://www.securityjourney.com/blog/a-pen-testers-transition-to-appsec-vote-for-ofer/&lt;br /&gt;
==Contact Me==&lt;br /&gt;
If you'd like to know more - feel free to reach out to me:&lt;br /&gt;
*Mail: ofer.maor@owasp.org&lt;br /&gt;
*Twitter: @OferMaor&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ofer_Maor_2019_Bio_and_Why_me&amp;diff=254300</id>
		<title>Ofer Maor 2019 Bio and Why me</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ofer_Maor_2019_Bio_and_Why_me&amp;diff=254300"/>
				<updated>2019-08-28T21:52:39Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: /* About Ofer */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About Myself==&lt;br /&gt;
I’m a passionate cybersecurity professional with 25 years of experience in the industry, 20 of which in the AppSec field. I’ve been part of OWASP for 17 years, (almost) since its inception, and I currently serve on its Board of Directors. I've also held multiple roles in OWASP, including Chapter Leader, Global AppSec Event Co-Chair, Global Committee Member and more... &lt;br /&gt;
&lt;br /&gt;
At the same time, I’ve also had the opportunity to work in various roles in the security industry, ranging from pen-testing, consulting, research, support, development, product management and all the way up to founding and managing several companies in this space. I’ve been a Breaker, a Builder and a Defender. I’ve been as hands-on and technical as it gets, but also had the chance to see how things operate on the larger scale.&lt;br /&gt;
&lt;br /&gt;
Deep inside, I’m still a (ethical) hacker at heart, and I’m still an idealist about the the notion of community and open source at large, and OWASP specifically, yet at the same time I understand how organizations operate and what they need to do to thrive, and I believe this balance is what I bring to the OWASP Board. Since the beginning of the year, I have worked with the foundation staff to help grow and improve OWASP so that it can better support the community. &lt;br /&gt;
&lt;br /&gt;
'''Today, after only a little over half a year on the board, I feel like we are starting to make a progress, and I would like to stay on the board to make sure that I can help drive those changes through.''' &lt;br /&gt;
&lt;br /&gt;
Link to my Video here: &lt;br /&gt;
&lt;br /&gt;
==Why Me?==&lt;br /&gt;
I’m passionate about OWASP, and especially about its community. I’ve been working with OWASP for a long time, and have always cared for it. I’ve met some of the best people along my professional career through the OWASP community, and many of them became long lasting friends. Through my entire time with OWASP, the community is what drives me forward, and driving this community forward is what I can bring to the table.&lt;br /&gt;
&lt;br /&gt;
OWASP is going through growing pains, that are natural at this time and place, yet still immensely challenging. OWASP has a growing financial pressure to support its growth, and at the same time has growing industry pressures, with vendors looking to influence the industry standards that it set. These pressures present great challenges for OWASP, both on the foundation and on the community, generating friction and frustration. Last year we’ve witnessed such a disconnect and miscommunication, which nearly ripped the community apart. During that time, I’ve worked with the board, the foundation and the community, to smooth things out, find the right solution, and prevent the rip.&lt;br /&gt;
&lt;br /&gt;
Seeing which challenges we are facing, and the contribution I can offer, made me join the board in the first place and do the best I can to contribute to OWASP. I would like to continue the work I have started so that we can truly turn the page onto OWASPs next chapter, making it a leading global organization in the cybersecurity industry. &lt;br /&gt;
===Focus===&lt;br /&gt;
I plan to continue focus on the fine balance between the community, the financial constraints and the industry as a whole, to make sure OWASP stays true to its spirit, yet is allowed to grows and evolve to its next phase, reaching new audiences and making a greater impact on the software industry as a whole.&lt;br /&gt;
&lt;br /&gt;
Some key areas I am already working on and plan on continuing:&lt;br /&gt;
*'''Membership''': I believe our current membership structure, both at the individual and corporate levels, makes it hard to increase membership revenue to the foundation, as it is not always clear what is the membership value.  As a board member I took upon myself to be the lead board member, working with the staff, on changing our membership models to make OWASP a more professional organization, run by its members and better supported by the corporates in our industry. Some of these changes have already been made and published, while others are still in work and are likely to take effect over the course of the next 12-18 months. &lt;br /&gt;
*'''Chapters''': Chapters are one of the two main pillars OWASP thrives upon. Without our chapters we have no audience and can reach no one. Yet our chapters are not all the same. Some chapters are run very well and reach a great audience, while others are struggling and failing to get traction. In my upcoming term, should I get elected, I plan to put more emphasize on helping chapters run more professionally and more consistently, giving our members and target audience a better, more consistent experience worldwide. &lt;br /&gt;
*'''Committees:''' I believe Global Committees can be a great way to drive more initiatives by people in community, who are eager to do more and need the right framework.  As a board member I supported initiatives that offer the community the framework to do more, especially around Chapters, Projects, and Education (and work to make sure they function better this time). &lt;br /&gt;
*'''Vendor Neutrality:''' Throughout my entire OWASP roles, I’ve always put great emphasize on vendor neutrality (despite working for one or another throughout this entire time). I believe the only way to keep OWASP relevant and valuable, is by making sure the content we produce in projects, conferences and education is neutral -  focusing on best practices and practical knowledge, and not on marketing pitches and sales activities.   As a board member I promise to vigorously fight against any attempt to externally influence OWASP as a whole, or any of its projects or conferences, in favor of specific vendor, whether it is financial gain or by taking control of an activity.&lt;br /&gt;
&lt;br /&gt;
=== Relevant Experience ===&lt;br /&gt;
I’ve been part of OWASP for 17 years, (almost) since its inception, and I’ve had the opportunity of being involved in various activities:&lt;br /&gt;
*I've been on the Global Board of OWASP since January 2019, serving as the Secretary of the Board. As part of this role I am working with the staff on driving changes both to corporate and individual membership, to help OWASP become more professional as well as stabilize its financials. I'm also working on driving other initiatives for making the board interactions and meetings more professional, delivering better outcomes. &lt;br /&gt;
*I've been the co-Chair of Global AppSec Tel Aviv that took place in 2019. We had a great turnaround of people and sponsors in a location that has never before had a Global AppSec Event. We've also managed to make Global AppSec Tel Aviv more inclusive than ever with over 30% female speakers!&lt;br /&gt;
*I’ve been on the board of OWASP Israel for 10 years, of which I was the chair for 4 years. During this time OWASP Israel has grown considerably and transformed from a small chapter with no funding (and a single board member) to one of the largest communities in OWASP with a proper board and volunteer base.&lt;br /&gt;
*For the past decade we’ve been running the OWASP AppSec IL conference every year, growing it from a half-day, single-track event with 90 attendees to a multi-day conference with trainings and over 700 attendees. Today, OWASP AppSec IL is one of the most attended OWASP events every year. I’ve had the chance of running the conference as a chair for several years and took on other roles later, including content committee (speaker selection), sponsorships (driving revenue to the conference), and more.&lt;br /&gt;
*I’ve also been part of the Global Membership Committee (before the committees were disassembled). In this role we drove initiatives to increase OWASP membership (and thus revenue) for both individuals and corporates.&lt;br /&gt;
Outside of OWASP, I’ve had the chance of working in various roles in the industry. I’ve also had the chance of founding and running my own companies – first an AppSec consulting company, followed by an AppSec product company (both later acquired and still alive). I’ve been on the Board of several companies (including a publicly traded company in NYSE/Euronext), and I’ve had the chance to define, manage and review budgets and financial management of companies.&lt;br /&gt;
&lt;br /&gt;
For more information about my professional experience you are welcome to visit my LinkedIn Profile: https://www.linkedin.com/in/ofermaor/&lt;br /&gt;
&lt;br /&gt;
You can also listen to my latest podcast recording from AppSec EU 2018 by Chris Romeo from the Application Security Podcast, where I share some of my history, my current work and my intention to run for the OWASP Board at: https://www.securityjourney.com/blog/a-pen-testers-transition-to-appsec-vote-for-ofer/&lt;br /&gt;
==Contact Me==&lt;br /&gt;
If you'd like to know more - feel free to reach out to me:&lt;br /&gt;
*Mail: ofer.maor@owasp.org&lt;br /&gt;
*Twitter: @OferMaor&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Staff-Projects/Board_Elections/2019_Global_Board_of_Directors_Election&amp;diff=254283</id>
		<title>Staff-Projects/Board Elections/2019 Global Board of Directors Election</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Staff-Projects/Board_Elections/2019_Global_Board_of_Directors_Election&amp;diff=254283"/>
				<updated>2019-08-28T18:39:36Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: /* Meet the Candidates and listen to their interviews */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== General Election Information ==&lt;br /&gt;
For general election information, including eligibility requirements, who can vote and how to vote, along with other frequently asked questions, please visit:&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/Staff-Projects/Board_Elections OWASP Board Elections] &lt;br /&gt;
&lt;br /&gt;
== Board Member Seats ==&lt;br /&gt;
The following individuals' Board Member Seats will expire on December 31, 2019. &lt;br /&gt;
&lt;br /&gt;
* Owen Pendlebury&lt;br /&gt;
* Chenxi Wang&lt;br /&gt;
* Sherif Mansour&lt;br /&gt;
* Ofer Maor&lt;br /&gt;
&lt;br /&gt;
== Meet the Candidates and listen to their interviews ==&lt;br /&gt;
''Links to the interviews will be posted here on or before September 6''&lt;br /&gt;
&lt;br /&gt;
''4 seats are open for this election''&lt;br /&gt;
&lt;br /&gt;
Ricardo Supo Picón&lt;br /&gt;
&lt;br /&gt;
Haral Tsitsivas&lt;br /&gt;
&lt;br /&gt;
Sherif Mansour&lt;br /&gt;
&lt;br /&gt;
Kenneth	Farrow&lt;br /&gt;
&lt;br /&gt;
Teuta Hyseni&lt;br /&gt;
&lt;br /&gt;
Ryan Tierney&lt;br /&gt;
&lt;br /&gt;
Valencia Payne&lt;br /&gt;
&lt;br /&gt;
[[Ofer Maor 2019 Bio and Why me|Ofer Maor]]&lt;br /&gt;
&lt;br /&gt;
Vandana Verma Sehgal&lt;br /&gt;
&lt;br /&gt;
Jon Nice&lt;br /&gt;
&lt;br /&gt;
Santosh	Pandit&lt;br /&gt;
&lt;br /&gt;
Andrew Stevens&lt;br /&gt;
&lt;br /&gt;
Ali AlEnezi&lt;br /&gt;
&lt;br /&gt;
Ricardo	Rodriguez&lt;br /&gt;
&lt;br /&gt;
Joe Blanchard&lt;br /&gt;
&lt;br /&gt;
Bil Corry&lt;br /&gt;
&lt;br /&gt;
Shawn Kammerdiener&lt;br /&gt;
&lt;br /&gt;
Grant Ongers&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury&lt;br /&gt;
&lt;br /&gt;
Trevor Hogan&lt;br /&gt;
&lt;br /&gt;
== Milestones ==&lt;br /&gt;
&lt;br /&gt;
* 2019-07-02 - Notify the current board member(s) whose term is up [Mike] COMPLETE&lt;br /&gt;
* 2019-07-03 - Call for Candidates Opens https://mailchi.mp/owasp/2019election  ([https://owasp.wufoo.com/forms/m18o8vlr0svp1uk/ Apply Here!])&lt;br /&gt;
* 2019-07-03 - Submission for Questions From the Community for the Candidate Interviews - ([https://github.com/OWASP-Foundation/Board-Election-Call-for-Questions/issues/2 Submit a Question Here])&lt;br /&gt;
* 2019-07-10 - Email Reminder Call For Candidates &amp;amp; Questions from the Community https://mailchi.mp/owasp/2019election-222595&lt;br /&gt;
* 2019-07-17 - Email Reminder Call For Candidates &amp;amp; Questions from the Community https://mailchi.mp/owasp/2019election-222603&lt;br /&gt;
* 2019-07-24 - Email Reminder Call For Candidates &amp;amp; Questions from the Community  https://mailchi.mp/owasp/2019election-222607&lt;br /&gt;
* 2019-07-31 - '''Deadline for Call for Candidates Closes''' &lt;br /&gt;
* 2019-07-31 - Deadline for Questions from the Community&lt;br /&gt;
* 2019-08-06 - Verification of candidates&lt;br /&gt;
* 2019-08-08 - Scheduling of group interviews&lt;br /&gt;
* 2019-08-13 - Candidates announced via email and social media&lt;br /&gt;
* 2019-08-15 - The 6-7 top questions from the community will be selected &amp;amp; shared with Candidates&lt;br /&gt;
* 2019-08-17 - Email Reminder Membership Required to Vote&lt;br /&gt;
* 2019-08-20 - Email Candidates with questions and guidelines for producing video and upload in 10 days.&lt;br /&gt;
* 2019-08-24 - Email Reminder Membership Required to Vote&lt;br /&gt;
* 2019-08-30 - Deadline for interview recordings to be completed&lt;br /&gt;
* 2019-09-06 - Recordings posted on the election wiki page&lt;br /&gt;
* 2019-09-06 - Email/Social Media notifying the community the recordings are posted&lt;br /&gt;
* 2019-09-07 - Final Email Reminder Membership Required to Vote&lt;br /&gt;
* 2019-09-13 - Paid Membership Deadline&lt;br /&gt;
* 2019-09-16 - '''Voting opens'''&lt;br /&gt;
* 2019-10-16 - '''Voting closes'''&lt;br /&gt;
* 2019-10-17 - Results shared with all candidates (morning per US Eastern time)&lt;br /&gt;
* 2019-10-17 - Results shared via email and social media (evening per US Eastern time)&lt;br /&gt;
&lt;br /&gt;
== Notifying Email to Expiring Board Members ==&lt;br /&gt;
&lt;br /&gt;
Dear Board Member,&lt;br /&gt;
&lt;br /&gt;
As the 2019 Global Board of Directors election gets set to kick off this week, I wanted to reach out to you and thank you for all of the countless hours you have donated to the OWASP Foundation.  &lt;br /&gt;
&lt;br /&gt;
Come December 31, 2019 your term will be successfully fulfilled.  According to the OWASP Foundation Bylaws you are eligible to run again in the upcoming election should you choose to run for the open Board seats.&lt;br /&gt;
&lt;br /&gt;
Thank you again for your contributions in helping to improve the OWASP Foundation!&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ofer_Maor_2019_Bio_and_Why_me&amp;diff=254282</id>
		<title>Ofer Maor 2019 Bio and Why me</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ofer_Maor_2019_Bio_and_Why_me&amp;diff=254282"/>
				<updated>2019-08-28T18:37:06Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About Ofer==&lt;br /&gt;
I’m a passionate cybersecurity professional with 25 years of experience in the industry, 20 of which in the AppSec field. I’ve been part of OWASP for 17 years, (almost) since its inception, and I currently serve on its Board of Directors. I've also held multiple roles in OWASP, including Chapter Leader, Global AppSec Event Co-Chair, Global Committee Member and more... &lt;br /&gt;
&lt;br /&gt;
At the same time, I’ve also had the opportunity to work in various roles in the security industry, ranging from pen-testing, consulting, research, support, development, product management and all the way up to founding and managing several companies in this space. I’ve been a Breaker, a Builder and a Defender. I’ve been as hands-on and technical as it gets, but also had the chance to see how things operate on the larger scale.&lt;br /&gt;
&lt;br /&gt;
Deep inside, I’m still a (ethical) hacker at heart, and I’m still an idealist about the the notion of community and open source at large, and OWASP specifically, yet at the same time I understand how organizations operate and what they need to do to thrive, and I believe this balance is what I bring to the OWASP Board. Since the beginning of the year, I have worked with the foundation staff to help grow and improve OWASP so that it can better support the community. &lt;br /&gt;
&lt;br /&gt;
'''Today, after only a little over half a year on the board, I feel like we are starting to make a progress, and I would like to stay on the board to make sure that I can help drive those changes through.''' &lt;br /&gt;
&lt;br /&gt;
Link to my Video here: &lt;br /&gt;
&lt;br /&gt;
==Why Me?==&lt;br /&gt;
I’m passionate about OWASP, and especially about its community. I’ve been working with OWASP for a long time, and have always cared for it. I’ve met some of the best people along my professional career through the OWASP community, and many of them became long lasting friends. Through my entire time with OWASP, the community is what drives me forward, and driving this community forward is what I can bring to the table.&lt;br /&gt;
&lt;br /&gt;
OWASP is going through growing pains, that are natural at this time and place, yet still immensely challenging. OWASP has a growing financial pressure to support its growth, and at the same time has growing industry pressures, with vendors looking to influence the industry standards that it set. These pressures present great challenges for OWASP, both on the foundation and on the community, generating friction and frustration. Last year we’ve witnessed such a disconnect and miscommunication, which nearly ripped the community apart. During that time, I’ve worked with the board, the foundation and the community, to smooth things out, find the right solution, and prevent the rip.&lt;br /&gt;
&lt;br /&gt;
Seeing which challenges we are facing, and the contribution I can offer, made me join the board in the first place and do the best I can to contribute to OWASP. I would like to continue the work I have started so that we can truly turn the page onto OWASPs next chapter, making it a leading global organization in the cybersecurity industry. &lt;br /&gt;
===Focus===&lt;br /&gt;
I plan to continue focus on the fine balance between the community, the financial constraints and the industry as a whole, to make sure OWASP stays true to its spirit, yet is allowed to grows and evolve to its next phase, reaching new audiences and making a greater impact on the software industry as a whole.&lt;br /&gt;
&lt;br /&gt;
Some key areas I am already working on and plan on continuing:&lt;br /&gt;
*'''Membership''': I believe our current membership structure, both at the individual and corporate levels, makes it hard to increase membership revenue to the foundation, as it is not always clear what is the membership value.  As a board member I took upon myself to be the lead board member, working with the staff, on changing our membership models to make OWASP a more professional organization, run by its members and better supported by the corporates in our industry. Some of these changes have already been made and published, while others are still in work and are likely to take effect over the course of the next 12-18 months. &lt;br /&gt;
*'''Chapters''': Chapters are one of the two main pillars OWASP thrives upon. Without our chapters we have no audience and can reach no one. Yet our chapters are not all the same. Some chapters are run very well and reach a great audience, while others are struggling and failing to get traction. In my upcoming term, should I get elected, I plan to put more emphasize on helping chapters run more professionally and more consistently, giving our members and target audience a better, more consistent experience worldwide. &lt;br /&gt;
*'''Committees:''' I believe Global Committees can be a great way to drive more initiatives by people in community, who are eager to do more and need the right framework.  As a board member I supported initiatives that offer the community the framework to do more, especially around Chapters, Projects, and Education (and work to make sure they function better this time). &lt;br /&gt;
*'''Vendor Neutrality:''' Throughout my entire OWASP roles, I’ve always put great emphasize on vendor neutrality (despite working for one or another throughout this entire time). I believe the only way to keep OWASP relevant and valuable, is by making sure the content we produce in projects, conferences and education is neutral -  focusing on best practices and practical knowledge, and not on marketing pitches and sales activities.   As a board member I promise to vigorously fight against any attempt to externally influence OWASP as a whole, or any of its projects or conferences, in favor of specific vendor, whether it is financial gain or by taking control of an activity.&lt;br /&gt;
&lt;br /&gt;
=== Relevant Experience ===&lt;br /&gt;
I’ve been part of OWASP for 17 years, (almost) since its inception, and I’ve had the opportunity of being involved in various activities:&lt;br /&gt;
*I've been on the Global Board of OWASP since January 2019, serving as the Secretary of the Board. As part of this role I am working with the staff on driving changes both to corporate and individual membership, to help OWASP become more professional as well as stabilize its financials. I'm also working on driving other initiatives for making the board interactions and meetings more professional, delivering better outcomes. &lt;br /&gt;
*I've been the co-Chair of Global AppSec Tel Aviv that took place in 2019. We had a great turnaround of people and sponsors in a location that has never before had a Global AppSec Event. We've also managed to make Global AppSec Tel Aviv more inclusive than ever with over 30% female speakers!&lt;br /&gt;
*I’ve been on the board of OWASP Israel for 10 years, of which I was the chair for 4 years. During this time OWASP Israel has grown considerably and transformed from a small chapter with no funding (and a single board member) to one of the largest communities in OWASP with a proper board and volunteer base.&lt;br /&gt;
*For the past decade we’ve been running the OWASP AppSec IL conference every year, growing it from a half-day, single-track event with 90 attendees to a multi-day conference with trainings and over 700 attendees. Today, OWASP AppSec IL is one of the most attended OWASP events every year. I’ve had the chance of running the conference as a chair for several years and took on other roles later, including content committee (speaker selection), sponsorships (driving revenue to the conference), and more.&lt;br /&gt;
*I’ve also been part of the Global Membership Committee (before the committees were disassembled). In this role we drove initiatives to increase OWASP membership (and thus revenue) for both individuals and corporates.&lt;br /&gt;
Outside of OWASP, I’ve had the chance of working in various roles in the industry. I’ve also had the chance of founding and running my own companies – first an AppSec consulting company, followed by an AppSec product company (both later acquired and still alive). I’ve been on the Board of several companies (including a publicly traded company in NYSE/Euronext), and I’ve had the chance to define, manage and review budgets and financial management of companies.&lt;br /&gt;
&lt;br /&gt;
For more information about my professional experience you are welcome to visit my LinkedIn Profile: https://www.linkedin.com/in/ofermaor/&lt;br /&gt;
&lt;br /&gt;
You can also listen to my latest podcast recording from AppSec EU 2018 by Chris Romeo from the Application Security Podcast, where I share some of my history, my current work and my intention to run for the OWASP Board at: https://www.securityjourney.com/blog/a-pen-testers-transition-to-appsec-vote-for-ofer/&lt;br /&gt;
==Contact Me==&lt;br /&gt;
If you'd like to know more - feel free to reach out to me:&lt;br /&gt;
*Mail: ofer.maor@owasp.org&lt;br /&gt;
*Twitter: @OferMaor&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ofer_Maor_2019_Bio_and_Why_me&amp;diff=254263</id>
		<title>Ofer Maor 2019 Bio and Why me</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ofer_Maor_2019_Bio_and_Why_me&amp;diff=254263"/>
				<updated>2019-08-28T08:40:13Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: Created page with &amp;quot;==About Ofer== I’m a passionate cybersecurity professional with 25 years of experience in the industry, 20 of which in the AppSec field. I’ve been part of OWASP for 17 yea...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About Ofer==&lt;br /&gt;
I’m a passionate cybersecurity professional with 25 years of experience in the industry, 20 of which in the AppSec field. I’ve been part of OWASP for 17 years, (almost) since its inception, and I currently serve on its Board of Directors. I've also held multiple roles in OWASP, including Chapter Leader, Global AppSec Event Co-Chair, Global Committee Member and more... &lt;br /&gt;
&lt;br /&gt;
At the same time, I’ve also had the opportunity to work in various roles in the security industry, ranging from pen-testing, consulting, research, support, development, product management and all the way up to founding and managing several companies in this space. I’ve been a Breaker, a Builder and a Defender. I’ve been as hands-on and technical as it gets, but also had the chance to see how things operate on the larger scale.&lt;br /&gt;
&lt;br /&gt;
Deep inside, I’m still a (ethical) hacker at heart, and I’m still an idealist about the the notion of community and open source at large, and OWASP specifically, yet at the same time I understand how organizations operate and what they need to do to thrive, and I believe this balance is what I bring to the OWASP Board. Since the beginning of the year, I have worked with the foundation staff to help grow and improve OWASP so that it can better support the community. &lt;br /&gt;
&lt;br /&gt;
'''Today, after only a little over half a year on the board, I feel like we are starting to make a progress, and I would like to stay on the board to make sure that I can help drive those changes through.''' &lt;br /&gt;
&lt;br /&gt;
Link to my Video here: &lt;br /&gt;
&lt;br /&gt;
==Why Me?==&lt;br /&gt;
I’m passionate about OWASP, and especially about its community. I’ve been working with OWASP for a long time, and have always cared for it. I’ve met some of the best people along my professional career through the OWASP community, and many of them became long lasting friends. Through my entire time with OWASP, the community is what drives me forward, and driving this community forward is what I can bring to the table.&lt;br /&gt;
&lt;br /&gt;
Rather than &amp;quot;Why Me?&amp;quot;, someone recently asked me &amp;quot;Why Now?&amp;quot;. These questions are related. Over the course of 16 years with OWASP, the thought of submitting my candidacy for the board has crossed my mind several times. At times I felt there were already candidates with more experience than I had, at other times I was too occupied by running my own company to allow for the time commitment that the OWASP board entails, but I feel now is the right time where I can contribute the most.&lt;br /&gt;
&lt;br /&gt;
OWASP is going through growing pains, that are natural at this time and place, yet still immensely challenging. OWASP has a growing financial pressure to support its growth, and at the same time has growing industry pressures, with vendors looking to influence the industry standards that it set. These pressures present great challenges for OWASP, both on the foundation and on the community, generating friction and frustration. Last year we’ve witnessed such a disconnect and miscommunication, which nearly ripped the community apart. During that time, I’ve worked with the board, the foundation and the community, to smooth things out, find the right solution, and prevent the rip.&lt;br /&gt;
&lt;br /&gt;
Seeing which challenges we are facing, and the contribution I can offer, allowed me to make up my mind that now is the time and place for me to become part of the board, and do the best I can to contribute to OWASP.&lt;br /&gt;
===Focus===&lt;br /&gt;
I plan to focus on the fine balance between the community, the financial constraints and the industry as a whole, to make sure OWASP stays true to its spirit, yet is allowed to grows and evolve to its next phase, reaching new audiences and making a greater impact on the software industry as a whole.&lt;br /&gt;
&lt;br /&gt;
Some key areas I plan to focus on include:&lt;br /&gt;
*'''Chapters:''' I believe there’s room to reform the chapters structure – make it easier to kick off meetups and community activities, while reducing the administrative burden from the foundation.   As a board member I will initiate activities, together with the community, to find a more efficient structure that will serve us better.&lt;br /&gt;
*'''Membership''': I believe our current membership structure, both at the individual and corporate levels, makes it hard to increase membership revenue to the foundation, as it is not always clear what is the membership value.  As a board member I will work with the foundation and the community to build new membership offerings that could help increase membership revenue, while recognizing community contribution.&lt;br /&gt;
*'''Committees:''' I believe Global Committees can be a great way to drive more initiatives by people in community, who are eager to do more and need the right framework.  As a board member I will support initiatives that offer the community the framework to do more, especially around Chapters, Projects, and Education (and work to make sure they function better this time).&lt;br /&gt;
*'''Vendor Neutrality:''' Throughout my entire OWASP roles, I’ve always put great emphasize on vendor neutrality (despite working for one or another throughout this entire time). I believe the only way to keep OWASP relevant and valuable, is by making sure the content we produce in projects, conferences and education is neutral -  focusing on best practices and practical knowledge, and not on marketing pitches and sales activities.   As a board member I promise to vigorously fight against any attempt to externally influence OWASP as a whole, or any of its projects or conferences, in favor of specific vendor, whether it is financial gain or by taking control of an activity.&lt;br /&gt;
&lt;br /&gt;
=== Relevant Experience ===&lt;br /&gt;
I’ve been part of OWASP for 17 years, (almost) since its inception, and I’ve had the opportunity of being involved in various activities:&lt;br /&gt;
*I've been on the Global Board of OWASP since January 2019, serving as the Secretary of the Board. As part of this role I am working with the staff on driving changes both to corporate and individual membership, to help OWASP become more professional as well as stabilize its financials. I'm also working on driving other initiatives for making the board interactions and meetings more professional, delivering better outcomes. &lt;br /&gt;
*I've been the co-Chair of Global AppSec Tel Aviv that took place in 2019. We had a great turnaround of people and sponsors in a location that has never before had a Global AppSec Event. We've also managed to make Global AppSec Tel Aviv more inclusive than ever with over 30% female speakers!&lt;br /&gt;
*I’ve been on the board of OWASP Israel for 10 years, of which I was the chair for 4 years. During this time OWASP Israel has grown considerably and transformed from a small chapter with no funding (and a single board member) to one of the largest communities in OWASP with a proper board and volunteer base.&lt;br /&gt;
*For the past decade we’ve been running the OWASP AppSec IL conference every year, growing it from a half-day, single-track event with 90 attendees to a multi-day conference with trainings and over 700 attendees. Today, OWASP AppSec IL is one of the most attended OWASP events every year. I’ve had the chance of running the conference as a chair for several years and took on other roles later, including content committee (speaker selection), sponsorships (driving revenue to the conference), and more.&lt;br /&gt;
*I’ve also been part of the Global Membership Committee (before the committees were disassembled). In this role we drove initiatives to increase OWASP membership (and thus revenue) for both individuals and corporates.&lt;br /&gt;
Outside of OWASP, I’ve had the chance of working in various roles in the industry. I’ve also had the chance of founding and running my own companies – first an AppSec consulting company, followed by an AppSec product company (both later acquired and still alive). I’ve been on the Board of several companies (including a publicly traded company in NYSE/Euronext), and I’ve had the chance to define, manage and review budgets and financial management of companies.&lt;br /&gt;
&lt;br /&gt;
For more information about my professional experience you are welcome to visit my LinkedIn Profile: https://www.linkedin.com/in/ofermaor/&lt;br /&gt;
&lt;br /&gt;
You can also listen to my latest podcast recording from AppSec EU 2018 by Chris Romeo from the Application Security Podcast, where I share some of my history, my current work and my intention to run for the OWASP Board at: https://www.securityjourney.com/blog/a-pen-testers-transition-to-appsec-vote-for-ofer/&lt;br /&gt;
==Contact Me==&lt;br /&gt;
If you'd like to know more - feel free to reach out to me:&lt;br /&gt;
*Mail: ofer.maor@owasp.org&lt;br /&gt;
*Twitter: @OferMaor&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=August_2019&amp;diff=253725</id>
		<title>August 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=August_2019&amp;diff=253725"/>
				<updated>2019-08-14T13:27:57Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: added motion to update owasp board meetings&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
Meeting Date:&lt;br /&gt;
Aug 19&lt;br /&gt;
&lt;br /&gt;
Meeting Time:&lt;br /&gt;
11 AM US Pacific - [https://www.timeanddate.com/worldclock/meetingdetails.html?year=2019&amp;amp;month=8&amp;amp;day=19&amp;amp;hour=18&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=16&amp;amp;p2=919&amp;amp;p3=78&amp;amp;p4=136&amp;amp;p5=137&amp;amp;p6=676 other time zones]&lt;br /&gt;
&lt;br /&gt;
Meeting Location:&lt;br /&gt;
Remote&lt;br /&gt;
&lt;br /&gt;
Virtual: &lt;br /&gt;
[https://zoom.us/j/282821949 Zoom Meeting Link]  Meeting ID: 282 821 949 - [https://zoom.us/u/kvUg3969 local dial in numbers]&lt;br /&gt;
&lt;br /&gt;
 AGENDA&lt;br /&gt;
&lt;br /&gt;
 CALL TO ORDER&lt;br /&gt;
&lt;br /&gt;
 CHANGES TO THE AGENDA&lt;br /&gt;
&lt;br /&gt;
 APPROVAL OF MINUTES&lt;br /&gt;
 [https://docs.google.com/document/d/1uyvKi1yrisahNnZpT6cWUs6yMwje89PI2WvjhIMgkH4/edit?usp=sharing July 2019 Minutes]&lt;br /&gt;
&lt;br /&gt;
 REPORTS&lt;br /&gt;
&lt;br /&gt;
 OLD BUSINESS&lt;br /&gt;
&lt;br /&gt;
 NEW BUSINESS&lt;br /&gt;
 - Announce Board F2F Discussion regarding Director Criteria&lt;br /&gt;
&lt;br /&gt;
 COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS&lt;br /&gt;
&lt;br /&gt;
 ADJOURNMENT&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
Suggested updates to the board meeting guidelines:&lt;br /&gt;
* The OWASP Board will hold a public 1-Hour Board Meeting once a month.&lt;br /&gt;
* All board meetings will be held by Zoom video conference. All board members and staff members are required to participate with their Video on.&lt;br /&gt;
* Board meetings are generally scheduled to be on the third Tuesday of each month, at 11am Pacific / 2pm Eastern / 8pm Central Europe timeframe.&lt;br /&gt;
* Board meeting schedule may be changed to address scheduling issues such as holidays, alignment with Global AppSec Conferences, etc. Changes must be announced no later than 2 weeks before the board meeting.&lt;br /&gt;
* All OWASP Board Members must attend at least 75% of public board meetings.&lt;br /&gt;
* In addition to the public board meetings, OWASP Board will hold executive board meetings. These are designed to prepare the public board meetings as well as discuss OWASP Staff and other issues with associated privacy aspects. With the exception of issues with privacy aspects (such as staff salaries, etc.) - all suggested motions coming up in these meetings will be presented in the next public board meeting.&lt;br /&gt;
* To ensure smooth operations of OWASP Board, the board will hold twice a year 2-days face-to-face executive board meetings. These will be held during two days prior to the two large Global AppSec events, one in Europe and one in the USA. All board members must attend these meetings.&lt;br /&gt;
* In addition, each January, following the nomination of the new board, a 4 Hours, video-based meeting will take place to discuss the initiatives for the new year and get the new board up and running.&lt;br /&gt;
&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ofer_Maor&amp;diff=252920</id>
		<title>User:Ofer Maor</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ofer_Maor&amp;diff=252920"/>
				<updated>2019-07-09T18:34:23Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: /* Chapter Board, OWASP Israel */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== '''Ofer Maor''' ===&lt;br /&gt;
&lt;br /&gt;
==== '''Director, Solutions Management, Synopsys''' ====&lt;br /&gt;
&lt;br /&gt;
==== Member of the Board, OWASP ====&lt;br /&gt;
[[File:OferMaorProfile.jpg|thumb]]&lt;br /&gt;
A leading technology expert and entrepreneur with over 20 years of experience in information and application security. In the past two decades, I have been involved with a wide range of activities around information and application security, from hands on technology research, development, networking, IT and (ethical) hacking, through product building, strategy, marketing and sales, and all the way to M&amp;amp;A. In my current role I am part of an exciting journey with Synopsys (SNPS) to become the leader in Software Security &amp;amp; Quality through the acquisition and integration of various leading technologies and solutions in this space. &lt;br /&gt;
&lt;br /&gt;
Prior to Synopsys I founded several security technology companies, the latter acquired by Synopsys, and the rest were all acquired or are public to date. As Founder and CTO of Seeker, now acquired by Synopsys, I've pioneered IAST, the next generation of application security testing technology, currently used by some of the largest organizations in the world to continuously improve their software security. Prior to Seeker I was the Founder and CTO of Hacktics, a world-leading security services group, later acquired by Ernst &amp;amp; Young, and was previously the leader of Imperva's Application Defense Center research group.&lt;br /&gt;
&lt;br /&gt;
Over the past 15 years I have been involved with OWASP and its community, and was part of the journey of OWASP growing from a small initiative to the unquestionable standard in software security. Over the years I've been involved with multiple projects an activities within OWASP. I have served as the Chairman of OWASP Israel, and helped grow the Israeli community to over 1000 people, with over 500 attendees each year in our annual event. I've also served on the OWASP Global Membership Committee.   &lt;br /&gt;
&lt;br /&gt;
'''&amp;lt;u&amp;gt;Links:&amp;lt;/u&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
LinkedIn: https://www.linkedin.com/in/ofermaor/&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/OferMaor&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ofer_Maor_2018_Bio_and_Why_me&amp;diff=243381</id>
		<title>Ofer Maor 2018 Bio and Why me</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ofer_Maor_2018_Bio_and_Why_me&amp;diff=243381"/>
				<updated>2018-09-13T21:21:30Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: factual correction and spelling mistake.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== About Ofer ==&lt;br /&gt;
I’m a passionate cybersecurity professional with 25 years of experience in the industry, 20 of which in the AppSec field. I’ve been part of OWASP for 16 years, (almost) since its inception, and I’ve had the opportunity to take part of different activities and wear different hats with OWASP through those years, seeing how OWASP has grown and evolved over the years from a tiny idea to what drives the industry standard in application security today. &lt;br /&gt;
&lt;br /&gt;
At the same time, I’ve also had the opportunity to work in various roles in the security industry, ranging from pen-testing, consulting, research, support, development, product management and all the way up to founding and managing several companies in this space. I’ve been a Breaker, a Builder and a Defender. I’ve been as hands-on and technical as it gets, but also had the chance to see how things operate on the larger scale. &lt;br /&gt;
&lt;br /&gt;
Deep inside, I’m still a (ethical) hacker at heart, and I’m still an idealist about the the notion of community and open source at large, and OWASP specifically, yet at the same time I understand how organizations operate and what they need to do to thrive, and I believe this balance is what I can bring to the OWASP Board. I will strive to help the foundation to grow and improve so that it can better support the community which OWASP has always been and should be. I will work to keep this balance, so that OWASP can become even better than it is today.&lt;br /&gt;
&lt;br /&gt;
=== Experience ===&lt;br /&gt;
I’ve been part of OWASP for 16 years, (almost) since its inception, and I’ve had the opportunity of being involved in various activities:&lt;br /&gt;
* I’ve been on the board of OWASP Israel for 9 years, of which I was the chair for 4 years. During this time OWASP Israel has grown considerably and transformed from a small chapter with no funding (and a single board member) to one of the largest communities in OWASP with a proper board and volunteer base. &lt;br /&gt;
* For the past decade we’ve been running the OWASP AppSec IL conference every year, growing it from a half-day, single-track event with 90 attendees to a multi-day conference with trainings and over 700 attendees. Today, OWASP AppSec IL is one of the most attended OWASP events every year. I’ve had the chance of running the conference as a chair for several years and took on other roles later, including content committee (speaker selection), sponsorships (driving revenue to the conference), and more. &lt;br /&gt;
* I’ve also been part of the Global Membership Committee (before the committees were disassembled). In this role we drove initiatives to increase OWASP membership (and thus revenue) for both individuals and corporates.&lt;br /&gt;
&lt;br /&gt;
Outside of OWASP, I’ve had the chance of working in various roles in the industry. I’ve also had the chance of founding and running my own companies – first an AppSec consulting company, followed by an AppSec product company (both later acquired and still alive). I’ve been on the Board of several companies (including a publicly traded company in NYSE/Euronext), and I’ve had the chance to define, manage and review budgets and financial management of companies. &lt;br /&gt;
&lt;br /&gt;
For more information about my professional experience you are welcome to visit my LinkedIn Profile: https://www.linkedin.com/in/ofermaor/&lt;br /&gt;
&lt;br /&gt;
You can also listen to my latest podcast recording from AppSec EU 2018 by Chris Romeo from the Application Security Podcast, where I share some of my history, my current work and my intention to run for the OWASP Board at: https://www.securityjourney.com/blog/a-pen-testers-transition-to-appsec-vote-for-ofer/&lt;br /&gt;
&lt;br /&gt;
== Why Me? ==&lt;br /&gt;
I’m passionate about OWASP, and especially about its community. I’ve been working with OWASP for a long time, and have always cared for it. I’ve met some of the best people along my professional career through the OWASP community, and many of them became long lasting friends. Through my entire time with OWASP, the community is what drives me forward, and driving this community forward is what I can bring to the table.&lt;br /&gt;
&lt;br /&gt;
Rather than &amp;quot;Why Me?&amp;quot;, someone recently asked me &amp;quot;Why Now?&amp;quot;. These questions are related. Over the course of 16 years with OWASP, the thought of submitting my candidacy for the board has crossed my mind several times. At times I felt there were already candidates with more experience than I had, at other times I was too occupied by running my own company to allow for the time commitment that the OWASP board entails, but I feel now is the right time where I can contribute the most. &lt;br /&gt;
&lt;br /&gt;
OWASP is going through growing pains, that are natural at this time and place, yet still immensely challenging. OWASP has a growing financial pressure to support its growth, and at the same time has growing industry pressures, with vendors looking to influence the industry standards that it set. These pressures present great challenges for OWASP, both on the foundation and on the community, generating friction and frustration. Last year we’ve witnessed such a disconnect and miscommunication, which nearly ripped the community apart. During that time, I’ve worked with the board, the foundation and the community, to smooth things out, find the right solution, and prevent the rip. &lt;br /&gt;
&lt;br /&gt;
Seeing which challenges we are facing, and the contribution I can offer, allowed me to make up my mind that now is the time and place for me to become part of the board, and do the best I can to contribute to OWASP. &lt;br /&gt;
&lt;br /&gt;
=== Focus ===&lt;br /&gt;
I plan to focus on the fine balance between the community, the financial constraints and the industry as a whole, to make sure OWASP stays true to its spirit, yet is allowed to grows and evolve to its next phase, reaching new audiences and making a greater impact on the software industry as a whole. &lt;br /&gt;
&lt;br /&gt;
Some key areas I plan to focus on include:&lt;br /&gt;
* '''Chapters:''' I believe there’s room to reform the chapters structure – make it easier to kick off meetups and community activities, while reducing the administrative burden from the foundation.   As a board member I will initiate activities, together with the community, to find a more efficient structure that will serve us better.&lt;br /&gt;
* '''Membership''': I believe our current membership structure, both at the individual and corporate levels, makes it hard to increase membership revenue to the foundation, as it is not always clear what is the membership value.  As a board member I will work with the foundation and the community to build new membership offerings that could help increase membership revenue, while recognizing community contribution.  &lt;br /&gt;
* '''Committees:''' I believe Global Committees can be a great way to drive more initiatives by people in community, who are eager to do more and need the right framework.  As a board member I will support initiatives that offer the community the framework to do more, especially around Chapters, Projects, and Education (and work to make sure they function better this time). &lt;br /&gt;
* '''Vendor Neutrality:''' Throughout my entire OWASP roles, I’ve always put great emphasize on vendor neutrality (despite working for one or another throughout this entire time). I believe the only way to keep OWASP relevant and valuable, is by making sure the content we produce in projects, conferences and education is neutral -  focusing on best practices and practical knowledge, and not on marketing pitches and sales activities.   As a board member I promise to vigorously fight against any attempt to externally influence OWASP as a whole, or any of its projects or conferences, in favor of specific vendor, whether it is financial gain or by taking control of an activity.&lt;br /&gt;
&lt;br /&gt;
== Contact Me ==&lt;br /&gt;
If you'd like to know more - feel free to reach out to me:&lt;br /&gt;
* Mail: ofer.maor@owasp.org&lt;br /&gt;
* Twitter: @OferMaor&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ofer_Maor_2018_Bio_and_Why_me&amp;diff=243378</id>
		<title>Ofer Maor 2018 Bio and Why me</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ofer_Maor_2018_Bio_and_Why_me&amp;diff=243378"/>
				<updated>2018-09-13T20:41:28Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: Contact Me Info&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== About Ofer ==&lt;br /&gt;
I’m a passionate cybersecurity professional with 25 years of experience in the industry, 20 of which in the AppSec field. I’ve been part of OWASP for 16 years, (almost) since its inception, and I’ve had the opportunity to take part of different activities and wear different hats with OWASP through those years, seeing how OWASP has grown and evolved over the years from a tiny idea to what drives the industry standard in application security today. &lt;br /&gt;
&lt;br /&gt;
At the same time, I’ve also had the opportunity to work in various roles in the security industry, ranging from pen-testing, consulting, research, support, development, product management and all the way up to founding and managing several companies in this space. I’ve been a Breaker, a Builder and a Defender. I’ve been as hands-on and technical as it gets, but also had the chance to see how things operate on the larger scale. &lt;br /&gt;
&lt;br /&gt;
Deep inside, I’m still a (ethical) hacker at heart, and I’m still an idealist about the the notion of community and open source at large, and OWASP specifically, yet at the same time I understand how organizations operate and what they need to do to thrive, and I believe this balance is what I can bring to the OWASP Board. I will thrive to help the foundation to grow and improve so that it can better support the community which OWASP has always been and should be. I will work to keep this balance, so that OWASP can become even better than it is today.&lt;br /&gt;
&lt;br /&gt;
=== Experience ===&lt;br /&gt;
I’ve been part of OWASP for 16 years, (almost) since its inception, and I’ve had the opportunity of being involved in various activities:&lt;br /&gt;
* I’ve been on the board of OWASP Israel for 9 years, of which I was the chair for 4 years. During this time OWASP Israel has grown considerably and transformed from a small chapter with no funding (and a single board member) to one of the largest communities in OWASP with a proper board and volunteer base. &lt;br /&gt;
* For the past decade we’ve been running the OWASP AppSec IL conference every year, growing it from a single-day, single-track event with 100 attendees to a multi-day conference with trainings and over 700 attendees. Today, OWASP AppSec IL is one of the most attended OWASP events every year. I’ve had the chance of running the conference as a chair for several years and took on other roles later, including content committee (speaker selection), sponsorships (driving revenue to the conference), and more. &lt;br /&gt;
* I’ve also been part of the Global Membership Committee (before the committees were disassembled). In this role we drove initiatives to increase OWASP membership (and thus revenue) for both individuals and corporates.&lt;br /&gt;
&lt;br /&gt;
Outside of OWASP, I’ve had the chance of working in various roles in the industry. I’ve also had the chance of founding and running my own companies – first an AppSec consulting company, followed by an AppSec product company (both later acquired and still alive). I’ve been on the Board of several companies (including a publicly traded company in NYSE/Euronext), and I’ve had the chance to define, manage and review budgets and financial management of companies. &lt;br /&gt;
&lt;br /&gt;
For more information about my professional experience you are welcome to visit my LinkedIn Profile: https://www.linkedin.com/in/ofermaor/&lt;br /&gt;
&lt;br /&gt;
You can also listen to my latest podcast recording from AppSec EU 2018 by Chris Romeo from the Application Security Podcast, where I share some of my history, my current work and my intention to run for the OWASP Board at: https://www.securityjourney.com/blog/a-pen-testers-transition-to-appsec-vote-for-ofer/&lt;br /&gt;
&lt;br /&gt;
== Why Me? ==&lt;br /&gt;
I’m passionate about OWASP, and especially about its community. I’ve been working with OWASP for a long time, and have always cared for it. I’ve met some of the best people along my professional career through the OWASP community, and many of them became long lasting friends. Through my entire time with OWASP, the community is what drives me forward, and driving this community forward is what I can bring to the table.&lt;br /&gt;
&lt;br /&gt;
Rather than &amp;quot;Why Me?&amp;quot;, someone recently asked me &amp;quot;Why Now?&amp;quot;. These questions are related. Over the course of 16 years with OWASP, the thought of submitting my candidacy for the board has crossed my mind several times. At times I felt there were already candidates with more experience than I had, at other times I was too occupied by running my own company to allow for the time commitment that the OWASP board entails, but I feel now is the right time where I can contribute the most. &lt;br /&gt;
&lt;br /&gt;
OWASP is going through growing pains, that are natural at this time and place, yet still immensely challenging. OWASP has a growing financial pressure to support its growth, and at the same time has growing industry pressures, with vendors looking to influence the industry standards that it set. These pressures present great challenges for OWASP, both on the foundation and on the community, generating friction and frustration. Last year we’ve witnessed such a disconnect and miscommunication, which nearly ripped the community apart. During that time, I’ve worked with the board, the foundation and the community, to smooth things out, find the right solution, and prevent the rip. &lt;br /&gt;
&lt;br /&gt;
Seeing which challenges we are facing, and the contribution I can offer, allowed me to make up my mind that now is the time and place for me to become part of the board, and do the best I can to contribute to OWASP. &lt;br /&gt;
&lt;br /&gt;
=== Focus ===&lt;br /&gt;
I plan to focus on the fine balance between the community, the financial constraints and the industry as a whole, to make sure OWASP stays true to its spirit, yet is allowed to grows and evolve to its next phase, reaching new audiences and making a greater impact on the software industry as a whole. &lt;br /&gt;
&lt;br /&gt;
Some key areas I plan to focus on include:&lt;br /&gt;
* '''Chapters:''' I believe there’s room to reform the chapters structure – make it easier to kick off meetups and community activities, while reducing the administrative burden from the foundation.   As a board member I will initiate activities, together with the community, to find a more efficient structure that will serve us better.&lt;br /&gt;
* '''Membership''': I believe our current membership structure, both at the individual and corporate levels, makes it hard to increase membership revenue to the foundation, as it is not always clear what is the membership value.  As a board member I will work with the foundation and the community to build new membership offerings that could help increase membership revenue. &lt;br /&gt;
* '''Committees:''' I believe Global Committees can be a great way to drive more initiatives by people in community, who are eager to do more and need the right framework.  As a board member I will support initiatives that offer the community the framework to do more, especially around Chapters, Projects, and Education (and work to make sure they function better this time). &lt;br /&gt;
* '''Vendor Neutrality:''' Throughout my entire OWASP roles, I’ve always put great emphasize on vendor neutrality (despite working for one or another throughout this entire time). I believe the only way to keep OWASP relevant and valuable, is by making sure the content we produce in projects, conferences and education is neutral -  focusing on best practices and practical knowledge, and not on marketing pitches and sales activities.   As a board member I promise to vigorously fight against any attempt to externally influence OWASP as a whole, or any of its projects or conferences, in favor of specific vendor, whether it is financial gain or by taking control of an activity.&lt;br /&gt;
&lt;br /&gt;
== Contact Me ==&lt;br /&gt;
If you'd like to know more - feel free to reach out to me:&lt;br /&gt;
* Mail: ofer.maor@owasp.org&lt;br /&gt;
* Twitter: @OferMaor&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ofer_Maor_2018_Bio_and_Why_me&amp;diff=243377</id>
		<title>Ofer Maor 2018 Bio and Why me</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ofer_Maor_2018_Bio_and_Why_me&amp;diff=243377"/>
				<updated>2018-09-13T20:38:20Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: Recreated the page with my Board Candidacy information.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== About Ofer ==&lt;br /&gt;
I’m a passionate cybersecurity professional with 25 years of experience in the industry, 20 of which in the AppSec field. I’ve been part of OWASP for 16 years, (almost) since its inception, and I’ve had the opportunity to take part of different activities and wear different hats with OWASP through those years, seeing how OWASP has grown and evolved over the years from a tiny idea to what drives the industry standard in application security today. &lt;br /&gt;
&lt;br /&gt;
At the same time, I’ve also had the opportunity to work in various roles in the security industry, ranging from pen-testing, consulting, research, support, development, product management and all the way up to founding and managing several companies in this space. I’ve been a Breaker, a Builder and a Defender. I’ve been as hands-on and technical as it gets, but also had the chance to see how things operate on the larger scale. &lt;br /&gt;
&lt;br /&gt;
Deep inside, I’m still a (ethical) hacker at heart, and I’m still an idealist about the the notion of community and open source at large, and OWASP specifically, yet at the same time I understand how organizations operate and what they need to do to thrive, and I believe this balance is what I can bring to the OWASP Board. I will thrive to help the foundation to grow and improve so that it can better support the community which OWASP has always been and should be. I will work to keep this balance, so that OWASP can become even better than it is today.&lt;br /&gt;
&lt;br /&gt;
=== Experience ===&lt;br /&gt;
I’ve been part of OWASP for 16 years, (almost) since its inception, and I’ve had the opportunity of being involved in various activities:&lt;br /&gt;
* I’ve been on the board of OWASP Israel for 9 years, of which I was the chair for 4 years. During this time OWASP Israel has grown considerably and transformed from a small chapter with no funding (and a single board member) to one of the largest communities in OWASP with a proper board and volunteer base. &lt;br /&gt;
* For the past decade we’ve been running the OWASP AppSec IL conference every year, growing it from a single-day, single-track event with 100 attendees to a multi-day conference with trainings and over 700 attendees. Today, OWASP AppSec IL is one of the most attended OWASP events every year. I’ve had the chance of running the conference as a chair for several years and took on other roles later, including content committee (speaker selection), sponsorships (driving revenue to the conference), and more. &lt;br /&gt;
* I’ve also been part of the Global Membership Committee (before the committees were disassembled). In this role we drove initiatives to increase OWASP membership (and thus revenue) for both individuals and corporates.&lt;br /&gt;
&lt;br /&gt;
Outside of OWASP, I’ve had the chance of working in various roles in the industry. I’ve also had the chance of founding and running my own companies – first an AppSec consulting company, followed by an AppSec product company (both later acquired and still alive). I’ve been on the Board of several companies (including a publicly traded company in NYSE/Euronext), and I’ve had the chance to define, manage and review budgets and financial management of companies. &lt;br /&gt;
&lt;br /&gt;
For more information about my professional experience you are welcome to visit my LinkedIn Profile: https://www.linkedin.com/in/ofermaor/&lt;br /&gt;
&lt;br /&gt;
You can also listen to my latest podcast recording from AppSec EU 2018 by Chris Romeo from the Application Security Podcast, where I share some of my history, my current work and my intention to run for the OWASP Board at: https://www.securityjourney.com/blog/a-pen-testers-transition-to-appsec-vote-for-ofer/&lt;br /&gt;
&lt;br /&gt;
== Why Me? ==&lt;br /&gt;
I’m passionate about OWASP, and especially about its community. I’ve been working with OWASP for a long time, and have always cared for it. I’ve met some of the best people along my professional career through the OWASP community, and many of them became long lasting friends. Through my entire time with OWASP, the community is what drives me forward, and driving this community forward is what I can bring to the table.&lt;br /&gt;
&lt;br /&gt;
Rather than &amp;quot;Why Me?&amp;quot;, someone recently asked me &amp;quot;Why Now?&amp;quot;. These questions are related. Over the course of 16 years with OWASP, the thought of submitting my candidacy for the board has crossed my mind several times. At times I felt there were already candidates with more experience than I had, at other times I was too occupied by running my own company to allow for the time commitment that the OWASP board entails, but I feel now is the right time where I can contribute the most. &lt;br /&gt;
&lt;br /&gt;
OWASP is going through growing pains, that are natural at this time and place, yet still immensely challenging. OWASP has a growing financial pressure to support its growth, and at the same time has growing industry pressures, with vendors looking to influence the industry standards that it set. These pressures present great challenges for OWASP, both on the foundation and on the community, generating friction and frustration. Last year we’ve witnessed such a disconnect and miscommunication, which nearly ripped the community apart. During that time, I’ve worked with the board, the foundation and the community, to smooth things out, find the right solution, and prevent the rip. &lt;br /&gt;
&lt;br /&gt;
Seeing which challenges we are facing, and the contribution I can offer, allowed me to make up my mind that now is the time and place for me to become part of the board, and do the best I can to contribute to OWASP. &lt;br /&gt;
&lt;br /&gt;
=== Focus ===&lt;br /&gt;
I plan to focus on the fine balance between the community, the financial constraints and the industry as a whole, to make sure OWASP stays true to its spirit, yet is allowed to grows and evolve to its next phase, reaching new audiences and making a greater impact on the software industry as a whole. &lt;br /&gt;
&lt;br /&gt;
Some key areas I plan to focus on include:&lt;br /&gt;
* '''Chapters:''' I believe there’s room to reform the chapters structure – make it easier to kick off meetups and community activities, while reducing the administrative burden from the foundation.   As a board member I will initiate activities, together with the community, to find a more efficient structure that will serve us better.&lt;br /&gt;
* '''Membership''': I believe our current membership structure, both at the individual and corporate levels, makes it hard to increase membership revenue to the foundation, as it is not always clear what is the membership value.  As a board member I will work with the foundation and the community to build new membership offerings that could help increase membership revenue. &lt;br /&gt;
* '''Committees:''' I believe Global Committees can be a great way to drive more initiatives by people in community, who are eager to do more and need the right framework.  As a board member I will support initiatives that offer the community the framework to do more, especially around Chapters, Projects, and Education (and work to make sure they function better this time). &lt;br /&gt;
* '''Vendor Neutrality:''' Throughout my entire OWASP roles, I’ve always put great emphasize on vendor neutrality (despite working for one or another throughout this entire time). I believe the only way to keep OWASP relevant and valuable, is by making sure the content we produce in projects, conferences and education is neutral -  focusing on best practices and practical knowledge, and not on marketing pitches and sales activities.   As a board member I promise to vigorously fight against any attempt to externally influence OWASP as a whole, or any of its projects or conferences, in favor of specific vendor, whether it is financial gain or by taking control of an activity.&lt;br /&gt;
&lt;br /&gt;
If you'd like to know more - feel free to reach out to me through my email at OWASP (ofer.maor@owasp.org) or my Twitter (@OferMaor)&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ofer_Maor&amp;diff=241752</id>
		<title>User:Ofer Maor</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ofer_Maor&amp;diff=241752"/>
				<updated>2018-07-10T15:40:56Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: added line space&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== '''Ofer Maor''' ===&lt;br /&gt;
&lt;br /&gt;
==== '''Director, Solutions Management, Synopsys''' ====&lt;br /&gt;
&lt;br /&gt;
==== Chapter Board, OWASP Israel ====&lt;br /&gt;
[[File:OferMaorProfile.jpg|thumb]]&lt;br /&gt;
A leading technology expert and entrepreneur with over 20 years of experience in information and application security. In the past two decades, I have been involved with a wide range of activities around information and application security, from hands on technology research, development, networking, IT and (ethical) hacking, through product building, strategy, marketing and sales, and all the way to M&amp;amp;A. In my current role I am part of an exciting journey with Synopsys (SNPS) to become the leader in Software Security &amp;amp; Quality through the acquisition and integration of various leading technologies and solutions in this space. &lt;br /&gt;
&lt;br /&gt;
Prior to Synopsys I founded several security technology companies, the latter acquired by Synopsys, and the rest were all acquired or are public to date. As Founder and CTO of Seeker, now acquired by Synopsys, I've pioneered IAST, the next generation of application security testing technology, currently used by some of the largest organizations in the world to continuously improve their software security. Prior to Seeker I was the Founder and CTO of Hacktics, a world-leading security services group, later acquired by Ernst &amp;amp; Young, and was previously the leader of Imperva's Application Defense Center research group.&lt;br /&gt;
&lt;br /&gt;
Over the past 15 years I have been involved with OWASP and its community, and was part of the journey of OWASP growing from a small initiative to the unquestionable standard in software security. Over the years I've been involved with multiple projects an activities within OWASP. I have served as the Chairman of OWASP Israel, and helped grow the Israeli community to over 1000 people, with over 500 attendees each year in our annual event. I've also served on the OWASP Global Membership Committee.   &lt;br /&gt;
&lt;br /&gt;
'''&amp;lt;u&amp;gt;Links:&amp;lt;/u&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
LinkedIn: https://www.linkedin.com/in/ofermaor/&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/OferMaor&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ofer_Maor&amp;diff=241751</id>
		<title>User:Ofer Maor</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ofer_Maor&amp;diff=241751"/>
				<updated>2018-07-10T15:40:30Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: Added Links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== '''Ofer Maor''' ===&lt;br /&gt;
&lt;br /&gt;
==== '''Director, Solutions Management, Synopsys''' ====&lt;br /&gt;
&lt;br /&gt;
==== Chapter Board, OWASP Israel ====&lt;br /&gt;
[[File:OferMaorProfile.jpg|thumb]]&lt;br /&gt;
A leading technology expert and entrepreneur with over 20 years of experience in information and application security. In the past two decades, I have been involved with a wide range of activities around information and application security, from hands on technology research, development, networking, IT and (ethical) hacking, through product building, strategy, marketing and sales, and all the way to M&amp;amp;A. In my current role I am part of an exciting journey with Synopsys (SNPS) to become the leader in Software Security &amp;amp; Quality through the acquisition and integration of various leading technologies and solutions in this space. &lt;br /&gt;
&lt;br /&gt;
Prior to Synopsys I founded several security technology companies, the latter acquired by Synopsys, and the rest were all acquired or are public to date. As Founder and CTO of Seeker, now acquired by Synopsys, I've pioneered IAST, the next generation of application security testing technology, currently used by some of the largest organizations in the world to continuously improve their software security. Prior to Seeker I was the Founder and CTO of Hacktics, a world-leading security services group, later acquired by Ernst &amp;amp; Young, and was previously the leader of Imperva's Application Defense Center research group.&lt;br /&gt;
&lt;br /&gt;
Over the past 15 years I have been involved with OWASP and its community, and was part of the journey of OWASP growing from a small initiative to the unquestionable standard in software security. Over the years I've been involved with multiple projects an activities within OWASP. I have served as the Chairman of OWASP Israel, and helped grow the Israeli community to over 1000 people, with over 500 attendees each year in our annual event. I've also served on the OWASP Global Membership Committee. &lt;br /&gt;
&lt;br /&gt;
'''&amp;lt;u&amp;gt;Links:&amp;lt;/u&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
LinkedIn: https://www.linkedin.com/in/ofermaor/&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/OferMaor&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ofer_Maor&amp;diff=241748</id>
		<title>User:Ofer Maor</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ofer_Maor&amp;diff=241748"/>
				<updated>2018-07-10T15:37:49Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: Updated Title, Bio and Headhost&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== '''Ofer Maor''' ===&lt;br /&gt;
&lt;br /&gt;
==== '''Director, Solutions Management, Synopsys''' ====&lt;br /&gt;
&lt;br /&gt;
==== Chapter Board, OWASP Israel ====&lt;br /&gt;
[[File:OferMaorProfile.jpg|thumb]]&lt;br /&gt;
A leading technology expert and entrepreneur with over 20 years of experience in information and application security. In the past two decades, I have been involved with a wide range of activities around information and application security, from hands on technology research, development, networking, IT and (ethical) hacking, through product building, strategy, marketing and sales, and all the way to M&amp;amp;A. In my current role I am part of an exciting journey with Synopsys (SNPS) to become the leader in Software Security &amp;amp; Quality through the acquisition and integration of various leading technologies and solutions in this space. &lt;br /&gt;
&lt;br /&gt;
Prior to Synopsys I founded several security technology companies, the latter acquired by Synopsys, and the rest were all acquired or are public to date. As Founder and CTO of Seeker, now acquired by Synopsys, I've pioneered IAST, the next generation of application security testing technology, currently used by some of the largest organizations in the world to continuously improve their software security. Prior to Seeker I was the Founder and CTO of Hacktics, a world-leading security services group, later acquired by Ernst &amp;amp; Young, and was previously the leader of Imperva's Application Defense Center research group.&lt;br /&gt;
&lt;br /&gt;
Over the past 15 years I have been involved with OWASP and its community, and was part of the journey of OWASP growing from a small initiative to the unquestionable standard in software security. Over the years I've been involved with multiple projects an activities within OWASP. I have served as the Chairman of OWASP Israel, and helped grow the Israeli community to over 1000 people, with over 500 attendees each year in our annual event. I've also served on the OWASP Global Membership Committee&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OferMaorProfile.jpg&amp;diff=241744</id>
		<title>File:OferMaorProfile.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OferMaorProfile.jpg&amp;diff=241744"/>
				<updated>2018-07-10T15:27:51Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Ofer Maor Profile Picture&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Appendix_A:_Testing_Tools&amp;diff=168076</id>
		<title>Appendix A: Testing Tools</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Appendix_A:_Testing_Tools&amp;diff=168076"/>
				<updated>2014-02-13T14:02:40Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:OWASP Testing Guide v4}}&lt;br /&gt;
&lt;br /&gt;
==Open Source Black Box Testing tools==&lt;br /&gt;
&lt;br /&gt;
=== General Testing ===&lt;br /&gt;
&lt;br /&gt;
* '''[[OWASP_WebScarab_Project|OWASP WebScarab]]'''&lt;br /&gt;
** WebScarab is a framework for analysing applications that communicate using the HTTP and HTTPS protocols. It is written in Java, and is thus portable to many platforms. WebScarab has several modes of operation, implemented by a number of plugins.&lt;br /&gt;
* '''[[OWASP_CAL9000_Project|OWASP CAL9000]]'''&lt;br /&gt;
** CAL9000 is a collection of browser-based tools that enable more effective and efficient manual testing efforts.&lt;br /&gt;
** Includes an XSS Attack Library, Character Encoder/Decoder, HTTP Request Generator and Response Evaluator, Testing Checklist, Automated Attack Editor and much more.&lt;br /&gt;
*  '''[[:Category:OWASP Pantera Web Assessment Studio Project|OWASP Pantera Web Assessment Studio Project]]'''&lt;br /&gt;
** Pantera uses an improved version of SpikeProxy to provide a powerful web application analysis engine. The primary goal of Pantera is to combine automated capabilities with complete manual testing to get the best penetration testing results.&lt;br /&gt;
* '''[[:OWASP Zed Attack Proxy Project]]'''&lt;br /&gt;
** The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing.&lt;br /&gt;
** ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.&lt;br /&gt;
* '''[[:OWASP Mantra - Security Framework]]'''&lt;br /&gt;
**Mantra is a web application security testing framework built on top of a browser. It supports Windows, Linux(both 32 and 64 bit) and Macintosh, in addition, it can work with other software like ZAP using built in proxy management function which makes it much more convenient. Mantra is available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish.&lt;br /&gt;
* '''SPIKE''' - http://www.immunitysec.com/resources-freesoftware.shtml&lt;br /&gt;
** SPIKE designed to analyze new network protocols for buffer overflows or similar weaknesses. It requires a strong knowledge of C to use and only available for the Linux platform.&lt;br /&gt;
* '''Burp Proxy''' - http://www.portswigger.net/Burp/&lt;br /&gt;
** Burp Proxy is an intercepting proxy server for security testing of web applications it allows Intercepting and modifying all HTTP/S traffic passing in both directions, it can work with custom SSL certificates and non-proxy-aware clients.&lt;br /&gt;
* '''Odysseus Proxy''' - http://www.wastelands.gen.nz/odysseus/&lt;br /&gt;
** Odysseus is a proxy server, which acts as a man-in-the-middle during an HTTP session. A typical HTTP proxy will relay packets to and from a client browser and a web server. It will intercept an HTTP session's data in either direction.&lt;br /&gt;
* '''Webstretch Proxy''' - http://sourceforge.net/projects/webstretch&lt;br /&gt;
** Webstretch Proxy enable users to view and alter all aspects of communications with a web site via a proxy. It can also be used for debugging during development. &lt;br /&gt;
*  '''WATOBO''' - http://sourceforge.net/apps/mediawiki/watobo/index.php?title=Main_Page&lt;br /&gt;
** WATOBO works like a local proxy, similar to Webscarab, ZAP or BurpSuite and it supports passive and active checks.&lt;br /&gt;
* '''Firefox LiveHTTPHeaders''' - https://addons.mozilla.org/en-US/firefox/addon/live-http-headers/&lt;br /&gt;
** View HTTP headers of a page and while browsing.&lt;br /&gt;
* '''Firefox Tamper Data''' - https://addons.mozilla.org/en-US/firefox/addon/tamper-data/&lt;br /&gt;
** Use tamperdata to view and modify HTTP/HTTPS headers and post parameters&lt;br /&gt;
* '''Firefox Web Developer Tools''' - https://addons.mozilla.org/en-US/firefox/addon/web-developer/&lt;br /&gt;
** The Web Developer extension adds various web developer tools to the browser.&lt;br /&gt;
* '''DOM Inspector''' - https://developer.mozilla.org/en/docs/DOM_Inspector&lt;br /&gt;
**  DOM Inspector is a developer tool used to inspect, browse, and edit the Document Object Model (DOM)&lt;br /&gt;
* '''Firefox Firebug''' - http://getfirebug.com/&lt;br /&gt;
** Firebug integrates with Firefox to edit, debug, and monitor CSS, HTML, and JavaScript.&lt;br /&gt;
* '''Grendel-Scan''' - http://securitytube-tools.net/index.php?title=Grendel_Scan&lt;br /&gt;
** Grendel-Scan is an automated security scanning of web applications and also supports manual penetration testing.&lt;br /&gt;
*  '''OWASP SWFIntruder''' - http://www.mindedsecurity.com/swfintruder.html&lt;br /&gt;
** SWFIntruder (pronounced Swiff Intruder) is the first tool specifically developed for analyzing and testing security of Flash applications at runtime.&lt;br /&gt;
* '''SWFScan''' - http://h30499.www3.hp.com/t5/Following-the-Wh1t3-Rabbit/SWFScan-FREE-Flash-decompiler/ba-p/5440167 &lt;br /&gt;
** Flash decompiler&lt;br /&gt;
*  '''Wikto''' - http://www.sensepost.com/labs/tools/pentest/wikto&lt;br /&gt;
** Wikto features including fuzzy logic error code checking, a back-end miner, Google-assisted directory mining and real time HTTP request/response monitoring.&lt;br /&gt;
* '''w3af''' - http://w3af.org&lt;br /&gt;
** w3af is a Web Application Attack and Audit Framework. The project’s goal is finding and exploiting web application vulnerabilities.&lt;br /&gt;
* '''skipfish''' - http://code.google.com/p/skipfish/&lt;br /&gt;
** Skipfish is an active web application security reconnaissance tool.&lt;br /&gt;
* '''Web Developer toolbar''' - https://chrome.google.com/webstore/detail/bfbameneiokkgbdmiekhjnmfkcnldhhm&lt;br /&gt;
** The Web Developer extension adds a toolbar button to the browser with various web developer tools. This is the official port of the Web Developer extension for Firefox.&lt;br /&gt;
** '''HTTP Request Maker''' - https://chrome.google.com/webstore/detail/kajfghlhfkcocafkcjlajldicbikpgnp?hl=en-US&lt;br /&gt;
* Request Maker is a tool for penetration testing. With it you can easily capture requests made by web pages, tamper with the URL, headers and POST data and, of course, make new requests&lt;br /&gt;
** '''Cookie Editor''' - https://chrome.google.com/webstore/detail/fngmhnnpilhplaeedifhccceomclgfbg?hl=en-US&lt;br /&gt;
* Edit This Cookie is a cookie manager. You can add, delete, edit, search, protect and block cookies&lt;br /&gt;
** '''Cookie swap''' - https://chrome.google.com/webstore/detail/dffhipnliikkblkhpjapbecpmoilcama?hl=en-US&lt;br /&gt;
* Swap My Cookies is a session manager, it manages cookies, letting you login on any website with several different accounts. &lt;br /&gt;
** '''Firebug lite for Chrome&amp;quot;&amp;quot; -  https://chrome.google.com/webstore/detail/bmagokdooijbeehmkpknfglimnifench&lt;br /&gt;
*Firebug Lite is not a substitute for Firebug, or Chrome Developer Tools. It is a tool to be used in conjunction with these tools. Firebug Lite provides the rich visual representation we are used to see in Firebug when it comes to HTML elements, DOM elements, and Box Model shading. It provides also some cool features like inspecting HTML elemements with your mouse, and live editing CSS properties&lt;br /&gt;
** '''Session Manager&amp;quot;&amp;quot; -  https://chrome.google.com/webstore/detail/bbcnbpafconjjigibnhbfmmgdbbkcjfi&lt;br /&gt;
*With Session Manager you can quickly save your current browser state and reload it whenever necessary. You can manage multiple sessions, rename or remove them from the session library. Each session remembers the state of the browser at its creation time, i.e the opened tabs and windows.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Testing for specific vulnerabilities ===&lt;br /&gt;
&lt;br /&gt;
==== Testing for DOM XSS ====&lt;br /&gt;
* DOMinator Pro - https://dominator.mindedsecurity.com&lt;br /&gt;
&lt;br /&gt;
==== Testing AJAX ====&lt;br /&gt;
* '''[[:Category:OWASP Sprajax Project|OWASP Sprajax Project]]'''&lt;br /&gt;
==== Testing for SQL Injection ====&lt;br /&gt;
* '''[[:Category:OWASP_SQLiX_Project|OWASP SQLiX]]'''&lt;br /&gt;
* Sqlninja: a SQL Server Injection &amp;amp; Takeover Tool - http://sqlninja.sourceforge.net&lt;br /&gt;
* Bernardo Damele A. G.: sqlmap, automatic SQL injection tool - http://sqlmap.org/&lt;br /&gt;
* Absinthe 1.1 (formerly SQLSqueal) - http://sourceforge.net/projects/absinthe/&lt;br /&gt;
* SQLInjector - Uses inference techniques to extract data and determine the backend database server.  http://www.databasesecurity.com/sql-injector.htm&lt;br /&gt;
* Bsqlbf-v2: A perl script allows extraction of data from Blind SQL Injections - http://code.google.com/p/bsqlbf-v2/&lt;br /&gt;
* Pangolin: An automatic SQL injection penetration testing tool - http://www.darknet.org.uk/2009/05/pangolin-automatic-sql-injection-tool/&lt;br /&gt;
* Antonio Parata: Dump Files by sql inference on Mysql - SqlDumper - http://www.ruizata.com/&lt;br /&gt;
* Multiple DBMS Sql Injection tool - SQL Power Injector - http://www.sqlpowerinjector.com/&lt;br /&gt;
* MySql Blind Injection Bruteforcing, Reversing.org - sqlbftools - http://packetstormsecurity.org/files/43795/sqlbftools-1.2.tar.gz.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Testing Oracle ====&lt;br /&gt;
* TNS Listener tool (Perl) - http://www.jammed.com/%7Ejwa/hacks/security/tnscmd/tnscmd-doc.html&lt;br /&gt;
* Toad for Oracle - http://www.quest.com/toad &lt;br /&gt;
==== Testing SSL ====&lt;br /&gt;
* Foundstone SSL Digger - http://www.mcafee.com/us/downloads/free-tools/ssldigger.aspx&lt;br /&gt;
==== Testing for Brute Force Password ====&lt;br /&gt;
* THC Hydra - http://www.thc.org/thc-hydra/&lt;br /&gt;
* John the Ripper - http://www.openwall.com/john/&lt;br /&gt;
* Brutus - http://www.hoobie.net/brutus/ &lt;br /&gt;
* Medusa - http://www.foofus.net/~jmk/medusa/medusa.html&lt;br /&gt;
*Ncat - http://nmap.org/ncat/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Testing Buffer Overflow ====&lt;br /&gt;
*  OllyDbg - http://www.ollydbg.de&lt;br /&gt;
** &amp;quot;A windows based debugger used for analyzing buffer overflow vulnerabilities&amp;quot;&lt;br /&gt;
* Spike - http://www.immunitysec.com/downloads/SPIKE2.9.tgz&lt;br /&gt;
** A fuzzer framework that can be used to explore vulnerabilities and perform length testing&lt;br /&gt;
* Brute Force Binary Tester (BFB) - http://bfbtester.sourceforge.net&lt;br /&gt;
** A proactive binary checker&lt;br /&gt;
&lt;br /&gt;
[[Category:FIXME|link not working&lt;br /&gt;
&lt;br /&gt;
* Metasploit - http://www.metasploit.com/projects/Framework/&lt;br /&gt;
** A rapid exploit development and Testing frame work&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
]]&lt;br /&gt;
==== Fuzzer  ====&lt;br /&gt;
* '''[[:Category:OWASP_WSFuzzer_Project|OWASP WSFuzzer]]'''&lt;br /&gt;
* Wfuzz - http://www.darknet.org.uk/2007/07/wfuzz-a-tool-for-bruteforcingfuzzing-web-applications/&lt;br /&gt;
&lt;br /&gt;
==== Googling ====&lt;br /&gt;
* Stach &amp;amp; Liu's Google Hacking Diggity Project - http://www.stachliu.com/resources/tools/google-hacking-diggity-project/&lt;br /&gt;
* Foundstone Sitedigger (Google cached fault-finding) - http://www.mcafee.com/us/downloads/free-tools/sitedigger.aspx&lt;br /&gt;
&lt;br /&gt;
==Commercial Black Box Testing tools==&lt;br /&gt;
&lt;br /&gt;
* NGS Typhon III - http://www.nccgroup.com/en/our-services/security-testing-audit-compliance/information-security-software/ngs-typhon-iii/&lt;br /&gt;
* NGSSQuirreL - http://www.nccgroup.com/en/our-services/security-testing-audit-compliance/information-security-software/ngs-squirrel-vulnerability-scanners/&lt;br /&gt;
* IBM AppScan - http://www-01.ibm.com/software/awdtools/appscan/&lt;br /&gt;
* Cenzic Hailstorm - http://www.cenzic.com/products_services/cenzic_hailstorm.php&lt;br /&gt;
* Burp Intruder - http://www.portswigger.net/burp/intruder.html&lt;br /&gt;
* Acunetix Web Vulnerability Scanner - http://www.acunetix.com&lt;br /&gt;
* Sleuth - http://www.sandsprite.com&lt;br /&gt;
* NT Objectives NTOSpider - http://www.ntobjectives.com/products/ntospider.php&lt;br /&gt;
* MaxPatrol Security Scanner - http://www.maxpatrol.com&lt;br /&gt;
* Ecyware GreenBlue Inspector - http://www.ecyware.com&lt;br /&gt;
* Parasoft SOAtest (more QA-type tool)- http://www.parasoft.com/jsp/products/soatest.jsp?itemId=101&lt;br /&gt;
* MatriXay - http://www.dbappsecurity.com/webscan.html&lt;br /&gt;
* N-Stalker Web Application Security Scanner - http://www.nstalker.com&lt;br /&gt;
* HP WebInspect - http://www.hpenterprisesecurity.com/products/hp-fortify-software-security-center/hp-webinspect&lt;br /&gt;
* SoapUI (Web Service security testing) - http://www.soapui.org/Security/getting-started.html&lt;br /&gt;
* Netsparker - http://www.mavitunasecurity.com/netsparker/&lt;br /&gt;
* SAINT - http://www.saintcorporation.com/&lt;br /&gt;
* QualysGuard WAS - http://www.qualys.com/enterprises/qualysguard/web-application-scanning/&lt;br /&gt;
* Retina Web - http://www.eeye.com/Products/Retina/Web-Security-Scanner.aspx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:FIXME|check these links&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Cenzic Hailstorm - http://www.cenzic.com/products_services/cenzic_hailstorm.php&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
link broken:&lt;br /&gt;
&lt;br /&gt;
* ScanDo - http://www.kavado.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
]]&lt;br /&gt;
&lt;br /&gt;
==Source Code Analyzers==&lt;br /&gt;
&lt;br /&gt;
===Open Source / Freeware===&lt;br /&gt;
* [[:Category:OWASP_Orizon_Project|Owasp Orizon]]&lt;br /&gt;
* '''[[:Category:OWASP_LAPSE_Project|OWASP LAPSE]]''' &lt;br /&gt;
* [[OWASP O2 Platform]]&lt;br /&gt;
* Google CodeSearchDiggity - http://www.stachliu.com/resources/tools/google-hacking-diggity-project/attack-tools/&lt;br /&gt;
* PMD - http://pmd.sourceforge.net/&lt;br /&gt;
* FlawFinder - http://www.dwheeler.com/flawfinder&lt;br /&gt;
* Microsoft’s [[FxCop]]&lt;br /&gt;
* Splint - http://splint.org&lt;br /&gt;
* Boon - http://www.cs.berkeley.edu/~daw/boon&lt;br /&gt;
* FindBugs - http://findbugs.sourceforge.net&lt;br /&gt;
* Oedipus - http://www.darknet.org.uk/2006/06/oedipus-open-source-web-application-security-analysis/&lt;br /&gt;
* W3af - http://w3af.sourceforge.net/&lt;br /&gt;
&lt;br /&gt;
[[Category:FIXME|broken link&lt;br /&gt;
&lt;br /&gt;
* Pscan - http://www.striker.ottawa.on.ca/~aland/pscan&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
]]&lt;br /&gt;
&lt;br /&gt;
===Commercial ===&lt;br /&gt;
&lt;br /&gt;
* Armorize CodeSecure - http://www.armorize.com/index.php?link_id=codesecure&lt;br /&gt;
* Parasoft C/C++ test - http://www.parasoft.com/jsp/products/cpptest.jsp/index.htm&lt;br /&gt;
* Checkmarx CxSuite  - http://www.checkmarx.com&lt;br /&gt;
* HP Fortify - http://www.hpenterprisesecurity.com/products/hp-fortify-software-security-center/hp-fortify-static-code-analyzer&lt;br /&gt;
* GrammaTech - http://www.grammatech.com&lt;br /&gt;
* ITS4 - http://seclab.cs.ucdavis.edu/projects/testing/tools/its4.html&lt;br /&gt;
* Appscan - http://www-01.ibm.com/software/rational/products/appscan/source/&lt;br /&gt;
* ParaSoft - http://www.parasoft.com&lt;br /&gt;
* Virtual Forge CodeProfiler for ABAP - http://www.virtualforge.de&lt;br /&gt;
* Veracode - http://www.veracode.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:FIXME|link not working&lt;br /&gt;
&lt;br /&gt;
* Armorize CodeSecure - http://www.armorize.com/product/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
]]&lt;br /&gt;
&lt;br /&gt;
==Acceptance Testing Tools==&lt;br /&gt;
Acceptance testing tools are used to validate the functionality of web applications.  Some follow a scripted approach and typically make use of a Unit Testing framework to construct test suites and test cases.  Most, if not all, can be adapted to perform security specific tests in addition to functional tests.&lt;br /&gt;
&lt;br /&gt;
===Open Source Tools===&lt;br /&gt;
&lt;br /&gt;
* WATIR - http://wtr.rubyforge.org&lt;br /&gt;
** A Ruby based web testing framework that provides an interface into Internet Explorer.&lt;br /&gt;
** Windows only.&lt;br /&gt;
* HtmlUnit - http://htmlunit.sourceforge.net &lt;br /&gt;
** A Java and JUnit based framework that uses the Apache HttpClient as the transport.&lt;br /&gt;
** Very robust and configurable and is used as the engine for a number of other testing tools.&lt;br /&gt;
* jWebUnit - http://jwebunit.sourceforge.net&lt;br /&gt;
** A Java based meta-framework that uses htmlunit or selenium as the testing engine.&lt;br /&gt;
* Canoo Webtest - http://webtest.canoo.com&lt;br /&gt;
** An XML based testing tool that provides a facade on top of htmlunit.&lt;br /&gt;
** No coding is necessary as the tests are completely specified in XML.&lt;br /&gt;
** There is the option of scripting some elements in Groovy if XML does not suffice.&lt;br /&gt;
** Very actively maintained.&lt;br /&gt;
* HttpUnit - http://httpunit.sourceforge.net&lt;br /&gt;
** One of the first web testing frameworks, suffers from using the native JDK provided HTTP transport, which can be a bit limiting for security testing.&lt;br /&gt;
* Watij - http://watij.com&lt;br /&gt;
** A Java implementation of WATIR.&lt;br /&gt;
** Windows only because it uses IE for its tests (Mozilla integration is in the works).&lt;br /&gt;
* Solex - http://solex.sourceforge.net&lt;br /&gt;
** An Eclipse plugin that provides a graphical tool to record HTTP sessions and make assertions based on the results.&lt;br /&gt;
* Selenium - http://seleniumhq.org/&lt;br /&gt;
** JavaScript based testing framework, cross-platform and provides a GUI for creating tests.&lt;br /&gt;
** Mature and popular tool, but the use of JavaScript could hamper certain security tests.&lt;br /&gt;
&lt;br /&gt;
==Other Tools==&lt;br /&gt;
&lt;br /&gt;
===Runtime Analysis===&lt;br /&gt;
&lt;br /&gt;
* Rational PurifyPlus - http://www-01.ibm.com/software/awdtools/purify/&lt;br /&gt;
* Seeker by Quotium - http://www.quotium.com/prod/security.php&lt;br /&gt;
&lt;br /&gt;
===Binary Analysis===&lt;br /&gt;
&lt;br /&gt;
* BugScam IDC Package - http://sourceforge.net/projects/bugscam&lt;br /&gt;
* Veracode - http://www.veracode.com&lt;br /&gt;
&lt;br /&gt;
===Requirements Management===&lt;br /&gt;
&lt;br /&gt;
* Rational Requisite Pro - http://www-306.ibm.com/software/awdtools/reqpro&lt;br /&gt;
&lt;br /&gt;
===Site Mirroring===&lt;br /&gt;
* wget - http://www.gnu.org/software/wget, http://www.interlog.com/~tcharron/wgetwin.html&lt;br /&gt;
* curl - http://curl.haxx.se &lt;br /&gt;
* Sam Spade - http://www.samspade.org&lt;br /&gt;
* Xenu's Link Sleuth - http://home.snafu.de/tilman/xenulink.html&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Source_Code_Analysis_Tools&amp;diff=168039</id>
		<title>Source Code Analysis Tools</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Source_Code_Analysis_Tools&amp;diff=168039"/>
				<updated>2014-02-13T10:30:06Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Source Code Analysis tools are designed to analyze source code and/or compiled version of code in order to help find security flaws. Ideally, such tools would automatically find security flaws with a high degree of confidence that what is found is indeed a flaw. However, this is beyond the state of the art for many types of application security flaws. Thus, such tools frequently serve as aids for an analyst to help them zero in on security relevant portions of code so they can find flaws more efficiently, rather than a tool that simply finds flaws automatically.&lt;br /&gt;
&lt;br /&gt;
Some tools are starting to move into the IDE. For the types of problems that can be detected during the software development phase itself, this is a powerful phase within the development lifecycle to employ such tools, as it provides immediate feedback to the developer on issues they might be introducing into the code during code development itself. This immediate feedback is very useful as compared to finding vulnerabilities much later in the development cycle.&lt;br /&gt;
&lt;br /&gt;
==Strengths and Weaknesses of such tools==&lt;br /&gt;
&lt;br /&gt;
=== Strengths ===&lt;br /&gt;
* Scales Well (Can be run on lots of software, and can be repeatedly (like in nightly builds))&lt;br /&gt;
* For things that such tools can automatically find with high confidence, such as buffer overflows, SQL Injection Flaws, etc. they are great.&lt;br /&gt;
* Output is good for developers - it highlights the precise source files and line numbers that are affected&lt;br /&gt;
&lt;br /&gt;
=== Weaknesses ===&lt;br /&gt;
* Many types of security vulnerabilities are very difficult to find automatically, such as authentication problems, access control issues, insecure use of cryptography, etc. The current state of the art only allows such tools to automatically find a relatively small percentage of application security flaws. Tools of this type are getting better, however.&lt;br /&gt;
* High numbers of false positives.&lt;br /&gt;
* Frequently can't find configuration issues, since they are not represented in the code.&lt;br /&gt;
* Difficult to 'prove' that an identified security issue is an actual vulnerability.&lt;br /&gt;
* Many of these tools have difficulty analyzing code that can't be compiled. Analysts frequently can't compile code because they don't have the right libraries, all the compilation instructions, all the code, etc.&lt;br /&gt;
&lt;br /&gt;
==Important Selection Criteria==&lt;br /&gt;
&lt;br /&gt;
* Requirement: Must support your language, but not usually a key factor once it does.&lt;br /&gt;
&lt;br /&gt;
* Types of Vulnerabilities it can detect (Out of the [[OWASP Top Ten]]?) (plus more?)&lt;br /&gt;
* Does it require a fully buildable set of source?&lt;br /&gt;
* Can it run against binaries instead of source?&lt;br /&gt;
* Can it be integrated into the developer's IDE?&lt;br /&gt;
* License cost for the tool. (Some are sold per user, per org, per app, per line of code analyzed. Consulting licenses are frequently different than end user licenses.)&lt;br /&gt;
&lt;br /&gt;
==OWASP Tools Of This Type==&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&lt;br /&gt;
* [[OWASP_LAPSE_Project | OWASP LAPSE Project]]&lt;br /&gt;
* [[OWASP O2 Platform]]&lt;br /&gt;
&lt;br /&gt;
==Disclaimer==&lt;br /&gt;
&lt;br /&gt;
Disclaimer: The tools listed in the tables below are presented in alphabetical order. OWASP does not endorse any of the Vendors or Tools by listing them in the table below. We have made every effort to provide this information as accurately as possible. If you are the vendor of a tool below and think that this information is incomplete or incorrect, please send an e-mail to our mailing list and we will make every effort to correct this information.&lt;br /&gt;
&lt;br /&gt;
==Open Source or Free Tools Of This Type==&lt;br /&gt;
&lt;br /&gt;
* [http://www.stachliu.com/resources/tools/google-hacking-diggity-project/attack-tools/ Google CodeSearchDiggity] - Utilizes Google Code Search to identifies vulnerabilities in open source code projects hosted by Google Code, MS CodePlex, SourceForge, Github, and more. The tool comes with over 130 default searches that identify SQL injection, cross-site scripting (XSS), insecure remote and local file includes, hard-coded passwords, and much more.  ''Essentially, Google CodeSearchDiggity provides a source code security analysis of nearly every single open source code project in existence – simultaneously.'' &lt;br /&gt;
* [http://findbugs.sourceforge.net/ FindBugs] - Find Bugs (including some security flaws) in Java Programs&lt;br /&gt;
* [http://msdn.microsoft.com/en-us/library/bb429476(VS.80).aspx FxCop] (Microsoft) - FxCop is an application that analyzes managed code assemblies (code that targets the .NET Framework common language runtime) and reports information about the assemblies, such as possible design, localization, performance, and security improvements.&lt;br /&gt;
* [http://pmd.sourceforge.net/ PMD] - PMD scans Java source code and looks for potential code problems (this is a code quality tool that does not focus on security issues)&lt;br /&gt;
* [http://msdn.microsoft.com/en-us/library/ms933794.aspx PreFast] (Microsoft) - PREfast is a static analysis tool that identifies defects in C/C++ programs&lt;br /&gt;
* [https://www.fortify.com/ssa-elements/threat-intelligence/rats.html RATS] (Fortify) - Scans C, C++, Perl, PHP and Python source code for security problems like buffer overflows and TOCTOU (Time Of Check, Time Of Use) race conditions&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_SWAAT_Project OWASP SWAAT Project] - Simplistic Beta Tool - Languages: Java, JSP, ASP .Net, and PHP&lt;br /&gt;
* [http://www.dwheeler.com/flawfinder/ Flawfinder] Flawfinder - Scans C and C++&lt;br /&gt;
* [http://sourceforge.net/projects/rips-scanner/ RIPS] - RIPS is a static source code analyzer for vulnerabilities in PHP web applications&lt;br /&gt;
* [http://brakemanscanner.org/ Brakeman] - Brakeman is an open source vulnerability scanner specifically designed for Ruby on Rails applications&lt;br /&gt;
* [http://rubygems.org/gems/codesake-dawn Codesake Dawn] - Codesake Dawn is an open source security source code analyzer designed for Sinatra, Padrino and Ruby on Rails applications. It can work also for non web application wrote in Ruby programming language &lt;br /&gt;
* [http://sourceforge.net/projects/visualcodegrepp/ VCG] - Scans C/C++, Java, C# and PL/SQL for security issues and for comments which may indicate defective code. The config files can be used to carry out additional checks for banned functions or functions which commonly cause security issues.&lt;br /&gt;
&lt;br /&gt;
==Commercial Tools Of This Type==&lt;br /&gt;
&lt;br /&gt;
* [http://www.contrastsecurity.com/ Contrast from Contrast Security] (Contrast Security is a subsidiary of [https://www.aspectsecurity.com/ Aspect Security])&lt;br /&gt;
** Contrast is not a static analysis tool like these others. It instruments the running application and provides code level results, but doesn't actually performing static analysis.&lt;br /&gt;
* [http://www-01.ibm.com/software/rational/products/appscan/source/ IBM Security AppScan Source Edition] (formerly Ounce)&lt;br /&gt;
* [http://www.klocwork.com/products/insight.asp Insight] (KlocWork)&lt;br /&gt;
* [http://www.parasoft.com/jsp/capabilities/static_analysis.jsp?itemId=547 Parasoft Test] (Parasoft)&lt;br /&gt;
* [http://www.quotium.com/prod/security.php Seeker] ([http://www.quotium.com/ Quotium])&lt;br /&gt;
** Seeker performs code security without actually doing static analysis. Seeker does Interactive Application Security Testing (IAST), correlating runtime code &amp;amp; data analysis with simulated attacks. It provides code level results without actually relying on static analysis.&lt;br /&gt;
* [http://www.sourcepatrol.co.uk/ Source Patrol] (Pentest)&lt;br /&gt;
* [http://www.armorize.com/codesecure/ Static Source Code Analysis with CodeSecure™] (Armorize Technologies)&lt;br /&gt;
* [http://www.checkmarx.com/technology/static-code-analysis-sca/ Static Code Analysis] (Checkmarx)&lt;br /&gt;
* [http://www.coverity.com/products/security-advisor.html Security Advisor] (Coverity)&lt;br /&gt;
* [https://www.fortify.com/products/hpfssc/source-code-analyzer.html Source Code Analysis] (HP/Fortify)&lt;br /&gt;
* [http://www.veracode.com/ Veracode] (Veracode)&lt;br /&gt;
&lt;br /&gt;
==More Info==&lt;br /&gt;
&lt;br /&gt;
* TODO: add comments from: http://lists.owasp.org/pipermail/owasp-dotnet/2006-August/000002.html&lt;br /&gt;
* [[Appendix_A:_Testing_Tools | Appendix A: Testing Tools]]&lt;br /&gt;
* [http://samate.nist.gov/index.php/Source_Code_Security_Analyzers NIST's list of Source Code Security Analysis Tools]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP .NET Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Source_Code_Analysis_Tools&amp;diff=168036</id>
		<title>Source Code Analysis Tools</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Source_Code_Analysis_Tools&amp;diff=168036"/>
				<updated>2014-02-13T10:05:55Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Source Code Analysis tools are designed to analyze source code and/or compiled version of code in order to help find security flaws. Ideally, such tools would automatically find security flaws with a high degree of confidence that what is found is indeed a flaw. However, this is beyond the state of the art for many types of application security flaws. Thus, such tools frequently serve as aids for an analyst to help them zero in on security relevant portions of code so they can find flaws more efficiently, rather than a tool that simply finds flaws automatically.&lt;br /&gt;
&lt;br /&gt;
Some tools are starting to move into the IDE. For the types of problems that can be detected during the software development phase itself, this is a powerful phase within the development lifecycle to employ such tools, as it provides immediate feedback to the developer on issues they might be introducing into the code during code development itself. This immediate feedback is very useful as compared to finding vulnerabilities much later in the development cycle.&lt;br /&gt;
&lt;br /&gt;
==Strengths and Weaknesses of such tools==&lt;br /&gt;
&lt;br /&gt;
=== Strengths ===&lt;br /&gt;
* Scales Well (Can be run on lots of software, and can be repeatedly (like in nightly builds))&lt;br /&gt;
* For things that such tools can automatically find with high confidence, such as buffer overflows, SQL Injection Flaws, etc. they are great.&lt;br /&gt;
* Output is good for developers - it highlights the precise source files and line numbers that are affected&lt;br /&gt;
&lt;br /&gt;
=== Weaknesses ===&lt;br /&gt;
* Many types of security vulnerabilities are very difficult to find automatically, such as authentication problems, access control issues, insecure use of cryptography, etc. The current state of the art only allows such tools to automatically find a relatively small percentage of application security flaws. Tools of this type are getting better, however.&lt;br /&gt;
* High numbers of false positives.&lt;br /&gt;
* Frequently can't find configuration issues, since they are not represented in the code.&lt;br /&gt;
* Difficult to 'prove' that an identified security issue is an actual vulnerability.&lt;br /&gt;
* Many of these tools have difficulty analyzing code that can't be compiled. Analysts frequently can't compile code because they don't have the right libraries, all the compilation instructions, all the code, etc.&lt;br /&gt;
&lt;br /&gt;
==Important Selection Criteria==&lt;br /&gt;
&lt;br /&gt;
* Requirement: Must support your language, but not usually a key factor once it does.&lt;br /&gt;
&lt;br /&gt;
* Types of Vulnerabilities it can detect (Out of the [[OWASP Top Ten]]?) (plus more?)&lt;br /&gt;
* Does it require a fully buildable set of source?&lt;br /&gt;
* Can it run against binaries instead of source?&lt;br /&gt;
* Can it be integrated into the developer's IDE?&lt;br /&gt;
* License cost for the tool. (Some are sold per user, per org, per app, per line of code analyzed. Consulting licenses are frequently different than end user licenses.)&lt;br /&gt;
&lt;br /&gt;
==OWASP Tools Of This Type==&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&lt;br /&gt;
* [[OWASP_LAPSE_Project | OWASP LAPSE Project]]&lt;br /&gt;
* [[OWASP O2 Platform]]&lt;br /&gt;
&lt;br /&gt;
==Disclaimer==&lt;br /&gt;
&lt;br /&gt;
Disclaimer: The tools listed in the tables below are presented in alphabetical order. OWASP does not endorse any of the Vendors or Tools by listing them in the table below. We have made every effort to provide this information as accurately as possible. If you are the vendor of a tool below and think that this information is incomplete or incorrect, please send an e-mail to our mailing list and we will make every effort to correct this information.&lt;br /&gt;
&lt;br /&gt;
==Open Source or Free Tools Of This Type==&lt;br /&gt;
&lt;br /&gt;
* [http://www.stachliu.com/resources/tools/google-hacking-diggity-project/attack-tools/ Google CodeSearchDiggity] - Utilizes Google Code Search to identifies vulnerabilities in open source code projects hosted by Google Code, MS CodePlex, SourceForge, Github, and more. The tool comes with over 130 default searches that identify SQL injection, cross-site scripting (XSS), insecure remote and local file includes, hard-coded passwords, and much more.  ''Essentially, Google CodeSearchDiggity provides a source code security analysis of nearly every single open source code project in existence – simultaneously.'' &lt;br /&gt;
* [http://findbugs.sourceforge.net/ FindBugs] - Find Bugs (including some security flaws) in Java Programs&lt;br /&gt;
* [http://msdn.microsoft.com/en-us/library/bb429476(VS.80).aspx FxCop] (Microsoft) - FxCop is an application that analyzes managed code assemblies (code that targets the .NET Framework common language runtime) and reports information about the assemblies, such as possible design, localization, performance, and security improvements.&lt;br /&gt;
* [http://pmd.sourceforge.net/ PMD] - PMD scans Java source code and looks for potential code problems (this is a code quality tool that does not focus on security issues)&lt;br /&gt;
* [http://msdn.microsoft.com/en-us/library/ms933794.aspx PreFast] (Microsoft) - PREfast is a static analysis tool that identifies defects in C/C++ programs&lt;br /&gt;
* [https://www.fortify.com/ssa-elements/threat-intelligence/rats.html RATS] (Fortify) - Scans C, C++, Perl, PHP and Python source code for security problems like buffer overflows and TOCTOU (Time Of Check, Time Of Use) race conditions&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_SWAAT_Project OWASP SWAAT Project] - Simplistic Beta Tool - Languages: Java, JSP, ASP .Net, and PHP&lt;br /&gt;
* [http://www.dwheeler.com/flawfinder/ Flawfinder] Flawfinder - Scans C and C++&lt;br /&gt;
* [http://sourceforge.net/projects/rips-scanner/ RIPS] - RIPS is a static source code analyzer for vulnerabilities in PHP web applications&lt;br /&gt;
* [http://brakemanscanner.org/ Brakeman] - Brakeman is an open source vulnerability scanner specifically designed for Ruby on Rails applications&lt;br /&gt;
* [http://rubygems.org/gems/codesake-dawn Codesake Dawn] - Codesake Dawn is an open source security source code analyzer designed for Sinatra, Padrino and Ruby on Rails applications. It can work also for non web application wrote in Ruby programming language &lt;br /&gt;
* [http://sourceforge.net/projects/visualcodegrepp/ VCG] - Scans C/C++, Java, C# and PL/SQL for security issues and for comments which may indicate defective code. The config files can be used to carry out additional checks for banned functions or functions which commonly cause security issues.&lt;br /&gt;
&lt;br /&gt;
==Commercial Tools Of This Type==&lt;br /&gt;
&lt;br /&gt;
* [http://www.contrastsecurity.com/ Contrast from Contrast Security] (Contrast Security is a subsidiary of [https://www.aspectsecurity.com/ Aspect Security])&lt;br /&gt;
** Contrast is not a static analysis tool like these others. It instruments the running application and provides code level results, but doesn't actually performing static analysis.&lt;br /&gt;
* [http://www-01.ibm.com/software/rational/products/appscan/source/ IBM Security AppScan Source Edition] (formerly Ounce)&lt;br /&gt;
* [http://www.klocwork.com/products/insight.asp Insight] (KlocWork)&lt;br /&gt;
* [http://www.parasoft.com/jsp/capabilities/static_analysis.jsp?itemId=547 Parasoft Test] (Parasoft)&lt;br /&gt;
* [http://www.quotium.com/prod/security.php Seeker] ([http://www.quotium.com/ Quotium])&lt;br /&gt;
** Seeker is not a static code analysis tool. It is an Interactive Application Security Testing, correlating runtime code &amp;amp; data analysis with simulated attacks. It provides code level results through runtime analysis rather than static analysis.  &lt;br /&gt;
* [http://www.sourcepatrol.co.uk/ Source Patrol] (Pentest)&lt;br /&gt;
* [http://www.armorize.com/codesecure/ Static Source Code Analysis with CodeSecure™] (Armorize Technologies)&lt;br /&gt;
* [http://www.checkmarx.com/technology/static-code-analysis-sca/ Static Code Analysis] (Checkmarx)&lt;br /&gt;
* [http://www.coverity.com/products/security-advisor.html Security Advisor] (Coverity)&lt;br /&gt;
* [https://www.fortify.com/products/hpfssc/source-code-analyzer.html Source Code Analysis] (HP/Fortify)&lt;br /&gt;
* [http://www.veracode.com/ Veracode] (Veracode)&lt;br /&gt;
&lt;br /&gt;
==More Info==&lt;br /&gt;
&lt;br /&gt;
* TODO: add comments from: http://lists.owasp.org/pipermail/owasp-dotnet/2006-August/000002.html&lt;br /&gt;
* [[Appendix_A:_Testing_Tools | Appendix A: Testing Tools]]&lt;br /&gt;
* [http://samate.nist.gov/index.php/Source_Code_Security_Analyzers NIST's list of Source Code Security Analysis Tools]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP .NET Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135210</id>
		<title>OWASP Top10 Hebrew</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135210"/>
				<updated>2012-09-02T20:45:10Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== About ==&lt;br /&gt;
Welcome to OWASP Top 10 Hebrew Edition&lt;br /&gt;
&lt;br /&gt;
== OWASP Top 10 Hebrew Edition == &lt;br /&gt;
OWASP Top 10 Hebrew Edition is available in PDF format. &amp;lt;br&amp;gt;&lt;br /&gt;
Download at [[Media:OWASP_Top_10_Heb.pdf]]&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
The Migration of OWASP Top 10 to Hebrew is lead by Or Katz, OWASP Israel Board Member.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Other Contributors (Translation/Editing/etc.):&amp;lt;br&amp;gt;&lt;br /&gt;
Eyal Estrin&amp;lt;br&amp;gt;&lt;br /&gt;
Shay Sivan&amp;lt;br&amp;gt;&lt;br /&gt;
Assaf Reshef&amp;lt;br&amp;gt;&lt;br /&gt;
Boaz Shunami&amp;lt;br&amp;gt;&lt;br /&gt;
Guilad Regev&amp;lt;br&amp;gt;&lt;br /&gt;
Uri Fleyder&amp;lt;br&amp;gt;&lt;br /&gt;
Hemed Gur Ari&amp;lt;br&amp;gt;&lt;br /&gt;
Rotem Matok&amp;lt;br&amp;gt;&lt;br /&gt;
Igor Livshitz&amp;lt;br&amp;gt;&lt;br /&gt;
Limor Kessem&amp;lt;br&amp;gt;&lt;br /&gt;
Shlomi Gagulashvili &amp;lt;br&amp;gt;&lt;br /&gt;
Nadav Atias&amp;lt;br&amp;gt;&lt;br /&gt;
Robert Moskovitz&amp;lt;br&amp;gt;&lt;br /&gt;
Eliraz Broyer&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135209</id>
		<title>OWASP Top10 Hebrew</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135209"/>
				<updated>2012-09-02T20:44:02Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== About ==&lt;br /&gt;
Welcome to OWASP Top 10 Hebrew Edition&lt;br /&gt;
&lt;br /&gt;
== OWASP Top 10 Hebrew Edition == &lt;br /&gt;
OWASP Top 10 Hebrew Edition is available in PDF format. &amp;lt;br&amp;gt;&lt;br /&gt;
Download at [[Media:OWASP_Top_10_Heb.pdf]]&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
The project leader is Or Katz.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Contributors:&amp;lt;br&amp;gt;&lt;br /&gt;
Eyal Estrin&amp;lt;br&amp;gt;&lt;br /&gt;
Shay Sivan&amp;lt;br&amp;gt;&lt;br /&gt;
Assaf Reshef&amp;lt;br&amp;gt;&lt;br /&gt;
Boaz Shunami&amp;lt;br&amp;gt;&lt;br /&gt;
Guilad Regev&amp;lt;br&amp;gt;&lt;br /&gt;
Uri Fleyder&amp;lt;br&amp;gt;&lt;br /&gt;
Hemed Gur Ari&amp;lt;br&amp;gt;&lt;br /&gt;
Rotem Matok&amp;lt;br&amp;gt;&lt;br /&gt;
Igor Livshitz&amp;lt;br&amp;gt;&lt;br /&gt;
Limor Kessem&amp;lt;br&amp;gt;&lt;br /&gt;
Shlomi Gagulashvili &amp;lt;br&amp;gt;&lt;br /&gt;
Nadav Atias&amp;lt;br&amp;gt;&lt;br /&gt;
Robert Moskovitz&amp;lt;br&amp;gt;&lt;br /&gt;
Eliraz Broyer&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135208</id>
		<title>OWASP Top10 Hebrew</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135208"/>
				<updated>2012-09-02T20:41:16Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== About ==&lt;br /&gt;
Welcome to OWASP Top 10 Hebrew Edition&lt;br /&gt;
&lt;br /&gt;
== OWASP Top 10 Hebrew Edition == &lt;br /&gt;
OWASP Top 10 Hebrew Edition is available in PDF format. &amp;lt;br&amp;gt;&lt;br /&gt;
Download at [[Media:OWASP_Top_10_Heb.pdf]]&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
The project leader was Or Katz.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Contributors:&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135207</id>
		<title>OWASP Top10 Hebrew</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135207"/>
				<updated>2012-09-02T20:41:08Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== About ==&lt;br /&gt;
Welcome to OWASP Top 10 Hebrew Edition&lt;br /&gt;
&lt;br /&gt;
== OWASP Top 10 Hebrew Edition == &lt;br /&gt;
OWASP Top 10 Hebrew Edition is available in PDF format. &lt;br /&gt;
Download at [[Media:OWASP_Top_10_Heb.pdf]]&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
The project leader was Or Katz.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Contributors:&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135206</id>
		<title>OWASP Top10 Hebrew</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135206"/>
				<updated>2012-09-02T20:40:04Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== About ==&lt;br /&gt;
Welcome to OWASP Top 10 Hebrew Edition&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Top 10 Hebrew Edition == &lt;br /&gt;
Download at [[Media:OWASP_Top_10_Heb.pdf OWASP_Top_10_Heb.pdf]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
The project leader was Or Katz.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Contributors:&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135205</id>
		<title>OWASP Top10 Hebrew</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135205"/>
				<updated>2012-09-02T20:38:58Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== About ==&lt;br /&gt;
Welcome to OWASP Top 10 Hebrew Edition&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Top 10 Hebrew Edition == &lt;br /&gt;
Download at [[File:OWASP_Top_10_Heb.pdf]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
The project leader was Or Katz.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Contributors:&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135204</id>
		<title>OWASP Top10 Hebrew</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135204"/>
				<updated>2012-09-02T20:38:21Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== About ==&lt;br /&gt;
Welcome to OWASP Top 10 Hebrew Edition&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Top 10 Hebrew Edition == &lt;br /&gt;
Click for download [[Media:OWASP_Top_10_Heb.pdf]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
The project leader was Or Katz.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Contributors:&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_Top_10_Heb.pdf&amp;diff=135203</id>
		<title>File:OWASP Top 10 Heb.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_Top_10_Heb.pdf&amp;diff=135203"/>
				<updated>2012-09-02T20:37:28Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135202</id>
		<title>OWASP Top10 Hebrew</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135202"/>
				<updated>2012-09-02T20:36:29Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== About ==&lt;br /&gt;
Welcome to OWASP Top 10 Hebrew Edition&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Top 10 Hebrew Edition == &lt;br /&gt;
Click for download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
The project leader was Or Katz.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Contributors:&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;br /&gt;
...&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135201</id>
		<title>OWASP Top10 Hebrew</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135201"/>
				<updated>2012-09-02T20:36:13Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== About ==&lt;br /&gt;
Welcome to OWASP Top 10 Hebrew Edition&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Top 10 Hebrew Edition == &lt;br /&gt;
Click for download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
The project leader was Or Katz.&lt;br /&gt;
Contributors:&lt;br /&gt;
...&lt;br /&gt;
...&lt;br /&gt;
...&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135200</id>
		<title>OWASP Top10 Hebrew</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Top10_Hebrew&amp;diff=135200"/>
				<updated>2012-09-02T20:35:03Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: Created page with &amp;quot; == OWASP Top 10 Hebrew ==&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== OWASP Top 10 Hebrew ==&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Agenda&amp;diff=135183</id>
		<title>Template:OWASP IL 2012 Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Agenda&amp;diff=135183"/>
				<updated>2012-09-01T17:07:01Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;border-collapse: collapse; border-width: 1px; border-style: solid; border-color: #000&amp;quot; cellpadding=2&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot; &lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D;white-space:nowrap&amp;quot; width=&amp;quot;90&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 08:45-09:15&lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=2 style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; | '''Registration, Gathering, Socializing &amp;amp; Networking'''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 09:15-09:45 &lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''Opening Words''' &amp;lt;br&amp;gt;&lt;br /&gt;
''Ofer Maor - Chairman, OWASP Israel; Global Membership Committee, OWASP''&amp;lt;br&amp;gt;&lt;br /&gt;
''Dr. Anat Bremler-Barr, Efi Arazi School of Computer Science, IDC''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 09:45-10:10&lt;br /&gt;
|  align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot;| '''OWASP Top 10 Hebrew Edition'''&lt;br /&gt;
''Or Katz, OWASP Israel Board''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;30&amp;quot; align=&amp;quot;right&amp;quot; valign=&amp;quot;center&amp;quot; | &amp;amp;nbsp;&lt;br /&gt;
|   style=&amp;quot;border-style: solid; border-width: 1px;&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; width=500 | &amp;lt;u&amp;gt;'''Breakers (Track #1)'''&amp;lt;/u&amp;gt;&lt;br /&gt;
|   style=&amp;quot;border-style: solid; border-width: 1px;&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; width=500 | &amp;lt;u&amp;gt;'''Defenders (Track #2)'''&amp;lt;/u&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 10:15-11:00&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''The Diviner – Digital Clairvoyance: Getting an Insight&amp;lt;br&amp;gt;Into Server Code &amp;amp; Memory Using Blackbox Techniques'''  &amp;lt;br&amp;gt;&lt;br /&gt;
''Shay Chen, CTO, Hacktics ASC, Ernst &amp;amp; Young''&amp;lt;br&amp;gt;&lt;br /&gt;
''Eran Tamari, Team Leader, Hacktics ASC, Ernst &amp;amp; Young''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;font-size:11pt&amp;quot;  | '''Case Study:&amp;lt;br&amp;gt;Providing Secure SDLC in an Agile Environment Using ESAPI ''' &lt;br /&gt;
''Yair Rovek, Security Specialist, Liveperson''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 11:00-11:15&lt;br /&gt;
|  valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Coffee Break'''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 11:15-12:00&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''FYI: You've Got LFI''' &lt;br /&gt;
''Tal Beery, Web Security Research Team Leader, Imperva''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''I&amp;gt;S+D! – Integrated Application Security Testing (IAST),&amp;lt;br&amp;gt; Beyond SAST/DAST ''' &lt;br /&gt;
''Ofer Maor, CTO, Quotium''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 12:00-12:30&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Zip It! – Owning Archived File Uploads ''' &lt;br /&gt;
''Alex Landa, Security Researcher, IBM''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Secure Development Lifecycle – Lessons Learned  ''' &lt;br /&gt;
''Boaz Shunami, Founder, Komodo Consulting''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 12:30-13:30&lt;br /&gt;
|  valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Lunch Break'''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 13:30-14:15&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Advanced Pen-Testing of iPhone Applications''' &lt;br /&gt;
''Chilik Tamir, Chief Scientist, AppSec Labs ''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Positive Logic XSS Detection &amp;amp; Prevention&amp;lt;br&amp;gt;using Generalized JavaScript Assembly ''' &lt;br /&gt;
''Tsvi Cherny, Interdisciplinary Center''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 14:15-15:00&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Attacking Android Mobile Applications''' &lt;br /&gt;
''Erez Metula, Founder, AppSec Labs'' &lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Application Counter Attack''' &lt;br /&gt;
''Ziv Gadot, SOC Team Leader, Radware''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 15:00-15:15&lt;br /&gt;
|  valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Coffee Break'''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 15:15-15:45&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''The Dark World of Mobile Payments''' &lt;br /&gt;
''Nir Valtman, CSO, Retalix''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Identifying Maladvertisements''' &lt;br /&gt;
''Maty Siman, CTO, Checkmarx''&amp;lt;br&amp;gt;''Meny Duek, Director of R&amp;amp;D, Mediamind''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 15:45-16:15&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Stylish XSS: Fonts Name Injection''' &lt;br /&gt;
''Adi Cohen, Security Researcher, IBM''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''My Authentication Album:&amp;lt;br&amp;gt;Adaptive Image-Based Login Mechanism ''' &lt;br /&gt;
''Ronen Margulis, Bar Ilan University''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 16:15-16:45&lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''Guest Lecture&amp;lt;br&amp;gt;&amp;amp;nbsp;&amp;lt;br&amp;gt;The New art of WAR &amp;amp; PEACE- a REAL FANTASY'''&amp;lt;br&amp;gt; A drill down to the &amp;quot;money time&amp;quot;: Was Iran Stuxnet’s main target? how economy is a battle zone?&amp;lt;br&amp;gt;&lt;br /&gt;
''Guy Phillip Goldstein (Author of &amp;quot;Babel Minute Zero&amp;quot;)''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 16:45-17:00&lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''End Notes''' &amp;amp;nbsp;&lt;br /&gt;
''Ofer Maor - Chairman, OWASP Israel; Global Membership Committee, OWASP''&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Agenda&amp;diff=135087</id>
		<title>Template:OWASP IL 2012 Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Agenda&amp;diff=135087"/>
				<updated>2012-08-30T15:11:14Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;border-collapse: collapse; border-width: 1px; border-style: solid; border-color: #000&amp;quot; cellpadding=2&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot; &lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D;white-space:nowrap&amp;quot; width=&amp;quot;90&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 08:45-09:15&lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=2 style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; | '''Registration, Gathering, Socializing &amp;amp; Networking'''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 09:15-09:45 &lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''Opening Words''' &amp;lt;br&amp;gt;&lt;br /&gt;
''Ofer Maor - Chairman, OWASP Israel; Global Membership Committee, OWASP''&amp;lt;br&amp;gt;&lt;br /&gt;
''Dr. Anat Bremler-Barr, Efi Arazi School of Computer Science, IDC''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 09:45-10:10&lt;br /&gt;
|  align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot;| '''OWASP Top 10 Hebrew Edition'''&lt;br /&gt;
''Or Katz, OWASP Israel Board''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;30&amp;quot; align=&amp;quot;right&amp;quot; valign=&amp;quot;center&amp;quot; | &amp;amp;nbsp;&lt;br /&gt;
|   style=&amp;quot;border-style: solid; border-width: 1px;&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; width=500 | &amp;lt;u&amp;gt;'''Breakers (Track #1)'''&amp;lt;/u&amp;gt;&lt;br /&gt;
|   style=&amp;quot;border-style: solid; border-width: 1px;&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; width=500 | &amp;lt;u&amp;gt;'''Defenders (Track #2)'''&amp;lt;/u&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 10:15-11:00&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''The Diviner – Digital Clairvoyance: Getting an Insight&amp;lt;br&amp;gt;Into Server Code &amp;amp; Memory Using Blackbox Techniques'''  &amp;lt;br&amp;gt;&lt;br /&gt;
''Shay Chen, CTO, Hacktics ASC, Ernst &amp;amp; Young''&amp;lt;br&amp;gt;&lt;br /&gt;
''Eran Tamari, Team Leader, Hacktics ASC, Ernst &amp;amp; Young''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;font-size:11pt&amp;quot;  | '''Case Study:&amp;lt;br&amp;gt;Providing Secure SDLC in an Agile Environment Using ESAPI ''' &lt;br /&gt;
''Yair Rovek, Security Specialist, Liveperson''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 11:00-11:15&lt;br /&gt;
|  valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Coffee Break'''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 11:15-12:00&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''FYI: You've Got LFI''' &lt;br /&gt;
''Tal Beery, Web Security Research Team Leader, Imperva''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''I&amp;gt;S+D! – Integrated Application Security Testing (IAST),&amp;lt;br&amp;gt; Beyond SAST/DAST ''' &lt;br /&gt;
''Ofer Maor, CTO, Quotium''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 12:00-12:30&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Zip It! – Owning Archived File Uploads ''' &lt;br /&gt;
''Alex Landa, Security Researcher, IBM''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Secure Development Lifecycle – Lessons Learned  ''' &lt;br /&gt;
''Boaz Shunami, Founder, Komodo Consulting''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 12:30-13:30&lt;br /&gt;
|  valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Lunch Break'''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 13:30-14:15&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Advanced Pen-Testing of iPhone Applications''' &lt;br /&gt;
''Chilik Tamir, Chief Scientist, AppSec Labs ''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Positive Logic XSS Detection &amp;amp; Prevention&amp;lt;br&amp;gt;using Generalized JavaScript Assembly ''' &lt;br /&gt;
''Tsvi Cherny, Interdisciplinary Center''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 14:15-15:00&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Attacking Android Mobile Applications''' &lt;br /&gt;
''Erez Metula, Founder, AppSec Labs'' &lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Application Counter Attack''' &lt;br /&gt;
''Ziv Gadot, SOC Team Leader, Radware''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 15:00-15:15&lt;br /&gt;
|  valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Coffee Break'''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 15:15-15:45&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''The Dark World of Mobile Payments''' &lt;br /&gt;
''Niv Valtman, CSO, Retalix''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Identifying Maladvertisements''' &lt;br /&gt;
''Maty Siman, CTO, Checkmarx''&amp;lt;br&amp;gt;''Meny Duek, Director of R&amp;amp;D, Mediamind''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 15:45-16:15&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Stylish XSS: Fonts Name Injection''' &lt;br /&gt;
''Adi Cohen, Security Researcher, IBM''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''My Authentication Album:&amp;lt;br&amp;gt;Adaptive Image-Based Login Mechanism ''' &lt;br /&gt;
''Ronen Margulis, Bar Ilan University''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 16:15-16:45&lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''Guest Lecture&amp;lt;br&amp;gt;&amp;amp;nbsp;&amp;lt;br&amp;gt;The New art of WAR &amp;amp; PEACE- a REAL FANTASY'''&amp;lt;br&amp;gt; A drill down to the &amp;quot;money time&amp;quot;: Was Iran Stuxnet’s main target? how economy is a battle zone?&amp;lt;br&amp;gt;&lt;br /&gt;
''Guy Phillip Goldstein (Author of &amp;quot;Babel Minute Zero&amp;quot;)''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 16:45-17:00&lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''End Notes''' &amp;amp;nbsp;&lt;br /&gt;
''Ofer Maor - Chairman, OWASP Israel; Global Membership Committee, OWASP''&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Israel_2012&amp;diff=135086</id>
		<title>OWASP Israel 2012</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Israel_2012&amp;diff=135086"/>
				<updated>2012-08-30T15:09:53Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Location and Time  ==&lt;br /&gt;
&lt;br /&gt;
The 2012 annual OWASP Israel conference will be held at the Interdisciplinary Center Herzliya (IDC) on September 5th in the Efi Arazi school of computer science. &lt;br /&gt;
&lt;br /&gt;
The conference is sponsored by: &lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP_IL_2012_Sponsors}} &lt;br /&gt;
&lt;br /&gt;
For further details contact Ofer Maor (ofer.maor at owasp.org) &lt;br /&gt;
&lt;br /&gt;
== Registration  ==&lt;br /&gt;
&lt;br /&gt;
'''OWASP Israel 2012 is FREE!'''&lt;br /&gt;
&lt;br /&gt;
Early registration is, however, required. '''YOU MUST REGISTER TO GUARANTEE YOUR ADMISSION.'''&lt;br /&gt;
&lt;br /&gt;
While attending the conference is free, '''we urge you to take this opportunity to become an OWASP Member''', supporting the OWASP cause and gaining additional benefits. &lt;br /&gt;
&lt;br /&gt;
Please register at '''[http://www.cvent.com/d/1cqwcq OWASP AppSec Israel 2012 Registration Page]'''&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP_IL_2012_Agenda}} &lt;br /&gt;
&lt;br /&gt;
== The people behind the conference  ==&lt;br /&gt;
&lt;br /&gt;
OWASP Israel is made by the people who contribute their time and brain to its success. The following people are working to ensure that OWASP Israel 2012 is a success. If you feel that you also can contribute or have interesting ideas regarding the conference, don't hesitate to contact me. &lt;br /&gt;
&lt;br /&gt;
[[Category:Israel]] [[Category:OWASP_Israel_2012]]&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135085</id>
		<title>Template:OWASP IL 2012 Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135085"/>
				<updated>2012-08-30T14:55:45Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| &lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:GoldIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.idc.ac.il https://www.owasp.org/images/f/f1/OWASP_IL_Sponsors_IDC_New.JPG]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.quotium.com https://www.owasp.org/images/5/56/LogoQuotium.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.imperva.com https://www.owasp.org/images/8/89/OWASP_IL_Sponsors_Imperva.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.ey.com https://www.owasp.org/images/3/34/EY-IL.jpg]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.akamai.com https://www.owasp.org/images/9/93/Akamai_logoIL.gif]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; [http://www.ibm.com/ https://www.owasp.org/images/a/a5/IBM-IL.png]&lt;br /&gt;
| [http://www.radware.com https://www.owasp.org/images/a/a3/RadwareIL-Logo.jpg]&lt;br /&gt;
|-&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:SilverIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.grsee.co.il https://www.owasp.org/images/0/0d/GRSEEIL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.liveperson.com/ https://www.owasp.org/images/3/33/LivepersonIL.png]&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.rsa.com https://www.owasp.org/images/5/5e/RSA-IL.png] &amp;amp;nbsp; [http://www.foresight-air.com/ https://www.owasp.org/images/c/c1/ForesightIL.jpg]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp; [http://www.komodosec.com/ https://www.owasp.org/images/0/03/Komodo-small.jpg]&lt;br /&gt;
| [http://www.secoz.com/ https://www.owasp.org/images/4/4e/SecOZ-ILLogo.jpg] [http://www.hp.com/ https://www.owasp.org/images/6/6c/HPLogoIL.png]&lt;br /&gt;
| &amp;amp;nbsp; [//http://www.rafael.co.il/ https://www.owasp.org/images/3/31/RafaelLogo.jpg]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135084</id>
		<title>Template:OWASP IL 2012 Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135084"/>
				<updated>2012-08-30T14:55:26Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| &lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:GoldIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.idc.ac.il https://www.owasp.org/images/f/f1/OWASP_IL_Sponsors_IDC_New.JPG]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.quotium.com https://www.owasp.org/images/5/56/LogoQuotium.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.imperva.com https://www.owasp.org/images/8/89/OWASP_IL_Sponsors_Imperva.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.ey.com https://www.owasp.org/images/3/34/EY-IL.jpg]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.akamai.com https://www.owasp.org/images/9/93/Akamai_logoIL.gif]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; [http://www.ibm.com/ https://www.owasp.org/images/a/a5/IBM-IL.png]&lt;br /&gt;
| [http://www.radware.com https://www.owasp.org/images/a/a3/RadwareIL-Logo.jpg]&lt;br /&gt;
|-&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:SilverIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.grsee.co.il https://www.owasp.org/images/0/0d/GRSEEIL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.liveperson.com/ https://www.owasp.org/images/3/33/LivepersonIL.png]&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.rsa.com https://www.owasp.org/images/5/5e/RSA-IL.png] &amp;amp;nbsp; [http://www.foresight-air.com/ https://www.owasp.org/images/c/c1/ForesightIL.jpg]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp; [http://www.komodosec.com/ https://www.owasp.org/images/0/03/Komodo-small.jpg]&lt;br /&gt;
| [http://www.secoz.com/ https://www.owasp.org/images/4/4e/SecOZ-ILLogo.jpg] [http://www.hp.com/ https://www.owasp.org/images/6/6c/HPLogoIL.png]&lt;br /&gt;
| &amp;amp;nbsp; [//http://www.rafael.co.il/ https://www.owasp.org/images/3/31/RafaelLogo.jpg]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135083</id>
		<title>Template:OWASP IL 2012 Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135083"/>
				<updated>2012-08-30T14:54:54Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| &lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:GoldIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.idc.ac.il https://www.owasp.org/images/f/f1/OWASP_IL_Sponsors_IDC_New.JPG]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.quotium.com https://www.owasp.org/images/5/56/LogoQuotium.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.imperva.com https://www.owasp.org/images/8/89/OWASP_IL_Sponsors_Imperva.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.ey.com https://www.owasp.org/images/3/34/EY-IL.jpg]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.akamai.com https://www.owasp.org/images/9/93/Akamai_logoIL.gif]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; [http://www.ibm.com/ https://www.owasp.org/images/a/a5/IBM-IL.png]&lt;br /&gt;
| [http://www.radware.com https://www.owasp.org/images/a/a3/RadwareIL-Logo.jpg]&lt;br /&gt;
|-&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:SilverIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.grsee.co.il https://www.owasp.org/images/0/0d/GRSEEIL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.liveperson.com/ https://www.owasp.org/images/3/33/LivepersonIL.png]&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.rsa.com https://www.owasp.org/images/5/5e/RSA-IL.png] &amp;amp;nbsp; [http://www.foresight-air.com/ https://www.owasp.org/images/c/c1/ForesightIL.jpg]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp; [http://www.komodosec.com/ https://www.owasp.org/images/0/03/Komodo-small.jpg]&lt;br /&gt;
| [http://www.secoz.com/ https://www.owasp.org/images/4/4e/SecOZ-ILLogo.jpg] [http://www.hp.com/ https://www.owasp.org/images/6/6c/HPLogoIL.png]&lt;br /&gt;
| &amp;amp;nbsp; [//http://www.rafael.co.il/ https://www.owasp.org/images/3/31/RafaelLogo.jpg]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:HPLogoIL.png&amp;diff=135082</id>
		<title>File:HPLogoIL.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:HPLogoIL.png&amp;diff=135082"/>
				<updated>2012-08-30T14:53:45Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: uploaded a new version of &amp;amp;quot;File:HPLogoIL.png&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135081</id>
		<title>Template:OWASP IL 2012 Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135081"/>
				<updated>2012-08-30T14:53:09Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| &lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:GoldIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.idc.ac.il https://www.owasp.org/images/f/f1/OWASP_IL_Sponsors_IDC_New.JPG]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.quotium.com https://www.owasp.org/images/5/56/LogoQuotium.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.imperva.com https://www.owasp.org/images/8/89/OWASP_IL_Sponsors_Imperva.png]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.ey.com https://www.owasp.org/images/3/34/EY-IL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.akamai.com https://www.owasp.org/images/9/93/Akamai_logoIL.gif]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; [http://www.ibm.com/ https://www.owasp.org/images/a/a5/IBM-IL.png]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
| [http://www.radware.com https://www.owasp.org/images/a/a3/RadwareIL-Logo.jpg]&lt;br /&gt;
|-&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:SilverIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.grsee.co.il https://www.owasp.org/images/0/0d/GRSEEIL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.liveperson.com/ https://www.owasp.org/images/3/33/LivepersonIL.png]&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.rsa.com https://www.owasp.org/images/5/5e/RSA-IL.png] &amp;amp;nbsp; [http://www.foresight-air.com/ https://www.owasp.org/images/c/c1/ForesightIL.jpg]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp; [http://www.komodosec.com/ https://www.owasp.org/images/0/03/Komodo-small.jpg]&lt;br /&gt;
| [http://www.secoz.com/ https://www.owasp.org/images/4/4e/SecOZ-ILLogo.jpg] [http://www.hp.com/ https://www.owasp.org/images/6/6c/HPLogoIL.png]&lt;br /&gt;
| &amp;amp;nbsp; [//http://www.rafael.co.il/ https://www.owasp.org/images/3/31/RafaelLogo.jpg]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:HPLogoIL.png&amp;diff=135080</id>
		<title>File:HPLogoIL.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:HPLogoIL.png&amp;diff=135080"/>
				<updated>2012-08-30T14:52:37Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135079</id>
		<title>Template:OWASP IL 2012 Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135079"/>
				<updated>2012-08-30T14:52:16Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| &lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:GoldIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.idc.ac.il https://www.owasp.org/images/f/f1/OWASP_IL_Sponsors_IDC_New.JPG]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.quotium.com https://www.owasp.org/images/5/56/LogoQuotium.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.imperva.com https://www.owasp.org/images/8/89/OWASP_IL_Sponsors_Imperva.png]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.ey.com https://www.owasp.org/images/3/34/EY-IL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.akamai.com https://www.owasp.org/images/9/93/Akamai_logoIL.gif]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; [http://www.ibm.com/ https://www.owasp.org/images/a/a5/IBM-IL.png]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
| [http://www.radware.com https://www.owasp.org/images/a/a3/RadwareIL-Logo.jpg]&lt;br /&gt;
|-&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:SilverIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.grsee.co.il https://www.owasp.org/images/0/0d/GRSEEIL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.liveperson.com/ https://www.owasp.org/images/3/33/LivepersonIL.png]&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.rsa.com https://www.owasp.org/images/5/5e/RSA-IL.png] &amp;amp;nbsp; [http://www.foresight-air.com/ https://www.owasp.org/images/c/c1/ForesightIL.jpg]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp; [http://www.komodosec.com/ https://www.owasp.org/images/0/03/Komodo-small.jpg]&lt;br /&gt;
| [http://www.secoz.com/ https://www.owasp.org/images/4/4e/SecOZ-ILLogo.jpg]&lt;br /&gt;
| &amp;amp;nbsp; [//http://www.rafael.co.il/ https://www.owasp.org/images/3/31/RafaelLogo.jpg]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:SecOZ-ILLogo.jpg&amp;diff=135078</id>
		<title>File:SecOZ-ILLogo.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:SecOZ-ILLogo.jpg&amp;diff=135078"/>
				<updated>2012-08-30T14:51:29Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: uploaded a new version of &amp;amp;quot;File:SecOZ-ILLogo.jpg&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135077</id>
		<title>Template:OWASP IL 2012 Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135077"/>
				<updated>2012-08-30T14:46:26Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| &lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:GoldIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.idc.ac.il https://www.owasp.org/images/f/f1/OWASP_IL_Sponsors_IDC_New.JPG]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.quotium.com https://www.owasp.org/images/5/56/LogoQuotium.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.imperva.com https://www.owasp.org/images/8/89/OWASP_IL_Sponsors_Imperva.png]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.ey.com https://www.owasp.org/images/3/34/EY-IL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.akamai.com https://www.owasp.org/images/9/93/Akamai_logoIL.gif]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; [http://www.ibm.com/ https://www.owasp.org/images/a/a5/IBM-IL.png]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
| [http://www.radware.com https://www.owasp.org/images/a/a3/RadwareIL-Logo.jpg]&lt;br /&gt;
|-&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:SilverIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.grsee.co.il https://www.owasp.org/images/0/0d/GRSEEIL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.liveperson.com/ https://www.owasp.org/images/3/33/LivepersonIL.png]&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.rsa.com https://www.owasp.org/images/5/5e/RSA-IL.png] &amp;amp;nbsp; [http://www.foresight-air.com/ https://www.owasp.org/images/c/c1/ForesightIL.jpg]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp; [http://www.komodosec.com/ https://www.owasp.org/images/0/03/Komodo-small.jpg]&lt;br /&gt;
| &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; [http://www.secoz.com/ https://www.owasp.org/images/4/4e/SecOZ-ILLogo.jpg]&lt;br /&gt;
| &amp;amp;nbsp; [//http://www.rafael.co.il/ https://www.owasp.org/images/3/31/RafaelLogo.jpg]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:RafaelLogo.jpg&amp;diff=135049</id>
		<title>File:RafaelLogo.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:RafaelLogo.jpg&amp;diff=135049"/>
				<updated>2012-08-30T07:36:45Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: uploaded a new version of &amp;amp;quot;File:RafaelLogo.jpg&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135048</id>
		<title>Template:OWASP IL 2012 Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135048"/>
				<updated>2012-08-30T07:35:58Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| &lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:GoldIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.idc.ac.il https://www.owasp.org/images/f/f1/OWASP_IL_Sponsors_IDC_New.JPG]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.quotium.com https://www.owasp.org/images/5/56/LogoQuotium.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.imperva.com https://www.owasp.org/images/8/89/OWASP_IL_Sponsors_Imperva.png]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.ey.com https://www.owasp.org/images/3/34/EY-IL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.akamai.com https://www.owasp.org/images/9/93/Akamai_logoIL.gif]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; [http://www.ibm.com/ https://www.owasp.org/images/a/a5/IBM-IL.png]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
| [http://www.radware.com https://www.owasp.org/images/a/a3/RadwareIL-Logo.jpg]&lt;br /&gt;
|-&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:SilverIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.grsee.co.il https://www.owasp.org/images/0/0d/GRSEEIL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.liveperson.com/ https://www.owasp.org/images/3/33/LivepersonIL.png]&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.rsa.com https://www.owasp.org/images/5/5e/RSA-IL.png]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp; [http://www.komodosec.com/ https://www.owasp.org/images/0/03/Komodo-small.jpg]&lt;br /&gt;
| &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; [http://www.secoz.com/ https://www.owasp.org/images/4/4e/SecOZ-ILLogo.jpg]&lt;br /&gt;
| &amp;amp;nbsp; [//http://www.rafael.co.il/ https://www.owasp.org/images/3/31/RafaelLogo.jpg]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:RafaelLogo.jpg&amp;diff=135047</id>
		<title>File:RafaelLogo.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:RafaelLogo.jpg&amp;diff=135047"/>
				<updated>2012-08-30T07:34:46Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Agenda&amp;diff=135046</id>
		<title>Template:OWASP IL 2012 Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Agenda&amp;diff=135046"/>
				<updated>2012-08-30T07:22:25Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;border-collapse: collapse; border-width: 1px; border-style: solid; border-color: #000&amp;quot; cellpadding=2&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot; &lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D;white-space:nowrap&amp;quot; width=&amp;quot;90&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 08:45-09:15&lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=2 style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; | '''Registration, Gathering, Socializing &amp;amp; Networking'''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 09:15-09:45 &lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''Opening Words''' &amp;lt;br&amp;gt;&lt;br /&gt;
''Ofer Maor - Chairman, OWASP Israel; Global Membership Committee, OWASP''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 09:45-10:10&lt;br /&gt;
|  align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot;| '''OWASP Top 10 Hebrew Edition'''&lt;br /&gt;
''Or Katz, OWASP Israel Board''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;30&amp;quot; align=&amp;quot;right&amp;quot; valign=&amp;quot;center&amp;quot; | &amp;amp;nbsp;&lt;br /&gt;
|   style=&amp;quot;border-style: solid; border-width: 1px;&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; width=500 | &amp;lt;u&amp;gt;'''Breakers (Track #1)'''&amp;lt;/u&amp;gt;&lt;br /&gt;
|   style=&amp;quot;border-style: solid; border-width: 1px;&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; width=500 | &amp;lt;u&amp;gt;'''Defenders (Track #2)'''&amp;lt;/u&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 10:15-11:00&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''The Diviner – Digital Clairvoyance: Getting an Insight&amp;lt;br&amp;gt;Into Server Code &amp;amp; Memory Using Blackbox Techniques'''  &amp;lt;br&amp;gt;&lt;br /&gt;
''Shay Chen, CTO, Hacktics ASC, Ernst &amp;amp; Young''&amp;lt;br&amp;gt;&lt;br /&gt;
''Eran Tamari, Team Leader, Hacktics ASC, Ernst &amp;amp; Young''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;font-size:11pt&amp;quot;  | '''Case Study:&amp;lt;br&amp;gt;Providing Secure SDLC in an Agile Environment Using ESAPI ''' &lt;br /&gt;
''Yair Rovek, Security Specialist, Liveperson''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 11:00-11:15&lt;br /&gt;
|  valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Coffee Break'''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 11:15-12:00&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''FYI: You've Got LFI''' &lt;br /&gt;
''Tal Beery, Web Security Research Team Leader, Imperva''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''I&amp;gt;S+D! – Integrated Application Security Testing (IAST),&amp;lt;br&amp;gt; Beyond SAST/DAST ''' &lt;br /&gt;
''Ofer Maor, CTO, Quotium''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 12:00-12:30&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Zip It! – Owning Archived File Uploads ''' &lt;br /&gt;
''Alex Landa, Security Researcher, IBM''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Secure Development Lifecycle – Lessons Learned  ''' &lt;br /&gt;
''Boaz Shunami, Founder, Komodo Consulting''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 12:30-13:30&lt;br /&gt;
|  valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Lunch Break'''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 13:30-14:15&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Advanced Pen-Testing of iPhone Applications''' &lt;br /&gt;
''Chilik Tamir, Chief Scientist, AppSec Labs ''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Positive Logic XSS Detection &amp;amp; Prevention&amp;lt;br&amp;gt;using Generalized JavaScript Assembly ''' &lt;br /&gt;
''Tsvi Cherny, Interdisciplinary Center''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 14:15-15:00&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Attacking Android Mobile Applications''' &lt;br /&gt;
''Erez Metula, Founder, AppSec Labs'' &lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Application Counter Attack''' &lt;br /&gt;
''Ziv Gadot, SOC Team Leader, Radware''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;40&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 15:00-15:15&lt;br /&gt;
|  valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:12pt&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Coffee Break'''&lt;br /&gt;
|- style=&amp;quot;border-style: solid; border-width: 1px;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 15:15-15:45&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''The Dark World of Mobile Payments''' &lt;br /&gt;
''Niv Valtman, CSO, Retalix''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Identifying Maladvertisements''' &lt;br /&gt;
''Maty Siman, CTO, Checkmarx''&amp;lt;br&amp;gt;''Meny Duek, Director of R&amp;amp;D, Mediamind''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; height=&amp;quot;25&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 15:45-16:15&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''Stylish XSS: Fonts Name Injection''' &lt;br /&gt;
''Adi Cohen, Security Researcher, IBM''&lt;br /&gt;
|  align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; cellpadding=5  | '''My Authentication Album:&amp;lt;br&amp;gt;Adaptive Image-Based Login Mechanism ''' &lt;br /&gt;
''Ronen Margulis, Bar Ilan University''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 16:15-16:45&lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''Guest Lecture&amp;lt;br&amp;gt;&amp;amp;nbsp;&amp;lt;br&amp;gt;The New art of WAR &amp;amp; PEACE- a REAL FANTASY'''&amp;lt;br&amp;gt; A drill down to the &amp;quot;money time&amp;quot;: Was Iran Stuxnet’s main target? how economy is a battle zone?&amp;lt;br&amp;gt;&lt;br /&gt;
''Guy Phillip Goldstein (Author of &amp;quot;Babel Minute Zero&amp;quot;)''&lt;br /&gt;
|- style=&amp;quot;font-size:10pt&amp;quot;&lt;br /&gt;
|style=&amp;quot;border-style: solid; border-width: 1px;color:#1F497D&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; | 16:45-17:00&lt;br /&gt;
| align=center valign=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; style=&amp;quot;border-style: solid; border-width: 1px;font-size:11pt&amp;quot; | '''End Notes''' &amp;amp;nbsp;&lt;br /&gt;
''Ofer Maor - Chairman, OWASP Israel; Global Membership Committee, OWASP''&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135045</id>
		<title>Template:OWASP IL 2012 Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135045"/>
				<updated>2012-08-30T06:05:26Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| &lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:GoldIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.idc.ac.il https://www.owasp.org/images/f/f1/OWASP_IL_Sponsors_IDC_New.JPG]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.quotium.com https://www.owasp.org/images/5/56/LogoQuotium.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.imperva.com https://www.owasp.org/images/8/89/OWASP_IL_Sponsors_Imperva.png]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.ey.com https://www.owasp.org/images/3/34/EY-IL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.akamai.com https://www.owasp.org/images/9/93/Akamai_logoIL.gif]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; [http://www.ibm.com/ https://www.owasp.org/images/a/a5/IBM-IL.png]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
| [http://www.radware.com https://www.owasp.org/images/a/a3/RadwareIL-Logo.jpg]&lt;br /&gt;
|-&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:SilverIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.grsee.co.il https://www.owasp.org/images/0/0d/GRSEEIL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.liveperson.com/ https://www.owasp.org/images/3/33/LivepersonIL.png]&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.rsa.com https://www.owasp.org/images/5/5e/RSA-IL.png]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp; [http://www.komodosec.com/ https://www.owasp.org/images/0/03/Komodo-small.jpg]&lt;br /&gt;
| &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; [http://www.secoz.com/ https://www.owasp.org/images/4/4e/SecOZ-ILLogo.jpg]&lt;br /&gt;
&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:RadwareIL-Logo.jpg&amp;diff=135019</id>
		<title>File:RadwareIL-Logo.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:RadwareIL-Logo.jpg&amp;diff=135019"/>
				<updated>2012-08-29T20:06:14Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: uploaded a new version of &amp;amp;quot;File:RadwareIL-Logo.jpg&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135018</id>
		<title>Template:OWASP IL 2012 Sponsors</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:OWASP_IL_2012_Sponsors&amp;diff=135018"/>
				<updated>2012-08-29T20:05:38Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| &lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:GoldIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.idc.ac.il https://www.owasp.org/images/f/f1/OWASP_IL_Sponsors_IDC_New.JPG]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.seekersec.com https://www.owasp.org/images/4/45/SeekerIL.png]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.imperva.com https://www.owasp.org/images/8/89/OWASP_IL_Sponsors_Imperva.png]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.ey.com https://www.owasp.org/images/3/34/EY-IL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.akamai.com https://www.owasp.org/images/9/93/Akamai_logoIL.gif]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; [http://www.ibm.com/ https://www.owasp.org/images/a/a5/IBM-IL.png]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
| [http://www.radware.com https://www.owasp.org/images/a/a3/RadwareIL-Logo.jpg]&lt;br /&gt;
|-&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[File:SilverIL.png]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.grsee.co.il https://www.owasp.org/images/0/0d/GRSEEIL.jpg]&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[http://www.liveperson.com/ https://www.owasp.org/images/3/33/LivepersonIL.png]&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
| &amp;amp;nbsp;&amp;amp;nbsp;[http://www.rsa.com https://www.owasp.org/images/5/5e/RSA-IL.png]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp; [http://www.komodosec.com/ https://www.owasp.org/images/0/03/Komodo-small.jpg]&lt;br /&gt;
| &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; [http://www.secoz.com/ https://www.owasp.org/images/4/4e/SecOZ-ILLogo.jpg]&lt;br /&gt;
&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:RadwareIL-Logo.jpg&amp;diff=135017</id>
		<title>File:RadwareIL-Logo.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:RadwareIL-Logo.jpg&amp;diff=135017"/>
				<updated>2012-08-29T20:05:23Z</updated>
		
		<summary type="html">&lt;p&gt;Ofer Maor: uploaded a new version of &amp;amp;quot;File:RadwareIL-Logo.jpg&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ofer Maor</name></author>	</entry>

	</feed>