<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Rally1</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Rally1"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Rally1"/>
		<updated>2026-04-21T01:10:50Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Newsletter_8&amp;diff=17889</id>
		<title>OWASP Newsletter 8</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Newsletter_8&amp;diff=17889"/>
				<updated>2007-04-17T13:01:52Z</updated>
		
		<summary type="html">&lt;p&gt;Rally1: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;''Sent to owasp-all mailing list on 17 April 2007''  __NOEDITSECTION__&lt;br /&gt;
==  OWASP Newsletter #8 (17-Apr-2007) ==&lt;br /&gt;
A bit later than normal, welcome to the 8th OWASP Newsletter, featuring the [[OWASP Spring Of Code 2007]], details on the [[6th_OWASP_AppSec_Conference_-_Italy_2007|6th AppSec Conference]], the [[:Category:OWASP Code Review Project|Code Review Project]], the [[:Category:OWASP WeBekci Project|WeBekci Project]] and the [[:Category:OWASP Code Review Project|OWASP Code Review Project]] is seeking for volunteers.&lt;br /&gt;
&lt;br /&gt;
Note that we also scan blogs for OWASP references.&lt;br /&gt;
&lt;br /&gt;
If you have any content to add to the next edition, feel free to add it directly to its WIKI page ([[OWASP Newsletter 9]]).&lt;br /&gt;
&lt;br /&gt;
Sebastien Deleersnyder&lt;br /&gt;
&lt;br /&gt;
Belgium Chapter Leader&lt;br /&gt;
&lt;br /&gt;
== Featured Item: [[OWASP Spring Of Code 2007]] ==&lt;br /&gt;
&lt;br /&gt;
We have received lots of [[OWASP Spring Of Code 2007 Applications]]! The submission period is now closed. The OWASP board is now evaluating the proposals and will publish the results as soon as possible.&lt;br /&gt;
&lt;br /&gt;
== Featured Item: Milan (Italy) Conference Agenda details! ==&lt;br /&gt;
&lt;br /&gt;
Join us for our [[6th_OWASP_AppSec_Conference_-_Italy_2007|6th AppSec Conference]] May 15-17 in Milan, Italy. Microsoft will be presenting &amp;quot;The Benefits of the SDL initiative to Microsoft and its Customers&amp;quot; and there will be expert talks on Web Services Security, Securing AJAX, the Microsoft Secure Development Lifecycle, all the new OWASP projects, and much more. &lt;br /&gt;
&lt;br /&gt;
== Featured Project: [[:Category:OWASP Code Review Project|OWASP Code Review Project]] ==&lt;br /&gt;
The OWASP Code Review project was concieved by Eoin Keary the OWASP Ireland Founder and Chapter Lead. We are actively seeking techies to add new sections as new web technologies emerge. Need help on this one, don't be shy, all help appreciated.&lt;br /&gt;
&lt;br /&gt;
View the [[OWASP Code Review Project Roadmap]].&lt;br /&gt;
&lt;br /&gt;
== Featured Project: [[:Category:OWASP WeBekci Project|OWASP WeBekci Project]] ==&lt;br /&gt;
WeBekci is a web based ModSecurity 2.x management tool. WeBekci is written in PHP, Its backend is powered by MySQL and the frontend by XAJAX framework. It will remove management overhead of ModSecurity 2.x. You can configure modsecurity.conf, add special rules and watch system, apache and modsecurity logs (only guardianlog has been implemented in this version). &lt;br /&gt;
&lt;br /&gt;
== Web Application Security Metrics Survey Participants Needed ==&lt;br /&gt;
Since meaningful web application security metrics are very lacking, the [[:Category:OWASP_Application_Security_Metrics_Project|Web Application Security Metrics]] seeks to identify and provide the web application security community with a basic set of application security metrics that have been found by contributors to be effective in measuring web application security effectiveness.   &lt;br /&gt;
&lt;br /&gt;
Since this Project was launched, it has proven to be challenging to get survey participants (e.g., customers too busy or have no metrics).  As a result, Bob Austin (the project leader) is turning directly to you:the OWASP community. He would be very grateful to OWASP members who are willing to take 30 minutes to complete a survey with him by phone (and/or to support collection of metric data from an organization you support).  The key data he seeks is as follows: &lt;br /&gt;
* Description of Metric, &lt;br /&gt;
* why the metric was created, &lt;br /&gt;
* how the metric is created, &lt;br /&gt;
* source of the data used to produce the metric, &lt;br /&gt;
* and how is the metric used.&lt;br /&gt;
&lt;br /&gt;
Bob can be contacted at  austinb &amp;lt;at&amp;gt; korelogic &amp;lt;dot&amp;gt; com or +1.804.379.4656&lt;br /&gt;
&lt;br /&gt;
== Latest additions to the WIKI ==&lt;br /&gt;
&lt;br /&gt;
==== New Pages====&lt;br /&gt;
* [[‎Denver February 2007 meeting]]&lt;br /&gt;
* [[‎6th OWASP AppSec Conference - Italy 2007/Agenda]]&lt;br /&gt;
* [[‎Comprehensive list of Threats to Authentication Procedures and Data]]&lt;br /&gt;
* [[‎WebScarab SSL Certificates]]&lt;br /&gt;
&lt;br /&gt;
==== Updated pages==== &lt;br /&gt;
Updated chapter pages:&lt;br /&gt;
* [[Taiwan]]&lt;br /&gt;
* [[Phoenix]]&lt;br /&gt;
* [[New Jersey]]&lt;br /&gt;
* [[Switzerland]]&lt;br /&gt;
* [[OWASP Community]]&lt;br /&gt;
* [[Greece]]&lt;br /&gt;
* [[Belgium]]&lt;br /&gt;
* [[Denver]]&lt;br /&gt;
* [[Washington DC]]&lt;br /&gt;
* [[Boston]]&lt;br /&gt;
* [[London]]&lt;br /&gt;
* [[Virginia (Northern Virginia)]]&lt;br /&gt;
* [[San Francisco]]&lt;br /&gt;
* [[SoCal]]&lt;br /&gt;
&lt;br /&gt;
Other pages:&lt;br /&gt;
* [[OWASP Spring Of Code 2007 Applications]]&lt;br /&gt;
* [[Testing for Directory Traversal]]&lt;br /&gt;
* [[Testing for Session Management Schema]]&lt;br /&gt;
* [[OWASP Education Presentation‎]]&lt;br /&gt;
* [[Phishing]]&lt;br /&gt;
* [[Comprehensive list of Threats to Authentication Procedures and Data]]&lt;br /&gt;
* [[Authentication Error‎]]&lt;br /&gt;
* [[:Category:OWASP Interceptor Project]]&lt;br /&gt;
* [[:Category:OWASProfiler Project]]&lt;br /&gt;
* [[OWASP AppSec Conference Sponsors]]&lt;br /&gt;
* [[:Category:OWASP WebGoat Project]]&lt;br /&gt;
* [[Fuzzing]]&lt;br /&gt;
* [[:Category:OWASP WeBekci Project]]&lt;br /&gt;
* [[Main Page]]&lt;br /&gt;
* [[:Category:OWASP AJAX Security Project]]&lt;br /&gt;
* [[OWASP Code Review Guide Table of Contents]]&lt;br /&gt;
* [[Java Security Frameworks]]&lt;br /&gt;
* [[OWASP Java Table of Contents]]&lt;br /&gt;
* [[PDF Attack Filter for Apache mod rewrite]]&lt;br /&gt;
* [[Member Offers]]&lt;br /&gt;
* [[Data Validation]]&lt;br /&gt;
* [[OWASP Application Security FAQ]]&lt;br /&gt;
* [[Phoenix/Tools]]&lt;br /&gt;
* [[OWASP Tiger]]&lt;br /&gt;
&lt;br /&gt;
==== New Documents &amp;amp; Presentations from chapters ==== &lt;br /&gt;
For a complete list of chapter presentations see [[OWASP_Education_Presentation|the online table of presentations]].&lt;br /&gt;
&lt;br /&gt;
==== Latest Blog entries ==== &lt;br /&gt;
* [http://blogs.owasp.org/diniscruz/2007/03/26/lists-of-tools-for-vmware-box/ Lists of tools for VMWare box]&lt;br /&gt;
* [http://blogs.owasp.org/orizon/2007/03/19/today-mantra/ Today mantra]&lt;br /&gt;
&lt;br /&gt;
==== OWASP Community====&lt;br /&gt;
* '''May 15 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
* '''May 10 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
* '''May 9 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
* '''May 9 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
* '''May 8 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
* '''May 2 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
* '''May 1 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
* '''May 21 (14:00h) - [[Israel|2nd OWASP Israel mini conference]]'''&lt;br /&gt;
* '''Apr 26 (17:00h) - [[Switzerland|Switzerland chapter meeting and &amp;quot;Swiss Security Dinner&amp;quot;]]'''&lt;br /&gt;
* '''Apr 20 (19:00h) - [[Hong Kong|Hong Kong chapter meeting - Objectives for 2007]]'''&lt;br /&gt;
* '''Apr 17 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
* '''Apr 12 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
* '''Apr 11 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
* '''Apr 10 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
* '''Apr 4 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
* '''Apr 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
* '''Mar 30 - [[http://www.owasp.org/index.php/Italy#March_30th.2C_2007_-_Master_in_Security_-_University_of_Rome_.22La_Sapienza.22| Italy@Master in Security at &amp;quot;La Sapienza&amp;quot;]]'''&lt;br /&gt;
&lt;br /&gt;
== OWASP references in the Media / Blogs ==&lt;br /&gt;
* [http://www.windowsitpro.com/Article/ArticleID/95598/Windows_95598.html SANS Launches Security Certification for Programmers]&lt;br /&gt;
* [http://denimgroup.typepad.com/denim_group/2007/03/web_application.html Web Application Remediation - OWASP San Antonio Meeting Tomorrow]&lt;br /&gt;
* [http://www.disenchant.ch/blog/owasp-meeting-and-swiss-security-dinner/54 OWASP Meeting and “Swiss Security Dinner”]&lt;br /&gt;
* [http://ajaxian.com/archives/owasp-testing-guide-20 OWASP Testing Guide 2.0]&lt;br /&gt;
* [http://shiflett.org/blog/2007/mar/owasp-spring-of-code-2007 OWASP Spring of Code 2007]&lt;br /&gt;
* [http://www.darknet.org.uk/2007/03/jbrofuzz-05-from-owasp-stateless-network-protocol-fuzzer/ JBroFuzz 0.5 from OWASP - Stateless Network Protocol Fuzzer]&lt;br /&gt;
* [http://www.disenchant.ch/blog/owasp-appsec-conference-italy-2007/60 OWASP AppSec Conference - Italy 2007]&lt;br /&gt;
* [http://www.javascriptsearch.com/news/press/070413WhiteHat.html WhiteHat Security Chief Technology Officer Jeremiah Grossman To Present at OWASP New York/New Jersey Meeting]&lt;br /&gt;
* [http://www.darkreading.com/document.asp?doc_id=120550&amp;amp;WT.svl=news1_1 Security's New School]&lt;/div&gt;</summary>
		<author><name>Rally1</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Application_Security_Metrics_Project_Roadmap&amp;diff=17882</id>
		<title>Category:OWASP Application Security Metrics Project Roadmap</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Application_Security_Metrics_Project_Roadmap&amp;diff=17882"/>
				<updated>2007-04-16T20:10:00Z</updated>
		
		<summary type="html">&lt;p&gt;Rally1: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Subject to Contributor feedback, the following Roadmap is proposed.  Phase One tasks are more specifically defined.  Phase Two tasks will be developed and defined over time based on Phase One experience.&lt;br /&gt;
&lt;br /&gt;
== Proposed Project Phases: ==&lt;br /&gt;
&lt;br /&gt;
'''Phase One - Collect and Provide Proven Metrics'''&lt;br /&gt;
&lt;br /&gt;
The objective is to provide useful current state metrics to the OWASP community in the near-term.&lt;br /&gt;
&lt;br /&gt;
'''Phase Two - Develop “Next Generation” metrics'''&lt;br /&gt;
&lt;br /&gt;
Develop new metrics using Contributor feedback on Phase One metrics and metrics that organizations have asked for but do not currently exist.&lt;br /&gt;
&lt;br /&gt;
== Summary of Proposed Phase One Tasks ==&lt;br /&gt;
&lt;br /&gt;
* Comment Period for Proposed Project Approach, Solicit Contributor Support&lt;br /&gt;
* Develop Metric Collection Survey Instrument&lt;br /&gt;
* Solicit Organizational Participants&lt;br /&gt;
* Conduct Metric Collection Survey&lt;br /&gt;
* Organize and Analyze Collected Survey Data&lt;br /&gt;
* Prepare Draft Findings and Provide to Reviewers&lt;br /&gt;
* Comment Period for Published Draft Findings&lt;br /&gt;
* Publish Final Findings, Metrics and Resources&lt;br /&gt;
* Conduct Phase One Project Post-Mortem&lt;br /&gt;
&lt;br /&gt;
== Detailed Phase One Tasks ==&lt;br /&gt;
&lt;br /&gt;
'''Task 1 – Comment Period for Proposed Project Approach'''&lt;br /&gt;
&lt;br /&gt;
Solicit Contributor feedback to ensure the most effective and widely supported approach. &lt;br /&gt;
&lt;br /&gt;
Target Time Frame: Completed&lt;br /&gt;
Current Status:	Call for Contributors &lt;br /&gt;
&lt;br /&gt;
'''Task 2 – Develop Metric Collection Survey Instrument'''&lt;br /&gt;
&lt;br /&gt;
Develop a survey instrument that can be used by Contributors to gather metrics data in a uniform fashion.  Design considerations will include “organizational” demographic data required (e.g., industry vertical), the format of the metric description, etc.  Ideally, we can categorize the metric types using a standard nomenclature.  The final survey instrument will be based on the 80/20 principle – developing the “perfect” instrument will excessively delay the Project.  Contributor support in developing a survey form that will allow efficient data aggregation and analysis would be appreciated (or at least ideas how this could be accomplished).  &lt;br /&gt;
&lt;br /&gt;
Target Time Frame: August, 2006&lt;br /&gt;
Current Status:	Completed&lt;br /&gt;
Contributors:	Bob Austin&lt;br /&gt;
&lt;br /&gt;
'''Task 3– Solicit Organizational Participants'''&lt;br /&gt;
&lt;br /&gt;
Contributors will be asked to approach organizations that are known to have effective metrics in use and request their (anonymous) participation in the survey. It may be wise to limit the number of organizations participating in the survey to 30 or so organizations.  One incentive to participate is the sharing of current “best practice” metrics.   From a confidentiality perspective, each Contributor would ensure that data provided by an organization is sanitized to ensure anonymity.&lt;br /&gt;
&lt;br /&gt;
Target Time Frame: Complete by August 15, 2006&lt;br /&gt;
Current Status:	Need more survey participants!&lt;br /&gt;
&lt;br /&gt;
'''Task 4 – Conduct Metric Collection Survey'''&lt;br /&gt;
&lt;br /&gt;
Using the survey instrument, collect survey data.  It may be wise to conduct a “pilot” survey with 1 or 2 organizations, make fine-tuning adjustments to the survey instrument, and then complete the surveys.&lt;br /&gt;
&lt;br /&gt;
Target Time Frame: Complete by September 15, 2006 (this date is particularly dependent upon Contributor support)&lt;br /&gt;
Current Status:	Need more survey participants to complete!&lt;br /&gt;
&lt;br /&gt;
'''Task 5 – Organize and Analyze Collected Survey Data'''&lt;br /&gt;
&lt;br /&gt;
This will involve merging and organizing the collected data to allow effective analysis and presentation of the data. &lt;br /&gt;
&lt;br /&gt;
Target Time Frame:	&lt;br /&gt;
Current Status:	Need more survey data to complete!&lt;br /&gt;
&lt;br /&gt;
'''Task 6 – Prepare Draft Findings and Provide to Reviewers'''&lt;br /&gt;
&lt;br /&gt;
We envision capturing a number of key data points including a description of metrics used, consumers of the metrics, length of time used, barriers to metric collection, metrics needed, planned metrics initiatives, useful tools/resources that facilitate metrics collection/analysis, etc.  We also will attempt to provide insight into management’s interest and support for the metrics program.&lt;br /&gt;
&lt;br /&gt;
Target Time Frame:	&lt;br /&gt;
Current Status:	Call for Volunteers&lt;br /&gt;
&lt;br /&gt;
'''Task 7 – Comment Period for Published Draft Findings'''&lt;br /&gt;
&lt;br /&gt;
Solicit feedback from the OWASP community, address errors/ambiguity.  Make edits based on feedback.&lt;br /&gt;
&lt;br /&gt;
Target Time Frame:	&lt;br /&gt;
Current Status:	Call for Volunteers&lt;br /&gt;
&lt;br /&gt;
'''Task 8 – Publish Final Findings, Metrics, and Resources'''&lt;br /&gt;
&lt;br /&gt;
Self-explanatory.  Ideally, present the metrics in a way that Contributors can continue to add to and comment on over time.  Create a Resources Page that incorporates the resources recommended by survey participants.&lt;br /&gt;
&lt;br /&gt;
Target Time Frame:	&lt;br /&gt;
Current Status:	Call for Volunteers&lt;br /&gt;
&lt;br /&gt;
'''Task 9 – Conduct Phase One Project Post-Mortem'''&lt;br /&gt;
&lt;br /&gt;
Solicit feedback and lessons learned on Phase One to improve Phase Two approach.&lt;br /&gt;
&lt;br /&gt;
Target Time Frame:&lt;br /&gt;
Current Status:	Call for Volunteers&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Application Security Metrics Project]]&lt;/div&gt;</summary>
		<author><name>Rally1</name></author>	</entry>

	</feed>