<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Simon+Bennetts</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Simon+Bennetts"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Simon_Bennetts"/>
		<updated>2026-04-24T00:27:35Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Leeds_UK&amp;diff=93465</id>
		<title>Leeds UK</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Leeds_UK&amp;diff=93465"/>
				<updated>2010-11-21T22:34:05Z</updated>
		
		<summary type="html">&lt;p&gt;Simon Bennetts: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Leeds UK|extra=&lt;br /&gt;
&lt;br /&gt;
This is a new chapter and we are looking for enthusiatic new members to make this one of the best OWASP chapters. We are hoping to accumalate a good proportion of subject matter experts who will in turn be able to provide guidance and presentations for the benefit of all chapter members. So please join the mailing list and contribute. &lt;br /&gt;
&lt;br /&gt;
Details of your chapter Board members can be found here [[Leeds_UK_chapter_leaders]] &lt;br /&gt;
&lt;br /&gt;
The chapter email address is [mailto:owaspleeds@gmail.com owaspleeds@gmail.com]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Leeds_UK|emailarchives=http://lists.owasp.org/pipermail/owasp-Leeds_UK}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Leeds_UK&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 2011 Planned Meetings ==&lt;br /&gt;
&lt;br /&gt;
March&lt;br /&gt;
&lt;br /&gt;
June&lt;br /&gt;
&lt;br /&gt;
September&lt;br /&gt;
&lt;br /&gt;
December&lt;br /&gt;
&lt;br /&gt;
== Next Meeting ==&lt;br /&gt;
'''Date:''' Wednesday 8th December in Manchester&lt;br /&gt;
&lt;br /&gt;
'''Location:''' To be announced&lt;br /&gt;
&lt;br /&gt;
'''Schedule: 18:00 for 18:15 start'''&lt;br /&gt;
&lt;br /&gt;
'''18:20 - 18:30'''&lt;br /&gt;
&lt;br /&gt;
OWASP Chapter introduction. OWASP values and membership. Chapter information. &lt;br /&gt;
&lt;br /&gt;
''Jason Alexander - OWASP Leeds/Northern Chapter Board Member''&lt;br /&gt;
&lt;br /&gt;
'''18:30 - 19:15'''&lt;br /&gt;
&lt;br /&gt;
upSploit - Vulnerability Advisory Solution&lt;br /&gt;
&lt;br /&gt;
''Thomas Mackenzie''&lt;br /&gt;
&lt;br /&gt;
Over the past year a lot of vulnerabilities have been released out into the wild and a lot of discussion has been had on what ethical disclosure is. upSploit is an online web application / tool that can be used by researchers to release vulnerabilities as ethically as possible.&lt;br /&gt;
&lt;br /&gt;
The talk consists of a number of parts including: Information on vulnerability disclosure before upSploit was around, the creation / idea of upSploit and how it has helped and is helping the community at the moment.&lt;br /&gt;
&lt;br /&gt;
''Speaker Bio'' &lt;br /&gt;
&lt;br /&gt;
Tom studies a BSc (Hons) in Ethical Hacking for Computer Security at Northumbria University in Newcastle and worked part time for Wetherby based company RandomStorm conducting Web Penetration testing, External Penetration testing and building wireless analysis solutions. Tom found a vulnerability in WordPress back in February 2010 which helped him kickstart his career in infosec whilst still studying. Previously the Co-host of popular UK student podcast Disaster Protocol Tom now spend all the time away from that on the upSploit project making sure his team get stuff done!&lt;br /&gt;
&lt;br /&gt;
'''19:15 - 20:00'''&lt;br /&gt;
&lt;br /&gt;
Avoiding the CWE/SANS Top 25 Most Dangerous Programming Errors&lt;br /&gt;
&lt;br /&gt;
''Jason Steer - Solution Architect at Veracode''&lt;br /&gt;
&lt;br /&gt;
The CWE/SANS list of the Top 25 Most Dangerous Programming Errors is becoming the standard for developing secure applications in large enterprises. Even the State of New York and the Depository Trust &amp;amp; Clearing Corporation (DTCC) plan to implement procurement contracts that include language mandating application security.  Whether you manage internal development activities, work with third party developers or are developing commercial-of-the-shelf (COTS)  applications for enterprises, your mandate is clear- safeguard your code and avoid the CWE/SANS Top 25 Most Dangerous Programming Errors. &lt;br /&gt;
&lt;br /&gt;
During this presentation, Jason will discuss:&lt;br /&gt;
&lt;br /&gt;
Prevalence of attacks using vulnerabilities listed in the CWE/SANS Top 25&lt;br /&gt;
&lt;br /&gt;
CWE categories illustrated with code snippets in .NET, Java, and other languages&lt;br /&gt;
&lt;br /&gt;
Impact of attacks on your application and your customers&lt;br /&gt;
&lt;br /&gt;
Methods to identify, track and remediate these vulnerabilities&lt;br /&gt;
&lt;br /&gt;
Session attendees will leave armed with the necessary steps to ensure that they’re building secure applications.&lt;br /&gt;
&lt;br /&gt;
'''20:00 - 20:45'''&lt;br /&gt;
&lt;br /&gt;
OWASP Zed Attack Proxy&lt;br /&gt;
&lt;br /&gt;
''Simon Bennetts - Project Lead and technical team lead at Sage UK''&lt;br /&gt;
&lt;br /&gt;
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. &lt;br /&gt;
It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who a new to penetration testing.&lt;br /&gt;
&lt;br /&gt;
In this presentation Simon will explain why it was released, who it is aimed at and where it is headed.&lt;br /&gt;
&lt;br /&gt;
== Past Events ==&lt;br /&gt;
&lt;br /&gt;
'''2010 Dates'''&lt;br /&gt;
&lt;br /&gt;
[[15th_September_Leeds]]&lt;br /&gt;
&lt;br /&gt;
[[16th_june_Leeds]]&lt;br /&gt;
&lt;br /&gt;
[[17th March - Leeds]]&lt;br /&gt;
&lt;br /&gt;
'''2009 Dates'''&lt;br /&gt;
&lt;br /&gt;
[[14th October 2009 - Leeds]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:United Kingdom]]&lt;/div&gt;</summary>
		<author><name>Simon Bennetts</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:HttpOnly&amp;diff=85101</id>
		<title>Talk:HttpOnly</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:HttpOnly&amp;diff=85101"/>
				<updated>2010-06-18T13:41:38Z</updated>
		
		<summary type="html">&lt;p&gt;Simon Bennetts: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Tomcat configuration ==&lt;br /&gt;
&lt;br /&gt;
Tomcat versions from 5.5.28 and 6.0.19 support the HttpOnly cookie option.&lt;br /&gt;
&lt;br /&gt;
This is configured in the conf/context.xml file:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Context useHttpOnly=&amp;quot;true&amp;quot;&amp;gt;&lt;br /&gt;
 ...&lt;br /&gt;
 &amp;lt;/Context&amp;gt;&lt;br /&gt;
[[User:Simon Bennetts|Simon Bennetts]] 14:40, 18 June 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Simon Bennetts</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Securing_tomcat&amp;diff=85100</id>
		<title>Talk:Securing tomcat</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Securing_tomcat&amp;diff=85100"/>
				<updated>2010-06-18T13:40:58Z</updated>
		
		<summary type="html">&lt;p&gt;Simon Bennetts: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== InvokerServlet ==&lt;br /&gt;
There needs to be an addendum in here about disabling the InvokerServlet. See my blog entry at [[http://yet-another-dev.blogspot.com/2009/12/this-post-is-especially-for-anyone.html yet-another-dev.blogspot.com]] for details about why this is a bad idea. --[[User:Chris Schmidt|Chris Schmidt]] 22:03, 17 December 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== File permissions ==&lt;br /&gt;
&lt;br /&gt;
Hmm, what does &amp;quot;Make sure tomcat user has read/write access to /tmp&amp;quot; mean?  &lt;br /&gt;
&lt;br /&gt;
Tomcat creates a directory &amp;quot;temp&amp;quot;, not &amp;quot;tmp&amp;quot;, and read/write on a directory doesn't actually allow reading or writing.  I assume the intention is &amp;quot;chmod 700 temp&amp;quot;... would love if anyone can clarify.&lt;br /&gt;
[[User:Douglasheld|Douglasheld]] 18:06, 3 April 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Newer Tomcat branches ==&lt;br /&gt;
&lt;br /&gt;
This page is hopelessly outdated for anyone working with the Tomcat 6 branch.  We need to figure out the best way to document security measures for the different supported branches.&lt;br /&gt;
[[User:Ken|Ken]] 10:25, 20 March 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
I've not had call to use Tomcat 6, but in a few months I plan to start experimenting with the embedded version.  I don't mind expanding the article to have a section on 6 (and keep the section on 5.5), but I can't contribute anything just yet.  My preference would be a single article as it will cut down on duplication.  In the meantime, any differences, areas to cover, new features, etc. that others could note down will help speed things up. [[User:Dledmonds|Darren]] 09:11, 26 March 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== HttpOnly configuration ==&lt;br /&gt;
&lt;br /&gt;
Tomcat versions from 5.5.28 and 6.0.19 support the HttpOnly [http://www.owasp.org/index.php/HttpOnly] cookie option.&lt;br /&gt;
&lt;br /&gt;
This is configured in the conf/context.xml file:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Context useHttpOnly=&amp;quot;true&amp;quot;&amp;gt;&lt;br /&gt;
 ...&lt;br /&gt;
 &amp;lt;/Context&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[User:Simon Bennetts|Simon Bennetts]] 14:40, 18 June 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Simon Bennetts</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:HttpOnly&amp;diff=85099</id>
		<title>Talk:HttpOnly</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:HttpOnly&amp;diff=85099"/>
				<updated>2010-06-18T13:37:04Z</updated>
		
		<summary type="html">&lt;p&gt;Simon Bennetts: Created page with '== Tomcat configuration ==  Tomcat versions from 5.5.28 and 6.0.19 support the HttpOnly cookie option.  This is configured in the conf/context.xml file:   &amp;lt;Context useHttpOnly=&amp;quot;t…'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Tomcat configuration ==&lt;br /&gt;
&lt;br /&gt;
Tomcat versions from 5.5.28 and 6.0.19 support the HttpOnly cookie option.&lt;br /&gt;
&lt;br /&gt;
This is configured in the conf/context.xml file:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Context useHttpOnly=&amp;quot;true&amp;quot;&amp;gt;&lt;br /&gt;
 ...&lt;br /&gt;
 &amp;lt;/Context&amp;gt;&lt;/div&gt;</summary>
		<author><name>Simon Bennetts</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Securing_tomcat&amp;diff=85098</id>
		<title>Talk:Securing tomcat</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Securing_tomcat&amp;diff=85098"/>
				<updated>2010-06-18T13:36:17Z</updated>
		
		<summary type="html">&lt;p&gt;Simon Bennetts: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== InvokerServlet ==&lt;br /&gt;
There needs to be an addendum in here about disabling the InvokerServlet. See my blog entry at [[http://yet-another-dev.blogspot.com/2009/12/this-post-is-especially-for-anyone.html yet-another-dev.blogspot.com]] for details about why this is a bad idea. --[[User:Chris Schmidt|Chris Schmidt]] 22:03, 17 December 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== File permissions ==&lt;br /&gt;
&lt;br /&gt;
Hmm, what does &amp;quot;Make sure tomcat user has read/write access to /tmp&amp;quot; mean?  &lt;br /&gt;
&lt;br /&gt;
Tomcat creates a directory &amp;quot;temp&amp;quot;, not &amp;quot;tmp&amp;quot;, and read/write on a directory doesn't actually allow reading or writing.  I assume the intention is &amp;quot;chmod 700 temp&amp;quot;... would love if anyone can clarify.&lt;br /&gt;
[[User:Douglasheld|Douglasheld]] 18:06, 3 April 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Newer Tomcat branches ==&lt;br /&gt;
&lt;br /&gt;
This page is hopelessly outdated for anyone working with the Tomcat 6 branch.  We need to figure out the best way to document security measures for the different supported branches.&lt;br /&gt;
[[User:Ken|Ken]] 10:25, 20 March 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
I've not had call to use Tomcat 6, but in a few months I plan to start experimenting with the embedded version.  I don't mind expanding the article to have a section on 6 (and keep the section on 5.5), but I can't contribute anything just yet.  My preference would be a single article as it will cut down on duplication.  In the meantime, any differences, areas to cover, new features, etc. that others could note down will help speed things up. [[User:Dledmonds|Darren]] 09:11, 26 March 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== HttpOnly configuration ==&lt;br /&gt;
&lt;br /&gt;
Tomcat versions from 5.5.28 and 6.0.19 support the HttpOnly [http://www.owasp.org/index.php/HttpOnly] cookie option.&lt;br /&gt;
&lt;br /&gt;
This is configured in the conf/context.xml file:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Context useHttpOnly=&amp;quot;true&amp;quot;&amp;gt;&lt;br /&gt;
 ...&lt;br /&gt;
 &amp;lt;/Context&amp;gt;&lt;/div&gt;</summary>
		<author><name>Simon Bennetts</name></author>	</entry>

	</feed>