<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Steingra</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Steingra"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Steingra"/>
		<updated>2026-05-28T09:22:08Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=23829</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=23829"/>
				<updated>2007-12-03T18:43:38Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Thursday, December 13, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Thursday, December 13, 2007 ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
OWASP Bay Area will host its next meeting at the Stanford University Alumni Association Center on Thursday, December 13.  As usual attendance is free and food and beverages will be provided.  This will be an awesome event and a great opportunity to network with industry peers.  The event is open to the public; please forward this invite to your colleagues and friends who are interested in computer and application security.  &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and Holiday Reception (food &amp;amp; beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:15pm ... Ghosts in the Browser – Niels Provos, Google&amp;lt;br/&amp;gt;&lt;br /&gt;
7:15pm - 8:00pm ... Ph.D. Student Presentations – Adam Barth &amp;amp; Collin Jackson, Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
8:00pm - 8:30pm ... Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford Alumni Association Center&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
326 Galvez Street&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford, CA  94305&amp;lt;br/&amp;gt;&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/#mvt=m&amp;amp;gid1=21396976&amp;amp;q1=326+galvez+st%2C+stanford%2C+ca&amp;amp;trf=0&amp;amp;lon=-122.164643&amp;amp;lat=37.430552&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Ghosts in the Browser'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Presented by: Niels Provos, Ph.D., Google, Inc.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
As more users are connected to the Internet and conduct their daily activities electronically, computer users have become the target of an underground economy that infects hosts with malware or adware for financial gain. Unfortunately, even a single visit to an infected web site enables the attacker to detect vulnerabilities in the user’s applications and force the download a multitude of malware binaries. Frequently, this malware allows the adversary to gain full control of the compromised systems leading to the ex-filtration of sensitive information or installation of utilities that facilitate remote control of the host. We believe that such behavior is similar to our traditional understanding of botnets. However, the main difference is that web-based malware infections are pull-based and that the resulting command feedback loop is looser. To characterize the nature of this rising thread, we identify the four prevalent mechanisms used to inject malicious content on popular web sites: web server security, user contributed content, advertising and third-party widgets.  For each of these areas, we present examples of abuse found on the Internet. Our aim is to present the state of malware on the Web and emphasize the importance of this rising threat.&lt;br /&gt;
&lt;br /&gt;
'''Bio:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Based out of Mt.View, Niels Provos is a Senior Staff Engineer at Google, Inc.  His interests include research in Web-Based Malware, Distributed Denial of Service, Steganography, Cryptography and Computer and Network Security.  Niels studied Physics and Mathematics at University of Hamburg, Germany, and attended the University of Michigan as a graduate student where he earned both is Masters in Computer Science and his Ph.D. in Computer Science.  He has published countless research papers and recently authored the book Virtual Honeypots: From Tracking Botnets to Intrusion Detection.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Ph.D. Student Presentations'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Presented by: Adam Barth &amp;amp; Collin Jackson, Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Preview of OWASP Bay Area, Mandeep Khera&amp;lt;br/&amp;gt;&lt;br /&gt;
Mandeep will provide an outline of the goals and objectives for local OWASP affiliates in 2008.   &lt;br /&gt;
&lt;br /&gt;
Please RSVP by responding to this email or visit http://owaspdec2007.eventbrite.com&lt;br /&gt;
&lt;br /&gt;
Special thanks to Stanford University Alumni Association for hosting this event and to Cenzic and AppSec Consulting for sponsoring.&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=23828</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=23828"/>
				<updated>2007-12-03T18:42:52Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Thursday, December 13, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Thursday, December 13, 2007 ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
OWASP Bay Area will host its next meeting at the Stanford University Alumni Association Center on Thursday, December 13.  As usual attendance is free and food and beverages will be provided.  This will be an awesome event and a great opportunity to network with industry peers.  The event is open to the public; please forward this invite to your colleagues and friends who are interested in computer and application security.  &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and Holiday Reception (food &amp;amp; beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:15pm ... Ghosts in the Browser – Niels Provos, Google&amp;lt;br/&amp;gt;&lt;br /&gt;
7:15pm - 8:00pm ... Ph.D. Student Presentations – Adam Barth &amp;amp; Collin Jackson, Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
8:00pm - 8:30pm ... Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford Alumni Association Center&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
326 Galvez Street&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford, CA  94305&amp;lt;br/&amp;gt;&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/#mvt=m&amp;amp;gid1=21396976&amp;amp;q1=326+galvez+st%2C+stanford%2C+ca&amp;amp;trf=0&amp;amp;lon=-122.164643&amp;amp;lat=37.430552&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Ghosts in the Browser'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Presented by: Niels Provos, Ph.D., Google, Inc.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
As more users are connected to the Internet and conduct their daily activities electronically, computer users have become the target of an underground economy that infects hosts with malware or adware for financial gain. Unfortunately, even a single visit to an infected web site enables the attacker to detect vulnerabilities in the user’s applications and force the download a multitude of malware binaries. Frequently, this malware allows the adversary to gain full control of the compromised systems leading to the ex-filtration of sensitive information or installation of utilities that facilitate remote control of the host. We believe that such behavior is similar to our traditional understanding of botnets. However, the main difference is that web-based malware infections are pull-based and that the resulting command feedback loop is looser. To characterize the nature of this rising thread, we identify the four prevalent mechanisms used to inject malicious content on popular web sites: web server security, user contributed content, advertising and third-party widgets.  For each of these areas, we present examples of abuse found on the Internet. Our aim is to present the state of malware on the Web and emphasize the importance of this rising threat.&lt;br /&gt;
&lt;br /&gt;
'''Bio:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Based out of Mt.View, Niels Provos is a Senior Staff Engineer at Google, Inc.  His interests include research in Web-Based Malware, Distributed Denial of Service, Steganography, Cryptography and Computer and Network Security.  Niels studied Physics and Mathematics at University of Hamburg, Germany, and attended the University of Michigan as a graduate student where he earned both is Masters in Computer Science and his Ph.D. in Computer Science.  He has published countless research papers and recently authored the book Virtual Honeypots: From Tracking Botnets to Intrusion Detection.  &lt;br /&gt;
&lt;br /&gt;
'''Ph.D. Student Presentations'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Presented by: Adam Barth &amp;amp; Collin Jackson, Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Preview of OWASP Bay Area, Mandeep Khera&amp;lt;br/&amp;gt;&lt;br /&gt;
Mandeep will provide an outline of the goals and objectives for local OWASP affiliates in 2008.   &lt;br /&gt;
&lt;br /&gt;
Please RSVP by responding to this email or visit http://owaspdec2007.eventbrite.com&lt;br /&gt;
&lt;br /&gt;
Special thanks to Stanford University Alumni Association for hosting this event and to Cenzic and AppSec Consulting for sponsoring.&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=23827</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=23827"/>
				<updated>2007-12-03T18:41:53Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Thursday, December 13, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Thursday, December 13, 2007 ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
OWASP Bay Area will host its next meeting at the Stanford University Alumni Association Center on Thursday, December 13.  As usual attendance is free and food and beverages will be provided.  This will be an awesome event and a great opportunity to network with industry peers.  The event is open to the public; please forward this invite to your colleagues and friends who are interested in computer and application security.  &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and Holiday Reception (food &amp;amp; beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:15pm ... Ghosts in the Browser – Niels Provos, Google&amp;lt;br/&amp;gt;&lt;br /&gt;
7:15pm - 8:00pm ... Ph.D. Student Presentations – Adam Barth &amp;amp; Collin Jackson, Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
8:00pm - 8:30pm ... Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford Alumni Association Center&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
326 Galvez Street&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford, CA  94305&amp;lt;br/&amp;gt;&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
Map[http://maps.yahoo.com/#mvt=m&amp;amp;gid1=21396976&amp;amp;q1=326+galvez+st%2C+stanford%2C+ca&amp;amp;trf=0&amp;amp;lon=-122.164643&amp;amp;lat=37.430552&amp;amp;mag=3]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Ghosts in the Browser'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Presented by: Niels Provos, Ph.D., Google, Inc.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
As more users are connected to the Internet and conduct their daily activities electronically, computer users have become the target of an underground economy that infects hosts with malware or adware for financial gain. Unfortunately, even a single visit to an infected web site enables the attacker to detect vulnerabilities in the user’s applications and force the download a multitude of malware binaries. Frequently, this malware allows the adversary to gain full control of the compromised systems leading to the ex-filtration of sensitive information or installation of utilities that facilitate remote control of the host. We believe that such behavior is similar to our traditional understanding of botnets. However, the main difference is that web-based malware infections are pull-based and that the resulting command feedback loop is looser. To characterize the nature of this rising thread, we identify the four prevalent mechanisms used to inject malicious content on popular web sites: web server security, user contributed content, advertising and third-party widgets.  For each of these areas, we present examples of abuse found on the Internet. Our aim is to present the state of malware on the Web and emphasize the importance of this rising threat.&lt;br /&gt;
&lt;br /&gt;
'''Bio:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Based out of Mt.View, Niels Provos is a Senior Staff Engineer at Google, Inc.  His interests include research in Web-Based Malware, Distributed Denial of Service, Steganography, Cryptography and Computer and Network Security.  Niels studied Physics and Mathematics at University of Hamburg, Germany, and attended the University of Michigan as a graduate student where he earned both is Masters in Computer Science and his Ph.D. in Computer Science.  He has published countless research papers and recently authored the book Virtual Honeypots: From Tracking Botnets to Intrusion Detection.  &lt;br /&gt;
&lt;br /&gt;
'''Ph.D. Student Presentations'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Presented by: Adam Barth &amp;amp; Collin Jackson, Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Preview of OWASP Bay Area, Mandeep Khera&amp;lt;br/&amp;gt;&lt;br /&gt;
Mandeep will provide an outline of the goals and objectives for local OWASP affiliates in 2008.   &lt;br /&gt;
&lt;br /&gt;
Please RSVP by responding to this email or visit http://owaspdec2007.eventbrite.com&lt;br /&gt;
&lt;br /&gt;
Special thanks to Stanford University Alumni Association for hosting this event and to Cenzic and AppSec Consulting for sponsoring.&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=23826</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=23826"/>
				<updated>2007-12-03T18:40:12Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Thursday, December 13, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Thursday, December 13, 2007 ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
OWASP Bay Area will host its next meeting at the Stanford University Alumni Association Center on Thursday, December 13.  As usual attendance is free and food and beverages will be provided.  This will be an awesome event and a great opportunity to network with industry peers.  The event is open to the public; please forward this invite to your colleagues and friends who are interested in computer and application security.  &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and Holiday Reception (food &amp;amp; beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:15pm ... Ghosts in the Browser – Niels Provos, Google&amp;lt;br/&amp;gt;&lt;br /&gt;
7:15pm - 8:00pm ... Ph.D. Student Presentations – Adam Barth &amp;amp; Collin Jackson, Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
8:00pm - 8:30pm ... Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford Alumni Association Center&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
326 Galvez Street&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford, CA  94305&amp;lt;br/&amp;gt;&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/#mvt=m&amp;amp;gid1=21396976&amp;amp;q1=326+galvez+st%2C+stanford%2C+ca&amp;amp;trf=0&amp;amp;lon=-122.164643&amp;amp;lat=37.430552&amp;amp;mag=3]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Ghosts in the Browser'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Presented by: Niels Provos, Ph.D., Google, Inc.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
As more users are connected to the Internet and conduct their daily activities electronically, computer users have become the target of an underground economy that infects hosts with malware or adware for financial gain. Unfortunately, even a single visit to an infected web site enables the attacker to detect vulnerabilities in the user’s applications and force the download a multitude of malware binaries. Frequently, this malware allows the adversary to gain full control of the compromised systems leading to the ex-filtration of sensitive information or installation of utilities that facilitate remote control of the host. We believe that such behavior is similar to our traditional understanding of botnets. However, the main difference is that web-based malware infections are pull-based and that the resulting command feedback loop is looser. To characterize the nature of this rising thread, we identify the four prevalent mechanisms used to inject malicious content on popular web sites: web server security, user contributed content, advertising and third-party widgets.  For each of these areas, we present examples of abuse found on the Internet. Our aim is to present the state of malware on the Web and emphasize the importance of this rising threat.&lt;br /&gt;
&lt;br /&gt;
'''Bio:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Based out of Mt.View, Niels Provos is a Senior Staff Engineer at Google, Inc.  His interests include research in Web-Based Malware, Distributed Denial of Service, Steganography, Cryptography and Computer and Network Security.  Niels studied Physics and Mathematics at University of Hamburg, Germany, and attended the University of Michigan as a graduate student where he earned both is Masters in Computer Science and his Ph.D. in Computer Science.  He has published countless research papers and recently authored the book Virtual Honeypots: From Tracking Botnets to Intrusion Detection.  &lt;br /&gt;
&lt;br /&gt;
'''Ph.D. Student Presentations'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Presented by: Adam Barth &amp;amp; Collin Jackson, Stanford University&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Preview of OWASP Bay Area, Mandeep Khera&amp;lt;br/&amp;gt;&lt;br /&gt;
Mandeep will provide an outline of the goals and objectives for local OWASP affiliates in 2008.   &lt;br /&gt;
&lt;br /&gt;
Please RSVP by responding to this email or visit http://owaspdec2007.eventbrite.com&lt;br /&gt;
&lt;br /&gt;
Special thanks to Stanford University Alumni Association for hosting this event and to Cenzic and AppSec Consulting for sponsoring.&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=23825</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=23825"/>
				<updated>2007-12-03T18:37:41Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Thursday, December 13, 2007 ==&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
OWASP Bay Area will host its next meeting at the Stanford University Alumni Association Center on Thursday, December 13.  As usual attendance is free and food and beverages will be provided.  This will be an awesome event and a great opportunity to network with industry peers.  The event is open to the public; please forward this invite to your colleagues and friends who are interested in computer and application security.  &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and Holiday Reception (food &amp;amp; beverages)&lt;br /&gt;
6:30pm - 7:15pm ... Ghosts in the Browser – Niels Provos, Google&lt;br /&gt;
7:15pm - 8:00pm ... Ph.D. Student Presentations – Adam Barth &amp;amp; Collin Jackson, Stanford University&lt;br /&gt;
8:00pm - 8:30pm ... Networking Session&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Stanford Alumni Association Center&lt;br /&gt;
Stanford University&lt;br /&gt;
326 Galvez Street&lt;br /&gt;
Stanford, CA  94305&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/#mvt=m&amp;amp;gid1=21396976&amp;amp;q1=326+galvez+st%2C+stanford%2C+ca&amp;amp;trf=0&amp;amp;lon=-122.164643&amp;amp;lat=37.430552&amp;amp;mag=3]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Ghosts in the Browser&lt;br /&gt;
Presented by: Niels Provos, Ph.D., Google, Inc.&lt;br /&gt;
&lt;br /&gt;
Abstract:  As more users are connected to the Internet and conduct their daily activities electronically, computer users have become the target of an underground economy that infects hosts with malware or adware for financial gain. Unfortunately, even a single visit to an infected web site enables the attacker to detect vulnerabilities in the user’s applications and force the download a multitude of malware binaries. Frequently, this malware allows the adversary to gain full control of the compromised systems leading to the ex-filtration of sensitive information or installation of utilities that facilitate remote control of the host. We believe that such behavior is similar to our traditional understanding of botnets. However, the main difference is that web-based malware infections are pull-based and that the resulting command feedback loop is looser. To characterize the nature of this rising thread, we identify the four prevalent mechanisms used to inject malicious content on popular web sites: web server security, user contributed content, advertising and third-party widgets.  For each of these areas, we present examples of abuse found on the Internet. Our aim is to present the state of malware on the Web and emphasize the importance of this rising threat.&lt;br /&gt;
&lt;br /&gt;
Bio: Based out of Mt.View, Niels Provos is a Senior Staff Engineer at Google, Inc.  His interests include research in Web-Based Malware, Distributed Denial of Service, Steganography, Cryptography and Computer and Network Security.  Niels studied Physics and Mathematics at University of Hamburg, Germany, and attended the University of Michigan as a graduate student where he earned both is Masters in Computer Science and his Ph.D. in Computer Science.  He has published countless research papers and recently authored the book Virtual Honeypots: From Tracking Botnets to Intrusion Detection.  &lt;br /&gt;
&lt;br /&gt;
Ph.D. Student Presentations&lt;br /&gt;
Presented by: Adam Barth &amp;amp; Collin Jackson, Stanford University&lt;br /&gt;
&lt;br /&gt;
Preview of OWASP Bay Area, Mandeep Khera&lt;br /&gt;
Mandeep will provide an outline of the goals and objectives for local OWASP affiliates in 2008.   &lt;br /&gt;
&lt;br /&gt;
Please RSVP by responding to this email or visit http://owaspdec2007.eventbrite.com&lt;br /&gt;
&lt;br /&gt;
Special thanks to Stanford University Alumni Association for hosting this event and to Cenzic and AppSec Consulting for sponsoring.&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose-Archive&amp;diff=23824</id>
		<title>San Jose-Archive</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose-Archive&amp;diff=23824"/>
				<updated>2007-12-03T18:18:35Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Meeting - Tuesday, December 19, 2006 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Meeting - Tuesday, December 19, 2006 ==&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Fujitsu Advanced Networking Solutions&amp;lt;br/&amp;gt;&lt;br /&gt;
1240 E. Arques Ave.&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, CA 94085&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''New Trends and Web Application Security Statistics'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Jeremiah Grossman, Founder &amp;amp; CTO, WhiteHat Security'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' First Look at New Web Application Security Statistics.  The Top 10 Web Application Vulnerabilities and their  Impact on the Enterprise Web applications are the newest attack target, hitting the biggest and best brands on the Internet.  And yet, until now, there has been limited information available about the most prevalent and most severe vulnerabilities that are facilitating the rapidly rising number of attacks.&lt;br /&gt;
&lt;br /&gt;
WhiteHat Security founder and CTO, Jeremiah Grossman, will present the findings from the first WhiteHat Security Web Application Security Risk Report.  Based on WhiteHat’s aggregate data from hundreds of web application assessments, Mr.Grossman's presentation will provide a first-of-its-kind look at the top vulnerabilities that attackers are exploiting at businesses across the Web.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
•    Identify and discuss the top ten vulnerabilities &amp;lt;br/&amp;gt;&lt;br /&gt;
•    Define the severity levels of web application vulnerabilities &amp;lt;br/&amp;gt;&lt;br /&gt;
•    Present strategies for web application vulnerability management &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Mr. Grossman is a world-renowned expert in Web security and a founding member of the Web Application Security Consortium.  He is a frequent speaker at industry events including the BlackHat Briefings, ISACA’s Networks Security Conference, NASA, the Air Force and Technology Conference, ISSA and Defcon.  Mr. Grossman is also a featured expert and frequent contributor on TechTarget’s SearchAppSecurity.com.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Thursday, September 6, 2007 ==&lt;br /&gt;
&lt;br /&gt;
'''Pictures From the Event'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Garrett Gee was nice enough to take some pictures of the September 6th event.  They can be found here:&amp;lt;br/&amp;gt;&lt;br /&gt;
http://flickr.com/photos/ggee/sets/72157601905839040/ &lt;br /&gt;
&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Note:''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructors:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
Tom Stracener - Cenzic&amp;lt;br/&amp;gt;&lt;br /&gt;
Arian Evans - WhiteHat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
Kurt Opsahl, EFF &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com or send an email to brian.bertacini at owasp.org. Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21696</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21696"/>
				<updated>2007-09-12T16:06:52Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Thursday, September 6, 2007 ==&lt;br /&gt;
&lt;br /&gt;
'''Pictures From the Event'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Garrett Gee was nice enough to take some pictures of the September 6th event.  They can be found here:&amp;lt;br/&amp;gt;&lt;br /&gt;
http://flickr.com/photos/ggee/sets/72157601905839040/ &lt;br /&gt;
&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Note:''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructors:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
Tom Stracener - Cenzic&amp;lt;br/&amp;gt;&lt;br /&gt;
Arian Evans - WhiteHat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
Kurt Opsahl, EFF &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com or send an email to brian.bertacini at owasp.org. Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose_Archive&amp;diff=21695</id>
		<title>San Jose Archive</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose_Archive&amp;diff=21695"/>
				<updated>2007-09-12T15:48:37Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Wednesday, July 25, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:15pm ... Attacking XML Security - Brad Hill&amp;lt;br/&amp;gt;&lt;br /&gt;
7:15pm - 8:00pm ... Development of a Security Metric System to Rate Enterprise Software - Fredrick Lee&amp;lt;br/&amp;gt;&lt;br /&gt;
8:00pm - 8:30pm ... Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ariba&amp;lt;br/&amp;gt;&lt;br /&gt;
807 11th Avenue&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, Ca 94089&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ariba.com/company/hq_map.cfm Map and Directions]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Attacking XML Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brad Hill, iSEC Partners'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
Brad will present his ongoing research into attacking the XML Digital Signature and Encryption standards that underpin the security  of Web Services, mobile code, SAML, federated identity systems and more.  The talk will begin with a high-level, critical take on the emerging conventional wisdom about message-oriented security and continue with a detailed discussion of design and implementation weaknesses in the standards.  Technical material will include a root cause analysis of the recent iSEC advisory on cross-platform, remote code execution vulnerabilities discovered in multiple XML Digital Signature products. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.isecpartners.com/files/iSEC_HILL_AttackingXMLSecurity_bh07.pdf Presentation Link]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Based out of Seattle, Brad Hill is a Senior Security Consultant at iSEC Partners, a full-service security consulting firm that provides penetration testing, secure systems development, security education and software design verification.   Brad brings a ten year background as a software developer and architect in the technology and financial services sectors to his work at iSEC, where he does design review, application assessment and development lifecycle improvement for some of the world’s leading software companies.  &lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Development of a Security Metric System to Rate Enterprise Software'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Fredrick Lee, Fortify Software'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
As part of Fortify Software’s Java Open Review (JOR) project, both security defects and quality issues discovered in open source software are collected. The projects being analyzed are diverse in their development methodologies, development stages, and application styles. The projects range from small utility packages (e.g. Apache Commons), to mid-size intranet applications (e.g. JSPWiki), to large-scale, commercial grade enterprise projects (e.g. JBoss). In essence, participants in the Java Open Review project reflect the typical enterprise organization’s code base: a large collection of several small utility/internal applications and a handful of enterprise “flagship” products.&lt;br /&gt;
&lt;br /&gt;
As part of the project, we have been challenged to answer the question: Which&lt;br /&gt;
application is more “secure.” To answer this question, Fortify has sought to develop a set of metrics that combine lessons learned from our experience working on various enterprise code bases and our work on the JOR project. The metrics are designed to incorporate diverse criteria, including the size of the application, the types of vulnerabilities identified, and time required to fix the vulnerabilities. The metrics provide a mechanism to rate software components for security concerns and enable enterprises to:&lt;br /&gt;
&lt;br /&gt;
- Evaluate which open source projects offer an acceptable level of security &amp;lt;br/&amp;gt;&lt;br /&gt;
- Compare competing open source software solutions based on their security &amp;lt;br/&amp;gt;&lt;br /&gt;
- Measure internal development efforts against open source open source counterparts&lt;br /&gt;
&lt;br /&gt;
Ultimately, with sufficient industry adoption, the metrics can also enable enterprises to compare their internal efforts against other enterprises within the same vertical. As part of the talk we will present our experience to date working with companies to develop an effective mechanism for evaluating the security of enterprise software.&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Fredrick Lee is a member of Fortify Software’s Security Research Group, where he manages the Java Open Review Project. Scanning the code of over 100 applications so far, Fredrick is helping assess and improve the security of open source software. Fredrick also helps the Security Research Group develop the secure coding rules that are use to run Fortify’s suite of products. &lt;br /&gt;
 &lt;br /&gt;
Prior to joining Fortify Software, Fredrick was a Senior Information Security Engineer at Bank of America, where he helped roll out a secure development framework, performed security assessments, and developed enterprise security solutions. &lt;br /&gt;
 &lt;br /&gt;
Fredrick graduated from the University of Oklahoma, with a BS in Computer Engineering. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Upcoming Security Workshops'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brian Bertacini, Volunteer Chapter Organizer'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' Introduce local volunteer expert trainers that are planning web application and infrastructure security workshops.&lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.ariba.com Ariba] for hosting this event and to [http://www.appsecconsulting.com AppSec Consulting] and [http://www.isecpartners.com iSEC Partners] for sponsoring.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Thursday, April 12, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:30pm ... Past, Present and Future of Web Application Security in PCI - Bernie Weidel&amp;lt;br/&amp;gt;&lt;br /&gt;
7:30pm - 8:30pm ... Top Web Application Vulnerabilities, Exploits and Countermeasures - Josh Daymont&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ariba&amp;lt;br/&amp;gt;&lt;br /&gt;
807 11th Avenue&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, Ca 94089&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ariba.com/company/hq_map.cfm Map and Directions]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Past, Present and Future of Web Application Security in PCI'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Bernie Weidel - PCI Product Manager, Qualys'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
This presentation will start off with a holistic view of Ecommerce Data Security in contrast to the overall scope of Fraud in the Financial Services Industry, thereby giving insights as to why the PCI DSS was created by the Credit Card Brands and developed into its current form. Next, we will explore the current state of Web Application Security in the PCI DSS v1.1 and attempt to bring clarity to some of the more confusing items. We will also outline the structure of the PCI DSS Council; reviewing its key concepts and requirements. Lastly, we will outline methods you can use to proactively get involved in shaping future versions of the PCI DSS.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Bernie Weidel, Product Manager for QualysGuard PCI is responsible for evaluating customer/partner requirements, integrating them into the product, and driving PCI to market. Bernie has been developing methods to achieve and evidence compliance since 2000, when he designed a HIPAA compliance program for Scarborough Insurance Agency. Prior to joining Qualys, Bernie was an Infrastructure Security Project Manager at Adobe Systems where he implemented, managed and streamlined SOX and PCI compliance programs. He was also responsible for various aspects of security such as Web Application Security, Database Security, PDA Security and Vulnerability Management. Before Adobe, Bernie worked for Symbol Wireless Technologies as a Wireless Systems Analyst; designing, installing and troubleshooting/fine tuning Enterprise Wireless Networks.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Top Web Application Vulnerabilities, Exploits and Countermeasures'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Josh Daymont - Sr. Security Consultant, Fortify'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
This presentation will take a look at Web Application Security from the Front lines to the back offices of systems development. First, a look at the top vulnerabilities and how are they exploited. Then look beyond the front lines and explore countermeasures that can be implemented during the development process to protect applications and sensitive data after deployment.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About OWASP'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brian Bertacini, Volunteer chapter organizer'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' An overview of the Open Web Application Security Project (OWASP), current projects and feedback from the recent WebAppSec Conference in Seattle.  &lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.aribe.com Ariba] for hosting this event.&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose_Archive&amp;diff=21693</id>
		<title>San Jose Archive</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose_Archive&amp;diff=21693"/>
				<updated>2007-09-12T15:46:48Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: New page: ==Wednesday, July 25, 2007 == Open to the public, attendance is free  '''Agenda and Presentations:'''&amp;lt;br/&amp;gt; 6:00pm - 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt; 6:30pm - 7:15pm ... ...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Wednesday, July 25, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:15pm ... Attacking XML Security - Brad Hill&amp;lt;br/&amp;gt;&lt;br /&gt;
7:15pm - 8:00pm ... Development of a Security Metric System to Rate Enterprise Software - Fredrick Lee&amp;lt;br/&amp;gt;&lt;br /&gt;
8:00pm - 8:30pm ... Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ariba&amp;lt;br/&amp;gt;&lt;br /&gt;
807 11th Avenue&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, Ca 94089&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ariba.com/company/hq_map.cfm Map and Directions]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Attacking XML Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brad Hill, iSEC Partners'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
Brad will present his ongoing research into attacking the XML Digital Signature and Encryption standards that underpin the security  of Web Services, mobile code, SAML, federated identity systems and more.  The talk will begin with a high-level, critical take on the emerging conventional wisdom about message-oriented security and continue with a detailed discussion of design and implementation weaknesses in the standards.  Technical material will include a root cause analysis of the recent iSEC advisory on cross-platform, remote code execution vulnerabilities discovered in multiple XML Digital Signature products. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.isecpartners.com/files/iSEC_HILL_AttackingXMLSecurity_bh07.pdf Presentation Link]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Based out of Seattle, Brad Hill is a Senior Security Consultant at iSEC Partners, a full-service security consulting firm that provides penetration testing, secure systems development, security education and software design verification.   Brad brings a ten year background as a software developer and architect in the technology and financial services sectors to his work at iSEC, where he does design review, application assessment and development lifecycle improvement for some of the world’s leading software companies.  &lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Development of a Security Metric System to Rate Enterprise Software'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Fredrick Lee, Fortify Software'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
As part of Fortify Software’s Java Open Review (JOR) project, both security defects and quality issues discovered in open source software are collected. The projects being analyzed are diverse in their development methodologies, development stages, and application styles. The projects range from small utility packages (e.g. Apache Commons), to mid-size intranet applications (e.g. JSPWiki), to large-scale, commercial grade enterprise projects (e.g. JBoss). In essence, participants in the Java Open Review project reflect the typical enterprise organization’s code base: a large collection of several small utility/internal applications and a handful of enterprise “flagship” products.&lt;br /&gt;
&lt;br /&gt;
As part of the project, we have been challenged to answer the question: Which&lt;br /&gt;
application is more “secure.” To answer this question, Fortify has sought to develop a set of metrics that combine lessons learned from our experience working on various enterprise code bases and our work on the JOR project. The metrics are designed to incorporate diverse criteria, including the size of the application, the types of vulnerabilities identified, and time required to fix the vulnerabilities. The metrics provide a mechanism to rate software components for security concerns and enable enterprises to:&lt;br /&gt;
&lt;br /&gt;
- Evaluate which open source projects offer an acceptable level of security &amp;lt;br/&amp;gt;&lt;br /&gt;
- Compare competing open source software solutions based on their security &amp;lt;br/&amp;gt;&lt;br /&gt;
- Measure internal development efforts against open source open source counterparts&lt;br /&gt;
&lt;br /&gt;
Ultimately, with sufficient industry adoption, the metrics can also enable enterprises to compare their internal efforts against other enterprises within the same vertical. As part of the talk we will present our experience to date working with companies to develop an effective mechanism for evaluating the security of enterprise software.&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Fredrick Lee is a member of Fortify Software’s Security Research Group, where he manages the Java Open Review Project. Scanning the code of over 100 applications so far, Fredrick is helping assess and improve the security of open source software. Fredrick also helps the Security Research Group develop the secure coding rules that are use to run Fortify’s suite of products. &lt;br /&gt;
 &lt;br /&gt;
Prior to joining Fortify Software, Fredrick was a Senior Information Security Engineer at Bank of America, where he helped roll out a secure development framework, performed security assessments, and developed enterprise security solutions. &lt;br /&gt;
 &lt;br /&gt;
Fredrick graduated from the University of Oklahoma, with a BS in Computer Engineering. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Upcoming Security Workshops'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brian Bertacini, Volunteer Chapter Organizer'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' Introduce local volunteer expert trainers that are planning web application and infrastructure security workshops.&lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.ariba.com Ariba] for hosting this event and to [http://www.appsecconsulting.com AppSec Consulting] and [http://www.isecpartners.com iSEC Partners] for sponsoring.&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21223</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21223"/>
				<updated>2007-08-29T22:22:13Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Note:''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructors:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
Arian Evans - WhiteHat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anythingcan be done to restore confidence in e-commerce?&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
Kurt Opsahl, EFF &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com or send an email to brian.bertacini at owasp.org. Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21199</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21199"/>
				<updated>2007-08-28T21:51:14Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Note:''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:''' Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
Kurt Opsahl, EFF &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com or send an email to brian.bertacini at owasp.org. Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21106</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21106"/>
				<updated>2007-08-24T18:31:06Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Note:''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:''' Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com or send an email to brian.bertacini at owasp.org. Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21105</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21105"/>
				<updated>2007-08-24T18:30:40Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Note:''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:''' &amp;lt;br/&amp;gt;&lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com or send an email to brian.bertacini at owasp.org. Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21104</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21104"/>
				<updated>2007-08-24T18:28:40Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Map and Directions:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:''' &amp;lt;br/&amp;gt;&lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com or send an email to brian.bertacini at owasp.org. Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;    &lt;br /&gt;
&lt;br /&gt;
'''Note:'''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21103</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21103"/>
				<updated>2007-08-24T18:27:18Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Map and Directions:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:''' &amp;lt;br/&amp;gt;&lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com.  Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;    &lt;br /&gt;
&lt;br /&gt;
'''Note:'''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21102</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21102"/>
				<updated>2007-08-24T18:26:32Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Map and Directions:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:''' &lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com.  Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;    &lt;br /&gt;
&lt;br /&gt;
'''Note:'''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21101</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21101"/>
				<updated>2007-08-24T18:25:16Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map and Directions: &lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:''' &lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com.  Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;    &lt;br /&gt;
&lt;br /&gt;
'''Note:'''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21100</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21100"/>
				<updated>2007-08-24T18:24:36Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map and Directions: &lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:''' &lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com.  Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;    &lt;br /&gt;
&lt;br /&gt;
Note:  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21099</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21099"/>
				<updated>2007-08-24T18:24:03Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map and Directions: &lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:''' &lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &lt;br /&gt;
&lt;br /&gt;
Moderator:          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Panelists:&amp;lt;br/&amp;gt;&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com.  Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;    &lt;br /&gt;
&lt;br /&gt;
Note:  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21098</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21098"/>
				<updated>2007-08-24T18:22:24Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map and Directions: &lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:'''&lt;br /&gt;
&lt;br /&gt;
Siva Ram, CISA&amp;lt;br/&amp;gt;&lt;br /&gt;
Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &lt;br /&gt;
&lt;br /&gt;
Moderator:          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Panelists:&amp;lt;br/&amp;gt;&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com.  Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;    &lt;br /&gt;
&lt;br /&gt;
Note:  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21097</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21097"/>
				<updated>2007-08-24T18:21:36Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map and Directions: &lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:'''&lt;br /&gt;
&lt;br /&gt;
Siva Ram, CISA&amp;lt;br/&amp;gt;&lt;br /&gt;
Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &lt;br /&gt;
&lt;br /&gt;
Moderator:          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
Panelists:          Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
                    David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
                    Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
                    Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com.  Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;    &lt;br /&gt;
&lt;br /&gt;
Note:  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21096</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21096"/>
				<updated>2007-08-24T18:20:23Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map and Directions: &lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructor:'''&lt;br /&gt;
&lt;br /&gt;
Siva Ram, CISA&amp;lt;br/&amp;gt;&lt;br /&gt;
Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &lt;br /&gt;
&lt;br /&gt;
Moderator:          Alex Stamos, iSEC Partners&lt;br /&gt;
Panelists:          Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&lt;br /&gt;
                    David Pollino, Washington Mutual Bank&lt;br /&gt;
                    Robert Fly, Salesforce.com&lt;br /&gt;
                    Larry Pingree, Safeway (co-founder, Digital Forensics Association)&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com.  Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;    &lt;br /&gt;
&lt;br /&gt;
Note:  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=20591</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=20591"/>
				<updated>2007-08-03T18:23:37Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: /* Next Meeting - Wednesday, July 25, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Wednesday, July 25, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:15pm ... Attacking XML Security - Brad Hill&amp;lt;br/&amp;gt;&lt;br /&gt;
7:15pm - 8:00pm ... Development of a Security Metric System to Rate Enterprise Software - Fredrick Lee&amp;lt;br/&amp;gt;&lt;br /&gt;
8:00pm - 8:30pm ... Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ariba&amp;lt;br/&amp;gt;&lt;br /&gt;
807 11th Avenue&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, Ca 94089&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ariba.com/company/hq_map.cfm Map and Directions]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Attacking XML Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brad Hill, iSEC Partners'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
Brad will present his ongoing research into attacking the XML Digital Signature and Encryption standards that underpin the security  of Web Services, mobile code, SAML, federated identity systems and more.  The talk will begin with a high-level, critical take on the emerging conventional wisdom about message-oriented security and continue with a detailed discussion of design and implementation weaknesses in the standards.  Technical material will include a root cause analysis of the recent iSEC advisory on cross-platform, remote code execution vulnerabilities discovered in multiple XML Digital Signature products. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.isecpartners.com/files/iSEC_HILL_AttackingXMLSecurity_bh07.pdf Presentation Link]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Based out of Seattle, Brad Hill is a Senior Security Consultant at iSEC Partners, a full-service security consulting firm that provides penetration testing, secure systems development, security education and software design verification.   Brad brings a ten year background as a software developer and architect in the technology and financial services sectors to his work at iSEC, where he does design review, application assessment and development lifecycle improvement for some of the world’s leading software companies.  &lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Development of a Security Metric System to Rate Enterprise Software'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Fredrick Lee, Fortify Software'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
As part of Fortify Software’s Java Open Review (JOR) project, both security defects and quality issues discovered in open source software are collected. The projects being analyzed are diverse in their development methodologies, development stages, and application styles. The projects range from small utility packages (e.g. Apache Commons), to mid-size intranet applications (e.g. JSPWiki), to large-scale, commercial grade enterprise projects (e.g. JBoss). In essence, participants in the Java Open Review project reflect the typical enterprise organization’s code base: a large collection of several small utility/internal applications and a handful of enterprise “flagship” products.&lt;br /&gt;
&lt;br /&gt;
As part of the project, we have been challenged to answer the question: Which&lt;br /&gt;
application is more “secure.” To answer this question, Fortify has sought to develop a set of metrics that combine lessons learned from our experience working on various enterprise code bases and our work on the JOR project. The metrics are designed to incorporate diverse criteria, including the size of the application, the types of vulnerabilities identified, and time required to fix the vulnerabilities. The metrics provide a mechanism to rate software components for security concerns and enable enterprises to:&lt;br /&gt;
&lt;br /&gt;
- Evaluate which open source projects offer an acceptable level of security &amp;lt;br/&amp;gt;&lt;br /&gt;
- Compare competing open source software solutions based on their security &amp;lt;br/&amp;gt;&lt;br /&gt;
- Measure internal development efforts against open source open source counterparts&lt;br /&gt;
&lt;br /&gt;
Ultimately, with sufficient industry adoption, the metrics can also enable enterprises to compare their internal efforts against other enterprises within the same vertical. As part of the talk we will present our experience to date working with companies to develop an effective mechanism for evaluating the security of enterprise software.&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Fredrick Lee is a member of Fortify Software’s Security Research Group, where he manages the Java Open Review Project. Scanning the code of over 100 applications so far, Fredrick is helping assess and improve the security of open source software. Fredrick also helps the Security Research Group develop the secure coding rules that are use to run Fortify’s suite of products. &lt;br /&gt;
 &lt;br /&gt;
Prior to joining Fortify Software, Fredrick was a Senior Information Security Engineer at Bank of America, where he helped roll out a secure development framework, performed security assessments, and developed enterprise security solutions. &lt;br /&gt;
 &lt;br /&gt;
Fredrick graduated from the University of Oklahoma, with a BS in Computer Engineering. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Upcoming Security Workshops'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brian Bertacini, Volunteer Chapter Organizer'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' Introduce local volunteer expert trainers that are planning web application and infrastructure security workshops.&lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.ariba.com Ariba] for hosting this event and to [http://www.appsecconsulting.com AppSec Consulting] and [http://www.isecpartners.com iSEC Partners] for sponsoring.&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=17628</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=17628"/>
				<updated>2007-04-02T03:54:08Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, April 12, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:30pm ... Past, Present and Future of Web Application Security in PCI - Bernie Weidel&amp;lt;br/&amp;gt;&lt;br /&gt;
7:30pm - 8:30pm ... Top Web Application Vulnerabilities, Exploits and Countermeasures - Josh Daymont&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ariba&amp;lt;br/&amp;gt;&lt;br /&gt;
807 11th Avenue&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, Ca 94089&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ariba.com/company/hq_map.cfm Map and Directions]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Past, Present and Future of Web Application Security in PCI'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Bernie Weidel - PCI Product Manager, Qualys'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
This presentation will start off with a holistic view of Ecommerce Data Security in contrast to the overall scope of Fraud in the Financial Services Industry, thereby giving insights as to why the PCI DSS was created by the Credit Card Brands and developed into its current form. Next, we will explore the current state of Web Application Security in the PCI DSS v1.1 and attempt to bring clarity to some of the more confusing items. We will also outline the structure of the PCI DSS Council; reviewing its key concepts and requirements. Lastly, we will outline methods you can use to proactively get involved in shaping future versions of the PCI DSS.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Bernie Weidel, Product Manager for QualysGuard PCI is responsible for evaluating customer/partner requirements, integrating them into the product, and driving PCI to market. Bernie has been developing methods to achieve and evidence compliance since 2000, when he designed a HIPAA compliance program for Scarborough Insurance Agency. Prior to joining Qualys, Bernie was an Infrastructure Security Project Manager at Adobe Systems where he implemented, managed and streamlined SOX and PCI compliance programs. He was also responsible for various aspects of security such as Web Application Security, Database Security, PDA Security and Vulnerability Management. Before Adobe, Bernie worked for Symbol Wireless Technologies as a Wireless Systems Analyst; designing, installing and troubleshooting/fine tuning Enterprise Wireless Networks.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Top Web Application Vulnerabilities, Exploits and Countermeasures'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Josh Daymont - Sr. Security Consultant, Fortify'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
This presentation will take a look at Web Application Security from the Front lines to the back offices of systems development. First, a look at the top vulnerabilities and how are they exploited. Then look beyond the front lines and explore countermeasures that can be implemented during the development process to protect applications and sensitive data after deployment.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About OWASP'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brian Bertacini, Volunteer chapter organizer'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' An overview of the Open Web Application Security Project (OWASP), current projects and feedback from the recent WebAppSec Conference in Seattle.  &lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.aribe.com Ariba] for hosting this event.&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=17627</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=17627"/>
				<updated>2007-04-02T03:52:57Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, April 12, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:30pm ... Past, Present and Future of Web Application Security in PCI - Bernie Weidel&amp;lt;br/&amp;gt;&lt;br /&gt;
7:30pm - 8:30pm ... Top Web Application Vulnerabilities, Exploits and Countermeasures - Josh Daymont&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ariba&amp;lt;br/&amp;gt;&lt;br /&gt;
807 11th Avenue&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, Ca 94089&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ariba.com/company/hq_map.cfm Map and Directions]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Past, Present and Future of Web Application Security in PCI'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Bernie Weidel - PCI Product Manager, Qualys'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
This presentation will start off with a holistic view of Ecommerce Data Security in contrast to the overall scope of Fraud in the Financial Services Industry, thereby giving insights as to why the PCI DSS was created by the Credit Card Brands and developed into its current form. Next, we will explore the current state of Web Application Security in the PCI DSS v1.1 and attempt to bring clarity to some of the more confusing items. We will also outline the structure of the PCI DSS Council; reviewing its key concepts and requirements. Lastly, we will outline methods you can use to proactively get involved in shaping future versions of the PCI DSS.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Bernie Weidel, Product Manager for QualysGuard PCI is responsible for evaluating customer/partner requirements, integrating them into the product, and driving PCI to market. Bernie has been developing methods to achieve and evidence compliance since 2000, when he designed a HIPAA compliance program for Scarborough Insurance Agency. Prior to joining Qualys, Bernie was an Infrastructure Security Project Manager at Adobe Systems where he implemented, managed and streamlined SOX and PCI compliance programs. He was also responsible for various aspects of security such as Web Application Security, Database Security, PDA Security and Vulnerability Management. Before Adobe, Bernie worked for Symbol Wireless Technologies as a Wireless Systems Analyst; designing, installing and troubleshooting/fine tuning Enterprise Wireless Networks.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Top Web Application Vulnerabilities, Exploits and Countermeasures'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Josh Daymont - Sr. Security Consultant, Fortify'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
This presentation will take a look at Web Application Security from the Front lines to the back offices of systems development. First, a look at the top vulnerabilities and how are they exploited. Then look beyond the front lines and explore countermeasures that can be implemented during the development process to protect applications and sensitive data after deployment.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About OWASP'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brian Bertacini, Volunteer chapter organizer'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' An overview of the Open Web Application Security Project (OWASP), current projects and feedback from the recent WebAppSec Conference in Seattle.  &lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.fsba.com Fujitsu Advanced Networking Solutions] for hosting this event.&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose-Archive&amp;diff=17624</id>
		<title>San Jose-Archive</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose-Archive&amp;diff=17624"/>
				<updated>2007-04-02T03:34:59Z</updated>
		
		<summary type="html">&lt;p&gt;Steingra: New page: == Meeting - Tuesday, December 19, 2006 ==  '''Venue:'''&amp;lt;br/&amp;gt; Fujitsu Advanced Networking Solutions&amp;lt;br/&amp;gt; 1240 E. Arques Ave.&amp;lt;br/&amp;gt; Sunnyvale, CA 94085&amp;lt;br/&amp;gt;   '''New Trends and Web Applicati...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Meeting - Tuesday, December 19, 2006 ==&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Fujitsu Advanced Networking Solutions&amp;lt;br/&amp;gt;&lt;br /&gt;
1240 E. Arques Ave.&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, CA 94085&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''New Trends and Web Application Security Statistics'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Jeremiah Grossman, Founder &amp;amp; CTO, WhiteHat Security'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' First Look at New Web Application Security Statistics.  The Top 10 Web Application Vulnerabilities and their  Impact on the Enterprise Web applications are the newest attack target, hitting the biggest and best brands on the Internet.  And yet, until now, there has been limited information available about the most prevalent and most severe vulnerabilities that are facilitating the rapidly rising number of attacks.&lt;br /&gt;
&lt;br /&gt;
WhiteHat Security founder and CTO, Jeremiah Grossman, will present the findings from the first WhiteHat Security Web Application Security Risk Report.  Based on WhiteHat’s aggregate data from hundreds of web application assessments, Mr.Grossman's presentation will provide a first-of-its-kind look at the top vulnerabilities that attackers are exploiting at businesses across the Web.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
•    Identify and discuss the top ten vulnerabilities &amp;lt;br/&amp;gt;&lt;br /&gt;
•    Define the severity levels of web application vulnerabilities &amp;lt;br/&amp;gt;&lt;br /&gt;
•    Present strategies for web application vulnerability management &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Mr. Grossman is a world-renowned expert in Web security and a founding member of the Web Application Security Consortium.  He is a frequent speaker at industry events including the BlackHat Briefings, ISACA’s Networks Security Conference, NASA, the Air Force and Technology Conference, ISSA and Defcon.  Mr. Grossman is also a featured expert and frequent contributor on TechTarget’s SearchAppSecurity.com.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Steingra</name></author>	</entry>

	</feed>