<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Tanyajanca</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Tanyajanca"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Tanyajanca"/>
		<updated>2026-05-28T04:05:04Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=250645</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=250645"/>
				<updated>2019-04-25T12:51:03Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: /* Description */   More updates&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP [http://devslop.co DevSlop] Tool Project==&lt;br /&gt;
''DevSlop: learning how application security professionals fit into DevOps.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Project Website:  [http://devslop.co DevSlop]&lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services, however this changing landscape means security people need to step up their game.  DevSlop, &amp;quot;Sloppy DevOps&amp;quot;, is an exploration into this area, via several different modules consisting of pipelines, vulnerable apps, and [https://www.youtube.com/channel/UCSmjcWvgVBqF3x_7e5rfe3A The DevSlop Show], where project members learn and share. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop has many modules, including:&lt;br /&gt;
&lt;br /&gt;
'''Patty''' - An Azure DevSecOps pipeline, with constantly changing components, which published the project's website, [http://devslop.co DevSlop.co].&lt;br /&gt;
&lt;br /&gt;
'''Pixi-CRS''' &amp;amp; '''Pixi-CRS-ZAP''' are two Circle-CI pipelines that demonstrate adding a WAF to your pipeline for automatic tuning before moving your apps to prod.&lt;br /&gt;
&lt;br /&gt;
'''Pixi''' is an intentionally vulnerable app and consists of a vulnerable web app and API service.  &lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/channel/UCSmjcWvgVBqF3x_7e5rfe3A '''The DevSlop Show'''] is a video streaming series where project members build things live, interview members of the OWASP and InfoSec community, and learn where they fit into DevOps.&lt;br /&gt;
&lt;br /&gt;
[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of [http://devslop.co DevSlop] are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/DevSlop/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
Nancy Gariché [https://twitter.com/nanzgtweets Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
&lt;br /&gt;
[[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
[[User:Mordecai Kraushar|Mordecai Kraushar]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* Nancy Gariché was promoted to leader, making 3 leaders of this project! &lt;br /&gt;
* [http://devslop.co/Home/Schedule Check out our schedule!] &lt;br /&gt;
* [July 2] Tanya Janca will be giving the &amp;quot;Hack Your Own Apps&amp;quot; workshop at the [https://www.spaconference.org/spa2018 SPA Conference in London], England. &lt;br /&gt;
* [June 4-6, 2018] The entire DevSlop team will be at the [https://owaspsummit.org/ Open Security Summit] in London, England. &lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/OWASP_DevSlop DevSlop on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter]&lt;br /&gt;
* Nancy Gariché [https://twitter.com/nanzgtweets Twitter] &lt;br /&gt;
* Nicole Becher [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
* [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=250644</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=250644"/>
				<updated>2019-04-25T12:48:35Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: /* OWASP DevSlop Tool Project */ Updated project description&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP [http://devslop.co DevSlop] Tool Project==&lt;br /&gt;
''DevSlop: learning how application security professionals fit into DevOps.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Project Website:  [http://devslop.co DevSlop]&lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services, however this changing landscape means security people need to step up their game.  DevSlop, &amp;quot;Sloppy DevOps&amp;quot;, is an exploration into this area, via several different modules consisting of pipelines, vulnerable apps, and [https://www.youtube.com/channel/UCSmjcWvgVBqF3x_7e5rfe3A The DevSlop Show], where project members learn and share. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop has many modules, including:&lt;br /&gt;
&lt;br /&gt;
'''Patty''' - An Azure DevSecOps pipeline, with constantly changing components, which published the project's website, [http://devslop.co DevSlop.co].&lt;br /&gt;
&lt;br /&gt;
'''Pixi-CRS''' &amp;amp; '''Pixi-CRS-ZAP''' are two Circle-CI pipelines that demonstrate adding a WAF to your pipeline for automatic tuning before moving your apps to prod.&lt;br /&gt;
&lt;br /&gt;
'''Pixi''' is an intentionally vulnerable app and consists of a vulnerable web app and API service.  &lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/channel/UCSmjcWvgVBqF3x_7e5rfe3A '''The DevSlop Show'''] is a video streaming series where project members build things live, interview members of the OWASP and InfoSec community, and learn where they fit into DevOps.&lt;br /&gt;
&lt;br /&gt;
[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of [http://devslop.co DevSlop] are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/DevSlop/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
Nancy Gariché [https://twitter.com/nanzgtweets Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
&lt;br /&gt;
[[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
[[User:Mordecai Kraushar|Mordecai Kraushar]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* Nancy Gariché was promoted to leader, making 3 leaders of this project! &lt;br /&gt;
* [http://devslop.co/Home/Schedule Check out our schedule!] &lt;br /&gt;
* [July 2] Tanya Janca will be giving the &amp;quot;Hack Your Own Apps&amp;quot; workshop at the [https://www.spaconference.org/spa2018 SPA Conference in London], England. &lt;br /&gt;
* [June 4-6, 2018] The entire DevSlop team will be at the [https://owaspsummit.org/ Open Security Summit] in London, England. &lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher [https://twitter.com/thedeadrobots Twitter]&lt;br /&gt;
* [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter]&lt;br /&gt;
* [[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
* [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=250643</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=250643"/>
				<updated>2019-04-25T12:44:19Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: /* Main */  Update project description&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP [http://devslop.co DevSlop] Tool Project==&lt;br /&gt;
''DevSlop: learning how application security professionals fit into DevOps.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Project Website:  [http://devslop.co DevSlop]&lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services, however this changing landscape means security people need to step up their game.  DevSlop, &amp;quot;Sloppy DevOps&amp;quot;, is an exploration into this area, via several different modules consisting of pipelines, vulnerable apps, and [https://www.youtube.com/channel/UCSmjcWvgVBqF3x_7e5rfe3A The DevSlop Show], where project members learn and share. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''' is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of [http://devslop.co DevSlop] are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/DevSlop/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
Nancy Gariché [https://twitter.com/nanzgtweets Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
&lt;br /&gt;
[[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
[[User:Mordecai Kraushar|Mordecai Kraushar]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* Nancy Gariché was promoted to leader, making 3 leaders of this project! &lt;br /&gt;
* [http://devslop.co/Home/Schedule Check out our schedule!] &lt;br /&gt;
* [July 2] Tanya Janca will be giving the &amp;quot;Hack Your Own Apps&amp;quot; workshop at the [https://www.spaconference.org/spa2018 SPA Conference in London], England. &lt;br /&gt;
* [June 4-6, 2018] The entire DevSlop team will be at the [https://owaspsummit.org/ Open Security Summit] in London, England. &lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher [https://twitter.com/thedeadrobots Twitter]&lt;br /&gt;
* [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter]&lt;br /&gt;
* [[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
* [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=250642</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=250642"/>
				<updated>2019-04-25T12:40:12Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added Nancy as leader.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP [http://devslop.co DevSlop] Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Project Website:  [http://devslop.co DevSlop]&lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of [http://devslop.co DevSlop] are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/DevSlop/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
Nancy Gariché [https://twitter.com/nanzgtweets Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
&lt;br /&gt;
[[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
[[User:Mordecai Kraushar|Mordecai Kraushar]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* Nancy Gariché was promoted to leader, making 3 leaders of this project! &lt;br /&gt;
* [http://devslop.co/Home/Schedule Check out our schedule!] &lt;br /&gt;
* [July 2] Tanya Janca will be giving the &amp;quot;Hack Your Own Apps&amp;quot; workshop at the [https://www.spaconference.org/spa2018 SPA Conference in London], England. &lt;br /&gt;
* [June 4-6, 2018] The entire DevSlop team will be at the [https://owaspsummit.org/ Open Security Summit] in London, England. &lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher [https://twitter.com/thedeadrobots Twitter]&lt;br /&gt;
* [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter]&lt;br /&gt;
* [[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
* [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Top_10-2017_A9-Using_Components_with_Known_Vulnerabilities&amp;diff=245758</id>
		<title>Top 10-2017 A9-Using Components with Known Vulnerabilities</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Top_10-2017_A9-Using_Components_with_Known_Vulnerabilities&amp;diff=245758"/>
				<updated>2018-12-05T16:30:31Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Updated broken link to Mitre article: https://cdn2.hubspot.net/hub/203759/file-1100864196-pdf/docs/Contrast_-_Insecure_Libraries_2014.pdf&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Top_10_2013:TopTemplate&lt;br /&gt;
    |useprev=2017PrevLink&lt;br /&gt;
    |prev=A8-{{Top_10_2010:ByTheNumbers&lt;br /&gt;
        |8&lt;br /&gt;
        |year=2017&lt;br /&gt;
        |language=en&lt;br /&gt;
    }}&lt;br /&gt;
    |usenext=2017NextLink&lt;br /&gt;
    |next=A10-{{Top_10_2010:ByTheNumbers&lt;br /&gt;
        |10&lt;br /&gt;
        |year=2017&lt;br /&gt;
        |language=en&lt;br /&gt;
    }}&lt;br /&gt;
    |year=2017&lt;br /&gt;
    |language=en&lt;br /&gt;
}}&lt;br /&gt;
&amp;lt;!--- 2017 Using Components with Known Vulnerabilities ---&amp;gt;&lt;br /&gt;
{{Top_10_2010:SummaryTableHeaderBeginTemplate|year=2017|language=en}}&lt;br /&gt;
{{Top_10-2017:SummaryTableTemplate|exploitability=2 |prevalence=3 |detectability=2 |impact=2 |year=2017|language=en}}&lt;br /&gt;
{{Top_10_2010:SummaryTableHeaderEndTemplate|year=2017}}&lt;br /&gt;
    &amp;lt;td colspan=2 {{Template:Top_10_2010:SummaryTableRowStyleTemplate|year=2017}}&amp;gt;&lt;br /&gt;
&amp;lt;!--- Threat Agent: ---&amp;gt;&lt;br /&gt;
While it is easy to find already-written exploits for many known vulnerabilities, other vulnerabilities require concentrated effort to develop a custom exploit. &amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td colspan=2  {{Template:Top_10_2010:SummaryTableRowStyleTemplate|year=2017}}&amp;gt;&lt;br /&gt;
&amp;lt;!--- Security Weakness: ---&amp;gt;&lt;br /&gt;
 Prevalence of this issue is very widespread. Component-heavy development patterns can lead to development teams not even understanding which components they use in their application or API, much less keeping them up to date.&amp;lt;br/&amp;gt;Some scanners such as retire.js help in detection, but determining exploitability requires additional effort. &amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td colspan=2  {{Template:Top_10_2010:SummaryTableRowStyleTemplate|year=2017}}&amp;gt;&lt;br /&gt;
&amp;lt;!--- Impacts: ---&amp;gt;&lt;br /&gt;
 While some known vulnerabilities lead to only minor impacts, some of the largest breaches to date have relied on exploiting known vulnerabilities in components. Depending on the assets you are protecting, perhaps this risk should be at the top of the list. &amp;lt;/td&amp;gt;&lt;br /&gt;
{{Top_10_2010:SummaryTableEndTemplate|year=2017}}&lt;br /&gt;
&lt;br /&gt;
{{Top_10:SubsectionTableBeginTemplate|type=main}}&lt;br /&gt;
{{Top_10_2010:SubsectionAdvancedTemplate|type={{Top_10_2010:StyleTemplate}}|subsection=isTheApplicationVulnerable|position=firstLeft|year=2017|language=en}}&lt;br /&gt;
You are likely vulnerable:&lt;br /&gt;
* If you do not know the versions of all components you use (both client-side and server-side). This includes components you directly use as well as nested dependencies.&lt;br /&gt;
* If software is vulnerable, unsupported, or out of date. This includes the OS, web/application server, database management system (DBMS), applications, APIs and all components, runtime environments, and libraries.&lt;br /&gt;
* If you do not scan for vulnerabilities regularly and subscribe to security bulletins related to the components you use.&lt;br /&gt;
* If you do not fix or upgrade the underlying platform, frameworks, and dependencies in a risk-based, timely fashion. This commonly happens in environments when patching is a monthly or quarterly task under change control, which leaves organizations open to many days or months of unnecessary exposure to fixed vulnerabilities.&lt;br /&gt;
* If software developers do not test the compatibility of updated, upgraded, or patched libraries.&lt;br /&gt;
* If you do not secure the components' configurations (see &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;[[{{Top_10:LanguageFile|text=documentRootTop10New|language=en|year=2017 }}_A6-{{Top_10_2010:ByTheNumbers|6|year=2017|language=en}} | A6:2017-{{Top_10_2010:ByTheNumbers|6|year=2017|language=en}}]]&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
{{Top_10_2010:SubsectionAdvancedTemplate|type={{Top_10_2010:StyleTemplate}}|subsection=howToPrevent|position=right|year=2017|language=en}}&lt;br /&gt;
There should be a patch management process in place to:&lt;br /&gt;
* Remove unused dependencies, unnecessary features, components, files, and documentation.&lt;br /&gt;
* Continuously inventory the versions of both client-side and server-side components (e.g. frameworks, libraries) and their dependencies using tools like &amp;lt;u&amp;gt;[http://www.mojohaus.org/versions-maven-plugin/ versions]&amp;lt;/u&amp;gt;, &amp;lt;u&amp;gt;[[OWASP_Dependency_Check|DependencyCheck]]&amp;lt;/u&amp;gt;, &amp;lt;u&amp;gt;[https://github.com/retirejs/retire.js/ retire.js]&amp;lt;/u&amp;gt;, etc. Continuously monitor sources like &amp;lt;u&amp;gt;[https://cve.mitre.org/ CVE]&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;[https://nvd.nist.gov/ NVD]&amp;lt;/u&amp;gt; for vulnerabilities in the components. Use software composition analysis tools to automate the process. Subscribe to email alerts for security vulnerabilities related to components you use.&lt;br /&gt;
* Only obtain components from official sources over secure links. Prefer signed packages to reduce the chance of including a modified, malicious component.&lt;br /&gt;
* Monitor for libraries and components that are unmaintained or do not create security patches for older versions. If patching is not possible, consider deploying a &amp;lt;u&amp;gt;[[Virtual_Patching_Best_Practices#What_is_a_Virtual_Patch.3F | virtual patch]]&amp;lt;/u&amp;gt; to monitor, detect, or protect against the discovered issue.&lt;br /&gt;
Every organization must ensure that there is an ongoing plan for monitoring, triaging, and applying updates or configuration changes for the lifetime of the application or portfolio.&lt;br /&gt;
&lt;br /&gt;
{{Top_10_2010:SubsectionAdvancedTemplate|type={{Top_10_2010:StyleTemplate}}|subsection=exampleAttackScenarios|position=left|year=2017|language=en}}&lt;br /&gt;
&amp;lt;b&amp;gt;Scenario #1&amp;lt;/b&amp;gt;: Components typically run with the same privileges as the application itself, so flaws in any component can result in serious impact. Such flaws can be accidental (e.g. coding error) or intentional (e.g. backdoor in component). Some example exploitable component vulnerabilities discovered are:&lt;br /&gt;
* &amp;lt;u&amp;gt;[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5638 CVE-2017-5638]&amp;lt;/u&amp;gt;, a Struts 2 remote code execution vulnerability that enables execution of arbitrary code on the server, has been blamed for significant breaches.&lt;br /&gt;
* While &amp;lt;u&amp;gt;[https://en.wikipedia.org/wiki/Internet_of_things internet of things (IoT)]&amp;lt;/u&amp;gt; are frequently difficult or impossible to patch, the importance of patching them can be great (e.g. biomedical devices).&lt;br /&gt;
There are automated tools to help attackers find unpatched or misconfigured systems. For example, the &amp;lt;u&amp;gt;[https://www.shodan.io/report/89bnfUyJ Shodan IoT search engine]&amp;lt;/u&amp;gt; can help you find devices that still suffer from &amp;lt;u&amp;gt;[https://en.wikipedia.org/wiki/Heartbleed Heartbleed]&amp;lt;/u&amp;gt; vulnerability that was patched in April 2014.&lt;br /&gt;
&lt;br /&gt;
{{Top_10_2010:SubsectionAdvancedTemplate|type={{Top_10_2010:StyleTemplate}}|subsection=references|position=right|year=2017|language=en}}&lt;br /&gt;
{{Top_10_2010:SubSubsectionOWASPReferencesTemplate|year=2017|language=en}}&lt;br /&gt;
* &amp;lt;u&amp;gt;[[ASVS_V1_Architecture|OWASP Application Security Verification Standard: V1 Architecture, design and threat modelling]]&amp;lt;/u&amp;gt;&lt;br /&gt;
* &amp;lt;u&amp;gt;[[OWASP_Dependency_Check|OWASP Dependency Check (for Java and .NET libraries)]]&amp;lt;/u&amp;gt;&lt;br /&gt;
* &amp;lt;u&amp;gt;[[Map_Application_Architecture_(OTG-INFO-010)|OWASP Testing Guide - Map Application Architecture (OTG-INFO-010)]]&amp;lt;/u&amp;gt;&lt;br /&gt;
* &amp;lt;u&amp;gt;[[Virtual_Patching_Best_Practices|OWASP Virtual Patching Best Practices]]&amp;lt;/u&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Top_10_2010:SubSubsectionExternalReferencesTemplate|year=2017|language=en}}&lt;br /&gt;
* &amp;lt;u&amp;gt;[https://cdn2.hubspot.net/hub/203759/file-1100864196-pdf/docs/Contrast_-_Insecure_Libraries_2014.pdf The Unfortunate Reality of Insecure Libraries]&amp;lt;/u&amp;gt;&lt;br /&gt;
* &amp;lt;u&amp;gt;[https://www.cvedetails.com/version-search.php MITRE Common Vulnerabilities and Exposures (CVE) search]&amp;lt;/u&amp;gt;&lt;br /&gt;
* &amp;lt;u&amp;gt;[https://nvd.nist.gov/ National Vulnerability Database (NVD)]&amp;lt;/u&amp;gt;&lt;br /&gt;
* &amp;lt;u&amp;gt;[https://github.com/retirejs/retire.js/ Retire.js for detecting known vulnerable JavaScript libraries]&amp;lt;/u&amp;gt;&lt;br /&gt;
* &amp;lt;u&amp;gt;[https://nodesecurity.io/advisories Node Libraries Security Advisories]&amp;lt;/u&amp;gt;&lt;br /&gt;
* &amp;lt;u&amp;gt;[https://rubysec.com/ Ruby Libraries Security Advisory Database and Tools]&amp;lt;/u&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Top_10_2013:BottomAdvancedTemplate&lt;br /&gt;
    |type=box&lt;br /&gt;
    |useprev=2017PrevLink&lt;br /&gt;
    |prev=A8-{{Top_10_2010:ByTheNumbers&lt;br /&gt;
        |8&lt;br /&gt;
        |year=2017&lt;br /&gt;
        |language=en&lt;br /&gt;
    }}&lt;br /&gt;
    |usenext=2017NextLink&lt;br /&gt;
    |next=A10-{{Top_10_2010:ByTheNumbers&lt;br /&gt;
        |10&lt;br /&gt;
        |year=2017&lt;br /&gt;
        |language=en&lt;br /&gt;
    }}&lt;br /&gt;
    |year=2017&lt;br /&gt;
    |language=en&lt;br /&gt;
}}&lt;br /&gt;
&amp;lt;!-- [[Category:OWASP Top Ten Project]] --&amp;gt;&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=244413</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=244413"/>
				<updated>2018-10-22T13:38:12Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: /* Chapter Leadership */ Added Paul&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  &lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are:&amp;lt;br/&amp;gt;&lt;br /&gt;
[mailto:sherif.koussa@owasp.org Sherif Koussa] &amp;lt;br/&amp;gt;&lt;br /&gt;
[mailto:paul.ionescu@owasp.org Paul Ionescu] &amp;lt;br/&amp;gt;&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd] &amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Chapter Board Member: &amp;lt;br/&amp;gt;&lt;br /&gt;
[mailto:tanya.janca@owasp.org Tanya Janca]&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;br&amp;gt; &lt;br /&gt;
Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;br&amp;gt;&lt;br /&gt;
Talk to us on [https://owaspottawa.slack.com Slack]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email us: [mailto:sherif.koussa@owasp.org Sherif], [mailto:tanya.janca@owasp.org Tanya] or [mailto:garth.boyd@owasp.org Garth]&lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;meetup group=&amp;quot;OWASP-Ottawa&amp;quot; /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:paul.ionescu@owasp.org Paul Ionescu], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
Organization Committee: Paul Ionescu, Pierre Ernst, Nancy Gariche, Rick Mitchel, Adam Janzen, David Petrasovic, Annie Fry, Oliver, Mark Tse&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet&amp;diff=244079</id>
		<title>XSS (Cross Site Scripting) Prevention Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet&amp;diff=244079"/>
				<updated>2018-10-09T01:32:44Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Removed this dead link:A Systematic Analysis of XSS Sanitization in Web Application Frameworks  http://www.cs.berkeley.edu/~prateeks/papers/empirical-webfwks.pdf&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; __NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Cheatsheets-header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' &lt;br /&gt;
= Introduction  =&lt;br /&gt;
 __TOC__{{TOC hidden}}&lt;br /&gt;
&lt;br /&gt;
This article provides a simple positive model for preventing [[XSS]] using output escaping/encoding properly. While there are a huge number of XSS attack vectors, following a few simple rules can completely defend against this serious attack. This article does not explore the technical or business impact of XSS. Suffice it to say that it can lead to an attacker gaining the ability to do anything a victim can do through their browser.&lt;br /&gt;
&lt;br /&gt;
Both [[XSS#Stored_and_Reflected_XSS_Attacks | reflected and stored XSS]] can be addressed by performing the appropriate validation and escaping on the server-side. [[DOM Based XSS]] can be addressed with a special subset of rules described in the [[DOM based XSS Prevention Cheat Sheet]].&lt;br /&gt;
&lt;br /&gt;
For a cheatsheet on the attack vectors related to XSS, please refer to the [[XSS Filter Evasion Cheat Sheet]]. More background on browser security and the various browsers can be found in the [http://code.google.com/p/browsersec/ Browser Security Handbook].&lt;br /&gt;
&lt;br /&gt;
Before reading this cheatsheet, it is important to have a fundamental understanding of [[Injection Theory]].&lt;br /&gt;
&lt;br /&gt;
== A Positive XSS Prevention Model ==&lt;br /&gt;
&lt;br /&gt;
This article treats an HTML page like a template, with slots where a developer is allowed to put untrusted data. These slots cover the vast majority of the common places where a developer might want to put untrusted data. Putting untrusted data in other places in the HTML is not allowed. This is a &amp;quot;whitelist&amp;quot; model, that denies everything that is not specifically allowed.&lt;br /&gt;
&lt;br /&gt;
Given the way browsers parse HTML, each of the different types of slots has slightly different security rules. When you put untrusted data into these slots, you need to take certain steps to make sure that the data does not break out of that slot into a context that allows code execution. In a way, this approach treats an HTML document like a parameterized database query - the data is kept in specific places and is isolated from code contexts with escaping.&lt;br /&gt;
&lt;br /&gt;
This document sets out the most common types of slots and the rules for putting untrusted data into them safely. Based on the various specifications, known XSS vectors, and a great deal of manual testing with all the popular browsers, we have determined that the rules proposed here are safe.&lt;br /&gt;
&lt;br /&gt;
The slots are defined and a few examples of each are provided. Developers SHOULD NOT put data into any other slots without a very careful analysis to ensure that what they are doing is safe. Browser parsing is extremely tricky and many innocuous looking characters can be significant in the right context.&lt;br /&gt;
&lt;br /&gt;
== Why Can't I Just HTML Entity Encode Untrusted Data? ==&lt;br /&gt;
&lt;br /&gt;
HTML entity encoding is okay for untrusted data that you put in the body of the HTML document, such as inside a &amp;amp;lt;div&amp;gt; tag.  It even sort of works for untrusted data that goes into attributes, particularly if you're religious about using quotes around your attributes.  But HTML entity encoding doesn't work if you're putting untrusted data inside a &amp;amp;lt;script&amp;gt; tag anywhere, or an event handler attribute like onmouseover, or inside CSS, or in a URL.  So even if you use an HTML entity encoding method everywhere, you are still most likely vulnerable to XSS.  '''You MUST use the escape syntax for the part of the HTML document you're putting untrusted data into.'''  That's what the rules below are all about.&lt;br /&gt;
&lt;br /&gt;
== You Need a Security Encoding Library ==&lt;br /&gt;
&lt;br /&gt;
Writing these encoders is not tremendously difficult, but there are quite a few hidden pitfalls. For example, you might be tempted to use some of the escaping shortcuts like \&amp;quot; in JavaScript. However, these values are dangerous and may be misinterpreted by the nested parsers in the browser. You might also forget to escape the escape character, which attackers can use to neutralize your attempts to be safe. OWASP recommends using a security-focused encoding library to make sure these rules are properly implemented.&lt;br /&gt;
&lt;br /&gt;
Microsoft provides an encoding library named the [http://wpl.codeplex.com Microsoft Anti-Cross Site Scripting Library] for the .NET platform and ASP.NET Framework has built-in [http://msdn.microsoft.com/en-us/library/ms972969.aspx#securitybarriers_topic6 ValidateRequest] function that provides '''limited''' sanitization.&lt;br /&gt;
&lt;br /&gt;
The  [[OWASP Java Encoder Project]] provides a high-performance encoding library for Java.&lt;br /&gt;
&lt;br /&gt;
= XSS Prevention Rules = &lt;br /&gt;
&lt;br /&gt;
The following rules are intended to prevent all XSS in your application. While these rules do not allow absolute freedom in putting untrusted data into an HTML document, they should cover the vast majority of common use cases. You do not have to allow '''all''' the rules in your organization. Many organizations may find that '''allowing only Rule #1 and Rule #2 are sufficient for their needs'''. Please add a note to the discussion page if there is an additional context that is often required and can be secured with escaping.&lt;br /&gt;
&lt;br /&gt;
Do NOT simply escape the list of example characters provided in the various rules. It is NOT sufficient to escape only that list. Blacklist approaches are quite fragile.  The whitelist rules here have been carefully designed to provide protection even against future vulnerabilities introduced by browser changes.&lt;br /&gt;
&lt;br /&gt;
== RULE #0 - Never Insert Untrusted Data Except in Allowed Locations ==&lt;br /&gt;
&lt;br /&gt;
The first rule is to '''deny all''' - don't put untrusted data into your HTML document unless it is within one of the slots defined in Rule #1 through Rule #5. The reason for Rule #0 is that there are so many strange contexts within HTML that the list of escaping rules gets very complicated. We can't think of any good reason to put untrusted data in these contexts. This includes &amp;quot;nested contexts&amp;quot; like a URL inside a javascript -- the encoding rules for those locations are tricky and dangerous.  If you insist on putting untrusted data into nested contexts, please do a lot of cross-browser testing and let us know what you find out.&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;script&amp;gt;'''...NEVER PUT UNTRUSTED DATA HERE...'''&amp;lt;/script&amp;gt;   directly in a script&lt;br /&gt;
  &lt;br /&gt;
  &amp;amp;lt;!--'''...NEVER PUT UNTRUSTED DATA HERE...'''--&amp;gt;             inside an HTML comment&lt;br /&gt;
  &lt;br /&gt;
  &amp;amp;lt;div '''...NEVER PUT UNTRUSTED DATA HERE...'''=test /&amp;gt;       in an attribute name&lt;br /&gt;
  &lt;br /&gt;
  &amp;amp;lt;'''NEVER PUT UNTRUSTED DATA HERE...''' href=&amp;quot;/test&amp;quot; /&amp;gt;   in a tag name&lt;br /&gt;
  &lt;br /&gt;
  &amp;amp;lt;style&amp;gt;'''...NEVER PUT UNTRUSTED DATA HERE...'''&amp;lt;/style&amp;gt;   directly in CSS&lt;br /&gt;
&lt;br /&gt;
Most importantly, never accept actual JavaScript code from an untrusted source and then run it. For example, a parameter named &amp;quot;callback&amp;quot; that contains a JavaScript code snippet.  No amount of escaping can fix that.&lt;br /&gt;
&lt;br /&gt;
== RULE #1 - HTML Escape Before Inserting Untrusted Data into HTML Element Content ==&lt;br /&gt;
&lt;br /&gt;
Rule #1 is for when you want to put untrusted data directly into the HTML body somewhere. This includes inside normal tags like div, p, b, td, etc. Most web frameworks have a method for HTML escaping for the characters detailed below. However, this is '''absolutely not sufficient for other HTML contexts.'''  You need to implement the other rules detailed here as well.&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;body&amp;gt;'''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...'''&amp;lt;/body&amp;gt;&lt;br /&gt;
  &lt;br /&gt;
&amp;amp;lt;div&amp;gt;'''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...'''&lt;br /&gt;
  &lt;br /&gt;
  any other normal HTML elements&lt;br /&gt;
&lt;br /&gt;
Escape the following characters with HTML entity encoding to prevent switching into any execution context, such as script, style, or event handlers. Using hex entities is recommended in the spec. In addition to the 5 characters significant in XML (&amp;amp;, &amp;lt;, &amp;gt;, &amp;quot;, '), the forward slash is included as it helps to end an HTML entity.&lt;br /&gt;
&lt;br /&gt;
  &amp;amp; --&amp;gt; &amp;amp;amp;amp;&lt;br /&gt;
  &amp;lt; --&amp;gt; &amp;amp;amp;lt;&lt;br /&gt;
  &amp;gt; --&amp;gt; &amp;amp;amp;gt;&lt;br /&gt;
  &amp;quot; --&amp;gt; &amp;amp;amp;quot;&lt;br /&gt;
  ' --&amp;gt; &amp;amp;amp;#x27;     &amp;amp;amp;apos; not recommended because its not in the HTML spec (See: [http://www.w3.org/TR/html4/sgml/entities.html section 24.4.1]) &amp;amp;amp;apos; is in the XML and XHTML specs.&lt;br /&gt;
  / --&amp;gt; &amp;amp;amp;#x2F;     forward slash is included as it helps end an HTML entity&lt;br /&gt;
&lt;br /&gt;
== RULE #2 - Attribute Escape Before Inserting Untrusted Data into HTML Common Attributes ==&lt;br /&gt;
&lt;br /&gt;
Rule #2 is for putting untrusted data into typical attribute values like width, name, value, etc. This should not be used for complex attributes like href, src, style, or any of the event handlers like onmouseover.  It is extremely important that event handler attributes should follow Rule #3 for HTML JavaScript Data Values.&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;div attr='''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...'''&amp;gt;content&lt;br /&gt;
&lt;br /&gt;
inside UNquoted attribute&lt;br /&gt;
  &lt;br /&gt;
&amp;amp;lt;div attr='&amp;lt;nowiki/&amp;gt;'''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...''''&amp;gt;content&lt;br /&gt;
&lt;br /&gt;
inside single quoted attribute&lt;br /&gt;
  &lt;br /&gt;
&amp;amp;lt;div attr=&amp;quot;'''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...'''&amp;quot;&amp;gt;content&lt;br /&gt;
&lt;br /&gt;
inside double quoted attribute&lt;br /&gt;
&lt;br /&gt;
Except for alphanumeric characters, escape all characters with ASCII values less than 256 with the &amp;amp;amp;#xHH; format (or a named entity if available) to prevent switching out of the attribute. The reason this rule is so broad is that developers frequently leave attributes unquoted.  Properly quoted attributes can only be escaped with the corresponding quote. Unquoted attributes can be broken out of with many characters, including [space] % * + , - / ; &amp;lt; = &amp;gt; ^ and |.&lt;br /&gt;
&lt;br /&gt;
== RULE #3 - JavaScript Escape Before Inserting Untrusted Data into JavaScript Data Values ==&lt;br /&gt;
&lt;br /&gt;
Rule #3 concerns dynamically generated JavaScript code - both script blocks and event-handler attributes. The only safe place to put untrusted data into this code is inside a quoted &amp;quot;data value.&amp;quot;  Including untrusted data inside any other JavaScript context is quite dangerous, as it is extremely easy to switch into an execution context with characters including (but not limited to) semi-colon, equals, space, plus, and many more, so use with caution.&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;script&amp;gt;alert('&amp;lt;nowiki/&amp;gt;'''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...'''')&amp;amp;lt;/script&amp;gt;     inside a quoted string&lt;br /&gt;
  &lt;br /&gt;
  &amp;amp;lt;script&amp;gt;x='&amp;lt;nowiki/&amp;gt;'''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...''''&amp;amp;lt;/script&amp;gt;          one side of a quoted expression&lt;br /&gt;
  &lt;br /&gt;
  &amp;amp;lt;div onmouseover=&amp;quot;x='&amp;lt;nowiki/&amp;gt;'''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...''''&amp;quot;&amp;amp;lt;/div&amp;gt;  inside quoted event handler&lt;br /&gt;
&lt;br /&gt;
Please note there are some JavaScript functions that can never safely use untrusted data as input - &amp;lt;b&amp;gt;EVEN IF JAVASCRIPT ESCAPED&amp;lt;/b&amp;gt;! &lt;br /&gt;
&lt;br /&gt;
For example:&lt;br /&gt;
  &amp;amp;lt;script&amp;gt;&lt;br /&gt;
  window.setInterval('&amp;lt;nowiki/&amp;gt;'''...EVEN IF YOU ESCAPE UNTRUSTED DATA YOU ARE XSSED HERE...'''');&lt;br /&gt;
  &amp;amp;lt;/script&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Except for alphanumeric characters, escape all characters less than 256 with the \xHH format to prevent switching out of the data value into the script context or into another attribute. DO NOT use any escaping shortcuts like \&amp;quot; because the quote character may be matched by the HTML attribute parser which runs first. These escaping shortcuts are also susceptible to &amp;quot;escape-the-escape&amp;quot; attacks where the attacker sends \&amp;quot; and the vulnerable code turns that into \\&amp;quot; which enables the quote.&lt;br /&gt;
&lt;br /&gt;
If an event handler is properly quoted, breaking out requires the corresponding quote. However, we have intentionally made this rule quite broad because event handler attributes are often left unquoted.  Unquoted attributes can be broken out of with many characters including [space] % * + , - / ; &amp;lt; = &amp;gt; ^ and |. Also, a &amp;lt;/script&amp;gt; closing tag will close a script block even though it is inside a quoted string because the HTML parser runs before the JavaScript parser. Please note this is an aggressive escaping policy that over-encodes. If there is a guarantee that proper quoting is accomplished then a much smaller character set is needed.  Please look at the OWASP Java Encoder JavaScript escaping examples for examples of proper JavaScript use that requires minimal escaping. https://www.owasp.org/index.php/OWASP_Java_Encoder_Project#tab=Use_the_Java_Encoder_Project&lt;br /&gt;
&lt;br /&gt;
=== RULE #3.1 - HTML escape JSON values in an HTML context and read the data with JSON.parse ===&lt;br /&gt;
&lt;br /&gt;
In a Web 2.0 world, the need for having data dynamically generated by an application in a javascript context is common.  One strategy is to make an AJAX call to get the values, but this isn't always performant.  Often, an initial block of JSON is loaded into the page to act as a single place to store multiple values.  This data is tricky, though not impossible, to escape correctly without breaking the format and content of the values.&lt;br /&gt;
&lt;br /&gt;
'''Ensure returned ''Content-Type'' header is application/json and not text/html. '''&lt;br /&gt;
This shall instruct the browser not misunderstand the context and execute injected script&lt;br /&gt;
&lt;br /&gt;
'''Bad HTTP response:'''&lt;br /&gt;
&lt;br /&gt;
    HTTP/1.1 200&lt;br /&gt;
    Date: Wed, 06 Feb 2013 10:28:54 GMT&lt;br /&gt;
    Server: Microsoft-IIS/7.5....&lt;br /&gt;
    '''Content-Type: text/html; charset=utf-8''' &amp;lt;-- bad&lt;br /&gt;
    ....&lt;br /&gt;
    Content-Length: 373&lt;br /&gt;
    Keep-Alive: timeout=5, max=100&lt;br /&gt;
    Connection: Keep-Alive&lt;br /&gt;
    {&amp;quot;Message&amp;quot;:&amp;quot;No HTTP resource was found that matches the request URI 'dev.net.ie/api/pay/.html?HouseNumber=9&amp;amp;AddressLine&lt;br /&gt;
    =The+Gardens'''&amp;amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;'''&amp;amp;AddressLine2=foxlodge+woods&amp;amp;TownName=Meath'.&amp;quot;,&amp;quot;MessageDetail&amp;quot;:&amp;quot;No type was found&lt;br /&gt;
    that matches the controller named 'pay'.&amp;quot;}   &amp;lt;-- this script will pop!!&lt;br /&gt;
    &lt;br /&gt;
&lt;br /&gt;
'''Good HTTP response'''&lt;br /&gt;
&lt;br /&gt;
    HTTP/1.1 200&lt;br /&gt;
    Date: Wed, 06 Feb 2013 10:28:54 GMT&lt;br /&gt;
    Server: Microsoft-IIS/7.5....&lt;br /&gt;
    '''Content-Type: application/json; charset=utf-8''' &amp;lt;--good&lt;br /&gt;
    .....&lt;br /&gt;
    .....&lt;br /&gt;
&lt;br /&gt;
A common '''anti-pattern''' one would see:&lt;br /&gt;
&lt;br /&gt;
    &amp;amp;lt;script&amp;gt;&lt;br /&gt;
      var initData = &amp;lt;%= data.to_json %&amp;gt;; // '''Do NOT do this without encoding the data with one of the techniques listed below.'''&lt;br /&gt;
    &amp;amp;lt;/script&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== JSON serialization ====&lt;br /&gt;
&lt;br /&gt;
A safe JSON serializer will allow developers to serialize JSON as string of literal JavaScript which can be embedded in an HTML in the contents of the &amp;lt;script&amp;gt; tag. HTML characters and JavaScript line terminators need be escaped. Consider the Yahoo JavaScript Serializer for this task. https://github.com/yahoo/serialize-javascript&lt;br /&gt;
&lt;br /&gt;
==== HTML entity encoding ====&lt;br /&gt;
&lt;br /&gt;
This technique has the advantage that html entity escaping is widely supported and helps separate data from server side code without crossing any context boundaries. Consider placing the JSON block on the page as a normal element and then parsing the innerHTML to get the contents.  The javascript that reads the span can live in an external file, thus making the implementation of CSP enforcement easier.&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;div id=&amp;quot;init_data&amp;quot; style=&amp;quot;display: none&amp;quot;&amp;gt;&lt;br /&gt;
     &amp;amp;lt;%= html_escape(data.to_json) %&amp;gt;&lt;br /&gt;
  &amp;amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  // external js file&lt;br /&gt;
  var dataElement = document.getElementById('init_data');&lt;br /&gt;
  // decode and parse the content of the div&lt;br /&gt;
  var initData = JSON.parse(dataElement.textContent);&lt;br /&gt;
&lt;br /&gt;
An alternative to escaping and unescaping JSON directly in JavaScript, is to normalize JSON server-side by converting '&amp;lt;' to '\u003c' before delivering it to the browser.&lt;br /&gt;
&lt;br /&gt;
== RULE #4 - CSS Escape And Strictly Validate Before Inserting Untrusted Data into HTML Style Property Values ==&lt;br /&gt;
&lt;br /&gt;
Rule #4 is for when you want to put untrusted data into a stylesheet or a style tag. CSS is surprisingly powerful, and can be used for numerous attacks. Therefore, it's important that you only use untrusted data in a property '''value''' and not into other places in style data. You should stay away from putting untrusted data into complex properties like url, behavior, and custom (-moz-binding). You should also not put untrusted data into IE’s expression property value which allows JavaScript.&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;style&amp;gt;selector { property : '''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...'''; } &amp;amp;lt;/style&amp;gt;     property value&amp;lt;br /&amp;gt;&lt;br /&gt;
  &amp;amp;lt;style&amp;gt;selector { property : &amp;amp;quot;'''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...'''&amp;amp;quot;; } &amp;amp;lt;/style&amp;gt;   property value&amp;lt;br /&amp;gt;&lt;br /&gt;
  &amp;amp;lt;span style=&amp;amp;quot;property : '''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...'''&amp;amp;quot;&amp;gt;text&amp;amp;lt;/span&amp;gt;       property value&lt;br /&gt;
&lt;br /&gt;
Please note there are some CSS contexts that can never safely use untrusted data as input - &amp;lt;b&amp;gt;EVEN IF PROPERLY CSS ESCAPED&amp;lt;/b&amp;gt;! You will have to ensure that URLs only start with &amp;quot;http&amp;quot; not &amp;quot;javascript&amp;quot; and that properties never start with &amp;quot;expression&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
For example:&lt;br /&gt;
  { background-url : &amp;quot;javascript:alert(1)&amp;quot;; }  // and all other URLs&lt;br /&gt;
  { text-size: &amp;quot;expression(alert('XSS'))&amp;quot;; }   // only in IE&lt;br /&gt;
&lt;br /&gt;
Except for alphanumeric characters, escape all characters with ASCII values less than 256 with the \HH escaping format. DO NOT use any escaping shortcuts like \&amp;quot; because the quote character may be matched by the HTML attribute parser which runs first. These escaping shortcuts are also susceptible to &amp;quot;escape-the-escape&amp;quot; attacks where the attacker sends \&amp;quot; and the vulnerable code turns that into \\&amp;quot; which enables the quote.&lt;br /&gt;
&lt;br /&gt;
If attribute is quoted, breaking out requires the corresponding quote.  All attributes should be quoted but your encoding should be strong enough to prevent XSS when untrusted data is placed in unquoted contexts. Unquoted attributes can be broken out of with many characters including [space] % * + , - / ; &amp;lt; = &amp;gt; ^ and |.  Also, the &amp;lt;/style&amp;gt; tag will close the style block even though it is inside a quoted string because the HTML parser runs before the JavaScript parser. Please note that we recommend aggressive CSS encoding and validation to prevent XSS attacks for both quoted and unquoted attributes.&lt;br /&gt;
&lt;br /&gt;
== RULE #5 - URL Escape Before Inserting Untrusted Data into HTML URL Parameter Values ==&lt;br /&gt;
&lt;br /&gt;
Rule #5 is for when you want to put untrusted data into HTTP GET parameter value. &lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;a href=&amp;quot;http&amp;amp;#x3a;&amp;amp;#x2f;&amp;amp;#x2f;www.somesite.com&amp;amp;#x3f;test&amp;amp;#x3d;'''...ESCAPE UNTRUSTED DATA BEFORE PUTTING HERE...&amp;quot;'''&amp;gt;link&amp;amp;lt;/a &amp;gt;       &lt;br /&gt;
&lt;br /&gt;
Except for alphanumeric characters, escape all characters with ASCII values less than 256 with the %HH escaping format.  Including untrusted data in data: URLs should not be allowed as there is no good way to disable attacks with escaping to prevent switching out of the URL. All attributes should be quoted. Unquoted attributes can be broken out of with many characters including [space] % * + , - / ; &amp;lt; = &amp;gt; ^ and |. Note that entity encoding is useless in this context.&lt;br /&gt;
&lt;br /&gt;
WARNING: Do not encode complete or relative URL's with URL encoding! If untrusted input is meant to be placed into href, src or other URL-based attributes, it should be validated to make sure it does not point to an unexpected protocol, especially Javascript links. URL's should then be encoded based on the context of display like any other piece of data. For example, user driven URL's in HREF links should be attribute encoded. For example:&lt;br /&gt;
&lt;br /&gt;
  String userURL = request.getParameter( &amp;quot;userURL&amp;quot; )&lt;br /&gt;
  boolean isValidURL = Validator.IsValidURL(userURL, 255); &lt;br /&gt;
  if (isValidURL) {  &lt;br /&gt;
      &amp;lt;a href=&amp;quot;&amp;lt;%=encoder.encodeForHTMLAttribute(userURL)%&amp;gt;&amp;quot;&amp;gt;link&amp;lt;/a&amp;gt;&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
== RULE #6 - Sanitize HTML Markup with a Library Designed for the Job ==&lt;br /&gt;
&lt;br /&gt;
If your application handles markup -- untrusted input that is supposed to contain HTML -- it can be very difficult to validate. Encoding is also difficult, since it would break all the tags that are supposed to be in the input. Therefore, you need a library that can parse and clean HTML formatted text.  There are several available at OWASP that are simple to use:&lt;br /&gt;
&lt;br /&gt;
'''HtmlSanitizer''' - https://github.com/mganss/HtmlSanitizer&lt;br /&gt;
&lt;br /&gt;
An open-source .Net library. The HTML is cleaned with a white list approach. All allowed tags and attributes can be configured. The library is unit tested with the OWASP [[XSS Filter Evasion Cheat Sheet]]&lt;br /&gt;
&lt;br /&gt;
   var sanitizer = new HtmlSanitizer();&lt;br /&gt;
   sanitizer.AllowedAttributes.Add(&amp;quot;class&amp;quot;);&lt;br /&gt;
   var sanitized = sanitizer.Sanitize(html);&lt;br /&gt;
&lt;br /&gt;
'''OWASP Java HTML Sanitizer''' - [[OWASP Java HTML Sanitizer Project]]&lt;br /&gt;
&lt;br /&gt;
   import org.owasp.html.Sanitizers;&lt;br /&gt;
   import org.owasp.html.PolicyFactory;&lt;br /&gt;
   PolicyFactory sanitizer = Sanitizers.FORMATTING.and(Sanitizers.BLOCKS);&lt;br /&gt;
   String cleanResults = sanitizer.sanitize(&amp;quot;&amp;amp;lt;p&amp;amp;gt;Hello, &amp;amp;lt;b&amp;amp;gt;World!&amp;amp;lt;/b&amp;amp;gt;&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
For more information on OWASP Java HTML Sanitizer policy construction, see https://github.com/OWASP/java-html-sanitizer&lt;br /&gt;
&lt;br /&gt;
'''Ruby on Rails SanitizeHelper''' - http://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html&lt;br /&gt;
&lt;br /&gt;
The SanitizeHelper module provides a set of methods for scrubbing text of undesired HTML elements.&lt;br /&gt;
   &lt;br /&gt;
   &amp;amp;lt;%= sanitize @comment.body, tags: %w(strong em a), attributes: %w(href) %&amp;amp;gt;   &lt;br /&gt;
&lt;br /&gt;
'''Other libraries that provide HTML Sanitization include:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PHP HTML Purifier - http://htmlpurifier.org/&amp;lt;br /&amp;gt;&lt;br /&gt;
JavaScript/Node.js Bleach - https://github.com/ecto/bleach&amp;lt;br /&amp;gt;&lt;br /&gt;
Python Bleach - https://pypi.python.org/pypi/bleach&lt;br /&gt;
&lt;br /&gt;
== RULE #7 - Prevent DOM-based XSS  ==&lt;br /&gt;
&lt;br /&gt;
For details on what DOM-based XSS is, and defenses against this type of XSS flaw, please see the OWASP article on [[DOM based XSS Prevention Cheat Sheet]].&lt;br /&gt;
&lt;br /&gt;
== Bonus Rule #1: Use HTTPOnly cookie flag ==&lt;br /&gt;
&lt;br /&gt;
Preventing all XSS flaws in an application is hard, as you can see. To help mitigate the impact of an XSS flaw on your site, OWASP also recommends you set the HTTPOnly flag on your session cookie and any custom cookies you have that are not accessed by any Javascript you wrote. This cookie flag is typically on by default in .NET apps, but in other languages you have to set it manually.  For more details on the HTTPOnly cookie flag, including what it does, and how to use it, see the OWASP article on [[HTTPOnly]].&lt;br /&gt;
&lt;br /&gt;
== Bonus Rule #2: Implement Content Security Policy ==&lt;br /&gt;
&lt;br /&gt;
There is another good complex solution to mitigate the impact of an XSS flaw called Content Security Policy. It's a browser side mechanism which &lt;br /&gt;
allows you to create source whitelists for client side resources of your web application, e.g. JavaScript, CSS, images, etc. CSP via special HTTP header instructs the browser to only execute or render resources from those sources. For example this CSP &lt;br /&gt;
&lt;br /&gt;
 Content-Security-Policy: default-src: 'self'; script-src: 'self' static.domain.tld&lt;br /&gt;
&lt;br /&gt;
will instruct web browser to load all resources only from the page's origin and JavaScript source code files additionaly from static.domain.tld. For more details on Content Security Policy, including what it does, and how to use it, see the OWASP article on  [[Content_Security_Policy]]&lt;br /&gt;
&lt;br /&gt;
== Bonus Rule #3: Use an Auto-Escaping Template System ==&lt;br /&gt;
&lt;br /&gt;
Many web application frameworks provide automatic contextual escaping functionality such as [https://docs.angularjs.org/api/ng/service/$sce AngularJS strict contextual escaping] and [https://golang.org/pkg/html/template/ Go Templates]. Use these technologies when you can.&lt;br /&gt;
&lt;br /&gt;
== Bonus Rule #4: Use the X-XSS-Protection Response Header ==&lt;br /&gt;
&lt;br /&gt;
This HTTP response header enables the Cross-site scripting (XSS) filter built into some modern web browsers. This header is usually enabled by default anyway, so the role of this header is to re-enable the filter for this particular website if it was disabled by the user.&lt;br /&gt;
&lt;br /&gt;
= XSS Prevention Rules Summary =&lt;br /&gt;
&lt;br /&gt;
The following snippets of HTML demonstrate how to safely render untrusted data in a variety of different contexts. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable nowraplinks&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Data Type&lt;br /&gt;
! Context&lt;br /&gt;
! Code Sample&lt;br /&gt;
! Defense&lt;br /&gt;
|-&lt;br /&gt;
| String&lt;br /&gt;
| HTML Body&lt;br /&gt;
| &amp;amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED DATA&amp;lt;/span&amp;gt;&amp;amp;lt;/span&amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;[https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet#RULE_.231_-_HTML_Escape_Before_Inserting_Untrusted_Data_into_HTML_Element_Content HTML Entity Encoding]&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| String&lt;br /&gt;
| Safe HTML Attributes&lt;br /&gt;
| &amp;amp;lt;input type=&amp;quot;text&amp;quot; name=&amp;quot;fname&amp;quot; value=&amp;quot;&amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED DATA&amp;lt;/span&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;[https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet#RULE_.232_-_Attribute_Escape_Before_Inserting_Untrusted_Data_into_HTML_Common_Attributes Aggressive HTML Entity Encoding]&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Only place untrusted data into a whitelist of safe attributes (listed below).&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Strictly validate unsafe attributes such as background, id and name.&amp;lt;/ul&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| String&lt;br /&gt;
| GET Parameter&lt;br /&gt;
| &amp;amp;lt;a href=&amp;quot;/site/search?value=&amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED DATA&amp;lt;/span&amp;gt;&amp;quot;&amp;gt;clickme&amp;amp;lt;/a&amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;[https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet#RULE_.235_-_URL_Escape_Before_Inserting_Untrusted_Data_into_HTML_URL_Parameter_Values URL Encoding]&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| String&lt;br /&gt;
| Untrusted URL in a SRC or HREF attribute&lt;br /&gt;
| &amp;amp;lt;a href=&amp;quot;&amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED URL&amp;lt;/span&amp;gt;&amp;quot;&amp;gt;clickme&amp;amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;amp;lt;iframe src=&amp;quot;&amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED URL&amp;lt;/span&amp;gt;&amp;quot; /&amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Canonicalize input&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;URL Validation&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Safe URL verification&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Whitelist http and https URL's only ([[Avoid the JavaScript Protocol to Open a new Window]])&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Attribute encoder&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| String&lt;br /&gt;
| CSS Value&lt;br /&gt;
| &amp;amp;lt;div style=&amp;quot;width: &amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED DATA&amp;lt;/span&amp;gt;;&amp;quot;&amp;gt;Selection&amp;amp;lt;/div&amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;[https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet#RULE_.234_-_CSS_Escape_And_Strictly_Validate_Before_Inserting_Untrusted_Data_into_HTML_Style_Property_Values Strict structural validation]&amp;lt;li&amp;gt;CSS Hex encoding&amp;lt;li&amp;gt;Good design of CSS Features&amp;lt;/ul&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| String&lt;br /&gt;
| JavaScript Variable&lt;br /&gt;
| &amp;amp;lt;script&amp;gt;var currentValue='&amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED DATA&amp;lt;/span&amp;gt;';&amp;amp;lt;/script&amp;gt;&amp;lt;br /&amp;gt;&amp;amp;lt;script&amp;gt;someFunction('&amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED DATA&amp;lt;/span&amp;gt;');&amp;amp;lt;/script&amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Ensure JavaScript variables are quoted&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;JavaScript Hex Encoding&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;JavaScript Unicode Encoding&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoid backslash encoding (\&amp;quot; or \' or \\)&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| HTML&lt;br /&gt;
| HTML Body&lt;br /&gt;
| &amp;amp;lt;div&amp;gt;&amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED HTML&amp;lt;/span&amp;gt;&amp;amp;lt;/div&amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;[https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet#RULE_.236_-_Use_an_HTML_Policy_engine_to_validate_or_clean_user-driven_HTML_in_an_outbound_way HTML Validation (JSoup, AntiSamy, HTML Sanitizer)]&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt; &lt;br /&gt;
|-&lt;br /&gt;
| String&lt;br /&gt;
| DOM XSS&lt;br /&gt;
| &amp;amp;lt;script&amp;gt;document.write(&amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;&amp;quot;UNTRUSTED INPUT: &amp;quot; + document.location.hash&amp;lt;/span&amp;gt;);&amp;amp;lt;script/&amp;amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;[[DOM based XSS Prevention Cheat Sheet]]&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
'''''Safe HTML Attributes include:''''' align, alink, alt, bgcolor, border, cellpadding, cellspacing, class, color, cols, colspan, coords, dir, face, height, hspace, ismap, lang, marginheight, marginwidth, multiple, nohref, noresize, noshade, nowrap, ref, rel, rev, rows, rowspan, scrolling, shape, span, summary, tabindex, title, usemap, valign, value, vlink, vspace, width&lt;br /&gt;
&lt;br /&gt;
= Output Encoding Rules Summary =&lt;br /&gt;
&lt;br /&gt;
The purpose of output encoding (as it relates to Cross Site Scripting) is to convert untrusted input into a safe form where the input is displayed as '''data''' to the user without executing as '''code''' in the browser. The following charts details a list of critical output encoding methods needed to stop Cross Site Scripting.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Encoding Type&lt;br /&gt;
! Encoding Mechanism&lt;br /&gt;
|-&lt;br /&gt;
| HTML Entity Encoding&lt;br /&gt;
|   Convert &amp;amp; to &amp;amp;amp;amp;&amp;lt;br /&amp;gt;Convert &amp;lt; to &amp;amp;amp;lt;&amp;lt;br /&amp;gt;Convert &amp;gt; to &amp;amp;amp;gt;&amp;lt;br /&amp;gt;Convert &amp;quot; to &amp;amp;amp;quot;&amp;lt;br /&amp;gt;Convert ' to &amp;amp;amp;#x27;&amp;lt;br /&amp;gt;Convert / to &amp;amp;amp;#x2F;&lt;br /&gt;
|-&lt;br /&gt;
| HTML Attribute Encoding&lt;br /&gt;
| Except for alphanumeric characters, escape all characters with the HTML Entity &amp;amp;amp;#xHH; format, including spaces. (HH = Hex Value)&lt;br /&gt;
|-&lt;br /&gt;
| URL Encoding&lt;br /&gt;
| Standard percent encoding, see: http://www.w3schools.com/tags/ref_urlencode.asp. URL encoding should only be used to encode parameter values, not the entire URL or path fragments of a URL.&lt;br /&gt;
|-&lt;br /&gt;
| JavaScript Encoding&lt;br /&gt;
| Except for alphanumeric characters, escape all characters with the \uXXXX unicode escaping format (X = Integer).&lt;br /&gt;
|-&lt;br /&gt;
| CSS Hex Encoding&lt;br /&gt;
| CSS escaping supports \XX and \XXXXXX. Using a two character escape can cause problems if the next character continues the escape sequence. There are two solutions (a) Add a space after the CSS escape (will be ignored by the CSS parser) (b) use the full amount of CSS escaping possible by zero padding the value.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Related Articles =&lt;br /&gt;
&lt;br /&gt;
'''XSS Attack Cheat Sheet'''&lt;br /&gt;
&lt;br /&gt;
The following article describes how to exploit different kinds of XSS Vulnerabilities that this article was created to help you avoid:&lt;br /&gt;
&lt;br /&gt;
* OWASP: [[XSS Filter Evasion Cheat Sheet]] - Based on - RSnake's: &amp;quot;XSS Cheat Sheet&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''Description of XSS Vulnerabilities'''&lt;br /&gt;
&lt;br /&gt;
* OWASP article on [[XSS]] Vulnerabilities&lt;br /&gt;
&lt;br /&gt;
'''Discussion on the Types of XSS Vulnerabilities'''&lt;br /&gt;
&lt;br /&gt;
* [[Types of Cross-Site Scripting]]&lt;br /&gt;
&lt;br /&gt;
'''How to Review Code for Cross-site scripting Vulnerabilities'''&lt;br /&gt;
&lt;br /&gt;
* [[:Category:OWASP Code Review Project|OWASP Code Review Guide]] article on [[Reviewing Code for Cross-site scripting]] Vulnerabilities&lt;br /&gt;
&lt;br /&gt;
'''How to Test for Cross-site scripting  Vulnerabilities'''&lt;br /&gt;
&lt;br /&gt;
* [[:Category:OWASP Testing Project|OWASP Testing Guide]] article on [[Testing for Cross site scripting]] Vulnerabilities&lt;br /&gt;
&lt;br /&gt;
* [[XSS Experimental Minimal Encoding Rules]]&lt;br /&gt;
&lt;br /&gt;
= Other Cheatsheets =&lt;br /&gt;
{{Cheatsheet_Navigation_Body}}&lt;br /&gt;
&lt;br /&gt;
= Authors and Primary Editors =&lt;br /&gt;
&lt;br /&gt;
Jeff Williams - jeff.williams[at]contrastsecurity.com&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico - jim[at]owasp.org&amp;lt;br /&amp;gt;&lt;br /&gt;
Neil Mattatall - neil[at]owasp.org&lt;br /&gt;
&lt;br /&gt;
[[Category:Cheatsheets]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=242785</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=242785"/>
				<updated>2018-08-23T16:34:36Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added Paul Ionescu as 4th chapter leader.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:paul.ionescu@owasp.org Paul Ionescu], &lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd] and [mailto:tanya.janca@owasp.org Tanya Janca].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;br&amp;gt; &lt;br /&gt;
Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;br&amp;gt;&lt;br /&gt;
Talk to us on [https://owaspottawa.slack.com Slack]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email us: [mailto:sherif.koussa@owasp.org Sherif], [mailto:tanya.janca@owasp.org Tanya] or [mailto:garth.boyd@owasp.org Garth]&lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;meetup group=&amp;quot;OWASP-Ottawa&amp;quot; /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
Organization Committee: Paul Ionescu, Pierre Ernst, Nancy Gariche, Rick Mitchel, Adam Janzen, David Petrasovic, Annie Fry, Oliver, Mark Tse&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=241456</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=241456"/>
				<updated>2018-06-22T18:43:23Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Removed broken link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP [http://devslop.co DevSlop] Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Project Website:  [http://devslop.co DevSlop]&lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of [http://devslop.co DevSlop] are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/DevSlop/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
&lt;br /&gt;
[[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
[[User:Mordecai Kraushar|Mordecai Kraushar]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [http://devslop.co/Home/Schedule Check out our schedule!] &lt;br /&gt;
* [July 2] Tanya Janca will be giving the &amp;quot;Hack Your Own Apps&amp;quot; workshop at the [https://www.spaconference.org/spa2018 SPA Conference in London], England. &lt;br /&gt;
* [June 4-6, 2018] The entire DevSlop team will be at the [https://owaspsummit.org/ Open Security Summit] in London, England. &lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher [https://twitter.com/thedeadrobots Twitter]&lt;br /&gt;
* [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter]&lt;br /&gt;
* [[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
* [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=241133</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=241133"/>
				<updated>2018-06-04T20:02:10Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP [http://devslop.co DevSlop] Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Project Website:  [http://devslop.co DevSlop]&lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of [http://devslop.co DevSlop] are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/DevSlop/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
&lt;br /&gt;
[[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
[[User:mordecaikraushar|Mordecai Kraushar]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [http://devslop.co/Home/Schedule Check out our schedule!] &lt;br /&gt;
* [July 2] Tanya Janca will be giving the &amp;quot;Hack Your Own Apps&amp;quot; workshop at the [https://www.spaconference.org/spa2018 SPA Conference in London], England. &lt;br /&gt;
* [June 4-6, 2018] The entire DevSlop team will be at the [https://owaspsummit.org/ Open Security Summit] in London, England. &lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher [https://twitter.com/thedeadrobots Twitter]&lt;br /&gt;
* [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter]&lt;br /&gt;
* [[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
* [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=241132</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=241132"/>
				<updated>2018-06-04T19:56:50Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added SPA conference.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP [http://devslop.co DevSlop] Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Project Website:  [http://devslop.co DevSlop]&lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of [http://devslop.co DevSlop] are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/DevSlop/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
&lt;br /&gt;
[[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
[[User:mordecaikraushar|Mordecai Kraushar]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [July 2] Tanya Janca will be giving the &amp;quot;Hack Your Own Apps&amp;quot; workshop at the [https://www.spaconference.org/spa2018 SPA Conference in London], England. &lt;br /&gt;
* [June 4-6, 2018] The entire DevSlop team will be at the [https://owaspsummit.org/ Open Security Summit] in London, England. &lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher [https://twitter.com/thedeadrobots Twitter]&lt;br /&gt;
* [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter]&lt;br /&gt;
* [[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
* [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=240751</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=240751"/>
				<updated>2018-05-16T20:58:16Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added Imran as leader, Mo as participant, and https://owaspsummit.org/&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP [http://devslop.co DevSlop] Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Project Website:  [http://devslop.co DevSlop]&lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of [http://devslop.co DevSlop] are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DevSlop-Project/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
&lt;br /&gt;
[[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
[[User:mordecaikraushar|Mordecai Kraushar]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [June 4-6, 2018] The entire DevSlop team will be at the [https://owaspsummit.org/ Open Security Summit] in London, England. &lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher [https://twitter.com/thedeadrobots Twitter]&lt;br /&gt;
* [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter]&lt;br /&gt;
* [[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
* [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=239227</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=239227"/>
				<updated>2018-04-02T13:51:39Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added user links for team members&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DevSlop-Project/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
[[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher [https://twitter.com/thedeadrobots Twitter]&lt;br /&gt;
* [[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter]&lt;br /&gt;
* [[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
* [[User:Franziskabuehler|Franziska Bühler]] [https://twitter.com/bufrasch Twitter]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:DevSlop_Logo.jpg&amp;diff=239212</id>
		<title>File:DevSlop Logo.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:DevSlop_Logo.jpg&amp;diff=239212"/>
				<updated>2018-04-02T03:06:53Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Tanyajanca uploaded a new version of File:DevSlop Logo.jpg&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;DevSlop Project Logo&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=239211</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=239211"/>
				<updated>2018-04-02T03:03:05Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added User link for secfigo&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DevSlop-Project/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
[[User:Secfigo|Mohammed A. Imran]] [https://twitter.com/secfigo Twitter] &lt;br /&gt;
&lt;br /&gt;
Franziska Bühler [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
* Mohammed A. Imran &lt;br /&gt;
* Franziska Bühler&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=239210</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=239210"/>
				<updated>2018-04-02T03:00:59Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Roadmap update&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DevSlop-Project/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
Mohammed A. Imran [https://twitter.com/secfigo Twitter] &lt;br /&gt;
&lt;br /&gt;
Franziska Bühler [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
* Mohammed A. Imran &lt;br /&gt;
* Franziska Bühler&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of March 2018:&lt;br /&gt;
* Add new team members&lt;br /&gt;
* Each add our own components to our new repo&lt;br /&gt;
* Get ready for Open Security Summit&lt;br /&gt;
* Release and document all work done at the Open Security Summit&lt;br /&gt;
&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=239209</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=239209"/>
				<updated>2018-04-02T02:58:33Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added donate button&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DevSlop-Project/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
Mohammed A. Imran [https://twitter.com/secfigo Twitter] &lt;br /&gt;
&lt;br /&gt;
Franziska Bühler [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''How can I donate to DevSlop?''' &lt;br /&gt;
&lt;br /&gt;
Click the button!  :)&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=OWASP DevSlop&lt;br /&gt;
}}   &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=239208</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=239208"/>
				<updated>2018-04-02T02:47:25Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added two new project members, updated some links.  More work need to be done.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DevSlop-Project/ Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[Index.php/OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Team Members ==&lt;br /&gt;
Mohammed A. Imran [https://twitter.com/secfigo Twitter] &lt;br /&gt;
&lt;br /&gt;
Franziska Bühler [https://twitter.com/bufrasch Twitter]  &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [May 18, 2018] Pixi workshop presented at [https://www.nsec.io NorthSec] in Montreal, Canada. &lt;br /&gt;
* [March 2018] Introduced new project team members: Mohammed A. Imran and Franziska Bühler &lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=237289</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=237289"/>
				<updated>2018-02-04T18:57:13Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: dd&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;br&amp;gt; &lt;br /&gt;
Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;br&amp;gt;&lt;br /&gt;
Talk to us on [https://owaspottawa.slack.com Slack]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email us: [mailto:sherif.koussa@owasp.org Sherif], [mailto:tanya.janca@owasp.org Tanya] or [mailto:garth.boyd@owasp.org Garth]&lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;meetup group=&amp;quot;OWASP-Ottawa&amp;quot; /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
Organization Committee: Paul Ionescu, Pierre Ernst, Nancy Gariche, Rick Mitchel, Adam Janzen, David Petrasovic, Annie Fry, Oliver, Mark Tse&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=237288</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=237288"/>
				<updated>2018-02-04T18:56:38Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Troubleshooting autocorrect-related errors&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;br&amp;gt; &lt;br /&gt;
Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;br&amp;gt;&lt;br /&gt;
Talk to us on [https://owaspottawa.slack.com Slack]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email us: [mailto:sherif.koussa@owasp.org Sherif], [mailto:tanya.janca@owasp.org Tanya] or [mailto:garth.boyd@owasp.org Garth]&lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;meetup group=”OWASP-Ottawa” /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
Organization Committee: Paul Ionescu, Pierre Ernst, Nancy Gariche, Rick Mitchel, Adam Janzen, David Petrasovic, Annie Fry, Oliver, Mark Tse&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=237286</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=237286"/>
				<updated>2018-02-04T17:08:15Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Troubleshooting meetup link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;br&amp;gt; &lt;br /&gt;
Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;br&amp;gt;&lt;br /&gt;
Talk to us on [https://owaspottawa.slack.com Slack]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email us: [mailto:sherif.koussa@owasp.org Sherif], [mailto:tanya.janca@owasp.org Tanya] or [mailto:garth.boyd@owasp.org Garth]&lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;meetup group=“OWASP-Ottawa” /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
Organization Committee: Paul Ionescu, Pierre Ernst, Nancy Gariche, Rick Mitchel, Adam Janzen, David Petrasovic, Annie Fry, Oliver, Mark Tse&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=237252</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=237252"/>
				<updated>2018-02-03T18:07:58Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: troubleshooting meetup link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;br&amp;gt; &lt;br /&gt;
Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;br&amp;gt;&lt;br /&gt;
Talk to us on [https://owaspottawa.slack.com Slack]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email us: [mailto:sherif.koussa@owasp.org Sherif], [mailto:tanya.janca@owasp.org Tanya] or [mailto:garth.boyd@owasp.org Garth]&lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;meetup group=“OWASP-Ottawa” /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
Organization Committee: Paul Ionescu, Pierre Ernst, Nancy Gariche, Rick Mitchel, Adam Janzen, David Petrasovic, Annie Fry, Oliver, Mark Tse&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=237251</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=237251"/>
				<updated>2018-02-03T18:07:18Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added meetup link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;br&amp;gt; &lt;br /&gt;
Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;br&amp;gt;&lt;br /&gt;
Talk to us on [https://owaspottawa.slack.com Slack]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email us: [mailto:sherif.koussa@owasp.org Sherif], [mailto:tanya.janca@owasp.org Tanya] or [mailto:garth.boyd@owasp.org Garth]&lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
[https://www.meetup.com/OWASP-Ottawa Visit our group on meetup.com]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;meetup group=“OWASP-Ottawa” /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
Organization Committee: Paul Ionescu, Pierre Ernst, Nancy Gariche, Rick Mitchel, Adam Janzen, David Petrasovic, Annie Fry, Oliver, Mark Tse&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=236778</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=236778"/>
				<updated>2018-01-13T00:55:35Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added Event of AppSec California 2018.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [28 Jan 2018} DevSlop full day workshop at [http://sched.co/CuDe AppSec Cali: Intro To Web Hacking Using ZAP/Hacking APIs And The MEAN Stack] &lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Ottawa&amp;diff=236432</id>
		<title>Talk:Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Ottawa&amp;diff=236432"/>
				<updated>2017-12-27T00:12:57Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Adding new plugin link for previous Meetups.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Previous Meetups!'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;meetup group=&amp;quot;OWASP-Ottawa&amp;quot; /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=236431</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=236431"/>
				<updated>2017-12-27T00:05:26Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Removed dead PayPal link and added Slack link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;br&amp;gt; &lt;br /&gt;
Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;br&amp;gt;&lt;br /&gt;
Talk to us on [https://owaspottawa.slack.com Slack]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email us: [mailto:sherif.koussa@owasp.org Sherif], [mailto:tanya.janca@owasp.org Tanya] or [mailto:garth.boyd@owasp.org Garth]&lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
Organization Committee: Paul Ionescu, Pierre Ernst, Nancy Gariche, Rick Mitchel, Adam Janzen, David Petrasovic, Annie Fry, Oliver, Mark Tse&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=236430</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=236430"/>
				<updated>2017-12-27T00:01:39Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Removing extra spaces&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;b&amp;gt;Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Ottawa&amp;lt;/paypal&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email us: [mailto:sherif.koussa@owasp.org Sherif], [mailto:tanya.janca@owasp.org Tanya] or [mailto:garth.boyd@owasp.org Garth]&lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
Organization Committee: Paul Ionescu, Pierre Ernst, Nancy Gariche, Rick Mitchel, Adam Janzen, David Petrasovic, Annie Fry, Oliver, Mark Tse&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=236429</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=236429"/>
				<updated>2017-12-26T23:58:36Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;b&amp;gt;Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Ottawa&amp;lt;/paypal&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email us: [mailto:sherif.koussa@owasp.org Sherif], [mailto:tanya.janca@owasp.org Tanya] or [mailto:garth.boyd@owasp.org Garth]&lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
Organization Committee: Paul Ionescu, Pierre Ernst, Nancy Gariche, Rick Mitchel, Adam Janzen, David Petrasovic, Annie Fry, Oliver, Mark Tse &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=236428</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=236428"/>
				<updated>2017-12-26T23:53:41Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Adding Garth as Leader&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa].  The Chapter leaders are  [mailto:sherif.koussa@owasp.org Sherif Koussa], [mailto:tanya.janca@owasp.org Tanya Janca] and&lt;br /&gt;
[mailto:garth.boyd@owasp.org Garth Boyd]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;b&amp;gt;Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Ottawa&amp;lt;/paypal&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email one of us: [mailto:sherif.koussa@owasp.org Sherif] or [mailto:tanya.janca@owasp.org Tanya] &lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
Chapter Leaders: [mailto:sherif.koussa@owasp.org Sherif Koussa]&amp;amp;nbsp;and [mailto:tanya.janca@owasp.org Tanya Janca] &lt;br /&gt;
&lt;br /&gt;
Organization Committee: Garth Boyd, Pierre Ernst, Phil Dorman, Nancy Gariche, Adam Janzen&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=236284</id>
		<title>Ottawa</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ottawa&amp;diff=236284"/>
				<updated>2017-12-15T15:39:45Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added Meetup, corrected Tanya being chapter coordinator at bottom of screen.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Ottawa|extra=The chapter's president is [mailto:sherif.koussa@owasp.org Sherif Koussa] and Chapter Co-Leader is [mailto:tanya.janca@owasp.org Tanya Janca]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Join our [https://www.meetup.com/OWASP-Ottawa/ MeetUp]!&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;b&amp;gt;Follow us on  [http://twitter.com/#!/owasp_ottawa Twitter]&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Ottawa&amp;lt;/paypal&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-ottawa|emailarchives=http://lists.owasp.org/mailman/listinfo/owasp-ottawa}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Your Local Chapter==&lt;br /&gt;
Hi Ottawa, welcome to your local OWASP chapter! We are a place to come and meet local developers and information security professionals, share ideas, and learn. We try to hold a meeting at least once every two months in the downtown core. We provide a mix of infosec rockstar talks, hands on training sessions, and special interest discussion groups. We are always looking for new ideas for events so let us know if you have an idea. Email one of us: [mailto:sherif.koussa@owasp.org Sherif] or [mailto:tanya.janca@owasp.org Tanya] &lt;br /&gt;
&lt;br /&gt;
For updates, events, membership; please visit our meetup page: http://www.meetup.com/OWASP-Ottawa/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Leadership  ==&lt;br /&gt;
&lt;br /&gt;
Chapter Leaders: [mailto:sherif.koussa@owasp.org Sherif Koussa]&amp;amp;nbsp;and [mailto:tanya.janca@owasp.org Tanya Janca] &lt;br /&gt;
&lt;br /&gt;
Organization Committee: Garth Boyd, Pierre Ernst, Phil Dorman, Nancy Gariche, Adam Janzen&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Slides from the Previous Meeting: ===&lt;br /&gt;
Threat Modeling Toolkit - Jonathan Marcil - [https://www.owasp.org/images/0/02/Threat_Modeling_Toolkit_-_OWASP-ottawa-publish.pptx Slides]&lt;br /&gt;
&lt;br /&gt;
[[Category:Canada]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233481</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233481"/>
				<updated>2017-09-19T15:48:01Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added more to FAQ on how to start pixi&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
You can manually download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; cd pixi &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In your browser go to: &amp;lt;nowiki&amp;gt;http://localhost:8000/login&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233071</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233071"/>
				<updated>2017-09-10T18:03:01Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Nikki's wording changes.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|315x315px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs, microservices and containerization to deliver faster and better products and services.   There has been a massive migration away from monolithic web applications to this new, highly scalable architecture.  However, there are currently few training grounds for security testing in these areas. In comes DevSlop, OWASP's newest project, a collection of DevOps-driven applications, specifically designed to showcase security catastrophes and vulnerabilities for use in security testing, software testing, learning and teaching for both developers and security professionals. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi''', the first of many applications to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in several docker containers and consists of a vulnerable web app and API service.  The intent is to teach users how to test modern web applications and API's for security issues and how to write more secure API's in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
Download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233064</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233064"/>
				<updated>2017-09-10T01:20:39Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: /* Main */  Bad spacing.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|342x342px|DevSlop Project Logo]] &lt;br /&gt;
&lt;br /&gt;
Modern applications often use APIs and other micro services to deliver faster and better products and services. However, there are currently few training grounds for security testing in such areas. In comes DevSlop, OWASP's newest project, a collection of DevOps security catastrophes made as a vulnerable testing and proving ground for developers and security testers alike. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi,''' the first of many entries to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in a docker container and consists of vulnerable web services, which will hopefully teach users how to test APIs for security and how to write better APIs in the future.  It is intentionally vulnerable, with the hopes that users can learn to test on it and also learn how to create better APIs in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
Download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233061</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233061"/>
				<updated>2017-09-09T20:49:20Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: First draft COMPLETE!&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|342x342px|DevSlop Project Logo]]Modern applications often use APIs and other micro services to deliver faster and better products and services. However, there are currently few training grounds for security testing in such areas. In comes DevSlop, OWASP's newest project, a collection of DevOps security catastrophes made as a vulnerable testing and proving ground for developers and security testers alike. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi,''' the first of many entries to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in a docker container and consists of vulnerable web services, which will hopefully teach users how to test APIs for security and how to write better APIs in the future.  It is intentionally vulnerable, with the hopes that users can learn to test on it and also learn how to create better APIs in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
Download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
The OWASP DevSlop project is intended as place for people to learn about new, modern and different web related application security issues.  It is a vulnerable series of systems, open to the public to download and play with.  The first instalment is called Pixi and is available now.  More pieces will be released as they are available, as well as training and other learning aids.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233060</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233060"/>
				<updated>2017-09-09T20:44:53Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|342x342px|DevSlop Project Logo]]Modern applications often use APIs and other micro services to deliver faster and better products and services. However, there are currently few training grounds for security testing in such areas. In comes DevSlop, OWASP's newest project, a collection of DevOps security catastrophes made as a vulnerable testing and proving ground for developers and security testers alike. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi,''' the first of many entries to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in a docker container and consists of vulnerable web services, which will hopefully teach users how to test APIs for security and how to write better APIs in the future.  It is intentionally vulnerable, with the hopes that users can learn to test on it and also learn how to create better APIs in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
Download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233059</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233059"/>
				<updated>2017-09-09T20:42:22Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Not quite a finished first draft&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|342x342px|DevSlop Project Logo]]Modern applications often use APIs and other micro services to deliver faster and better products and services. However, there are currently few training grounds for security testing in such areas. In comes DevSlop, OWASP's newest project, a collection of DevOps security catastrophes made as a vulnerable testing and proving ground for developers and security testers alike. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi,''' the first of many entries to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in a docker container and consists of vulnerable web services, which will hopefully teach users how to test APIs for security and how to write better APIs in the future.  It is intentionally vulnerable, with the hopes that users can learn to test on it and also learn how to create better APIs in the future.[[File:Pixi logo.png|alt= Pixi Logo|thumb|145x145px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation.  OWASP DevSlop and any contributions are Copyright &amp;amp;copy; by Nicole Becher &amp;amp; Tanya Janca 2017.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thedeadrobots/pixi.git What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
[[OWASP DevSlop Project|Wiki Home Page]]&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
[https://www.slideshare.net/TanyaJanca/api-and-web-service-hacking-with-pixi-part-of-owasp-devslop Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Nicolebecher|Nicole Becher]] [https://twitter.com/thedeadrobots Twitter] &lt;br /&gt;
&lt;br /&gt;
[[User:Tanyajanca|Tanya Janca]] [https://twitter.com/shehackspurple Twitter] &lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
* [[OWASP Juice Shop Project]]&lt;br /&gt;
* [[OWASP WebGoat Project]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [19 Sept 2017] DevSlop 3 hour workshop presented as part of the [[AppSecUSA 2017 Developer Summit|AppSec USA 2017 Developer Summit]].&lt;br /&gt;
* [5 Sept 2017] DevSlop project team interviewed on [https://appsecpodcast.org/2017/09/05/hacking-apis-and-web-services-with-devslop-s02e13/ AppSec Podcast]&lt;br /&gt;
* [12 July 2017] [https://www.youtube.com/watch?v=td-2rN4PgRw&amp;amp;feature=youtu.be DevSlop Project announced at Microsoft Tech Days in NYC.]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
'''Where can I get Pixi?'''  [[File:Pixi Image.png|alt= Pixi|thumb|96x96px|'''Pixi''']]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
Download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone https://github.com/thedeadrobots/pixi.git &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up &amp;lt;enter&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You're all set!     &lt;br /&gt;
&lt;br /&gt;
'''I have a great idea for new DevSlop additions, how do I tell you(s)?'''  &lt;br /&gt;
&lt;br /&gt;
Email us!  firstname.lastname@owasp.org (Nicole Becher and Tanya Janca). You can do the math.  :)   &lt;br /&gt;
&lt;br /&gt;
'''How can I follow updates on the project?'''  &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/thedeadrobots Nicole Becher on Twitter]   &lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/shehackspurple Tanya Janca on Twitter] &lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for people to give us ideas for new components and problems to add, as well as people to help code them.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP DevSlop Project was created by the project leaders, Nicole and Tanya.  Contributors include: Mordecai Kraushar.   &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* Nicole Becher&lt;br /&gt;
* Tanya Janca&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September 2017, the highest priorities for the next 12 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
Each DevSlop component will have it's own roadmap.&lt;br /&gt;
&lt;br /&gt;
'''DevSlop Project Roadmap:'''&lt;br /&gt;
* Finish completing this Wiki page and get it reviewed/approved&lt;br /&gt;
* Move all Pixi code into OWASP GitHub&lt;br /&gt;
* Promote Project (interviews, speaking engagements, articles, etc)&lt;br /&gt;
* Document Project &lt;br /&gt;
* Create Issue Tracker&lt;br /&gt;
* Follow Pixi Roadmap&lt;br /&gt;
* Accept ideas for future components&lt;br /&gt;
* Create HTTP 2.0 app as Component #2&lt;br /&gt;
* Create more DevOps apps&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Pixi Roadmap (First DevSlop Component):'''&lt;br /&gt;
* Document all the vulnerabilities&lt;br /&gt;
* Multi language support&lt;br /&gt;
* Finish CTF mode&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of '''DevSlop''' is actively encouraged!  You do not have to be a security expert or a programmer to contribute.  Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
=== Ideas ===&lt;br /&gt;
We need to know where to go next with this project.  Have you seen an IT tragedy recently?  Tell us about it!  The more modern and 'different' the better!&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with coding it.  Someone like you.&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;DevSlop Project&amp;lt;/strong&amp;gt; into that language?  Pretty please?&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please email us to give us feedback: firstname.lastname@owasp.org (Nicole Becher and Tanya Janca)&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
The DevSlop Project must provide documentation (in form of videos, blog posts, interviews, within the app, or anything else) to teach users how to use it.  Without any information it's hard to know if the users are learning all of the lessons that they need to.  It would also be ideal if Pixi and other future components were translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233058</id>
		<title>OWASP DevSlop Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSlop_Project&amp;diff=233058"/>
				<updated>2017-09-09T19:43:20Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Not even first draft version yet.  Saving just in case!&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP DevSlop Tool Project==&lt;br /&gt;
''The hacker jungle gym built on DevOps disasters.''[[File:DevSlop Logo.jpg|alt= DevSlop Project Logo|thumb|342x342px|DevSlop Project Logo]]Modern applications often use APIs and other micro services to deliver faster and better products and services. However, there are currently few training grounds for security testing in such areas. In comes DevSlop, OWASP's newest project, a collection of DevOps security catastrophes made as a vulnerable testing and proving ground for developers and security testers alike. &lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
DevSlop's '''Pixi,''' the first of many entries to come for this OWASP project, is currently publicly available for your hacking and learning pleasure. Pixi is available in a docker container and consists of vulnerable web services, which will hopefully teach users how to test APIs for security and how to write better APIs in the future.[[File:Pixi Image.png|alt= Pixi|thumb|96x96px|Pixi]]&lt;br /&gt;
&lt;br /&gt;
To get Pixi is simple!&lt;br /&gt;
&lt;br /&gt;
Download Pixi here: &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install Docker and start it. &lt;br /&gt;
&lt;br /&gt;
Then type the following at your command prompt:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; git clone &amp;lt;nowiki&amp;gt;https://github.com/thedeadrobots/pixi.git&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;gt; docker-compose up&lt;br /&gt;
&lt;br /&gt;
You're all set!  [[File:Pixi logo.png|alt= Pixi Logo|thumb|188x188px|Pixi Logo]]&lt;br /&gt;
&lt;br /&gt;
As more pieces of DevSlop are released they will be introduced here.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
* [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Tool_Project_Template Tool Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Pixi_logo.png&amp;diff=233057</id>
		<title>File:Pixi logo.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Pixi_logo.png&amp;diff=233057"/>
				<updated>2017-09-09T19:38:33Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Pixi Logo&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Pixi_Image.png&amp;diff=233055</id>
		<title>File:Pixi Image.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Pixi_Image.png&amp;diff=233055"/>
				<updated>2017-09-09T19:37:21Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Pixi Image&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:DevSlop_Logo.jpg&amp;diff=233054</id>
		<title>File:DevSlop Logo.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:DevSlop_Logo.jpg&amp;diff=233054"/>
				<updated>2017-09-09T19:33:57Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;DevSlop Project Logo&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Nicole,_Tanya_and_Pixi_at_Microsoft_Tech_Day,_NYC,_July_2017.jpg&amp;diff=233053</id>
		<title>File:Nicole, Tanya and Pixi at Microsoft Tech Day, NYC, July 2017.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Nicole,_Tanya_and_Pixi_at_Microsoft_Tech_Day,_NYC,_July_2017.jpg&amp;diff=233053"/>
				<updated>2017-09-09T19:32:57Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Nicole and Tanya present Pixi to the world for the first time, my crushing her into oblivion in front of a live audience.&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Tanyajanca&amp;diff=233051</id>
		<title>User:Tanyajanca</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Tanyajanca&amp;diff=233051"/>
				<updated>2017-09-09T19:19:05Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: grammar&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Tanya Janca and the Canadian Parliament.jpg|thumb]]&lt;br /&gt;
Tanya Janca is an application security evangelist, web application penetration tester, trainer, public speaker, ethical hacker, an effective altruist and has been developing software since the late 90’s.  She is an [[Ottawa|Ottawa Chapter Leader]] and has helped to grow her chapter by doing public speaking at OWASP and other places, creating new types of OWASP events for their chapter (workshops, debates, capture the flags, trivia nights), starting a mentoring program, and has been heavily promoting OWASP and the use of it's tools in the Canadian Government for years.  She's also working on a new OWASP Project called [[OWASP DevSlop Project|DevSlop]] with [[User:Nicolebecher|Nicole Becher]].&lt;br /&gt;
&lt;br /&gt;
During her 20 years of working in IT Tanya has worn many hats and done many things, including; Web App PenTesting, Technical Training, Custom Apps/Software Development, Network VA, Ethical Hacking, COTS, Incident Response, Enterprise Architect, Project and People Management, and even Tech Support.  She is currently helping the Government of Canada secure their web applications.  &lt;br /&gt;
&lt;br /&gt;
Tanya will talk to anyone, any time, about application security and OWASP.  Find out more of what Tanya's up to on Twitter: @SheHacksPurple&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Tanyajanca&amp;diff=233050</id>
		<title>User:Tanyajanca</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Tanyajanca&amp;diff=233050"/>
				<updated>2017-09-09T19:17:35Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added links to DevSlop, Ottawa Chapter and Nicole user page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Tanya Janca and the Canadian Parliament.jpg|thumb]]&lt;br /&gt;
Tanya Janca is an application security evangelist, web application penetration tester, trainer, public speaker, ethical hacker, an effective altruist and has been developing software since the late 90’s.  She is an [[Ottawa|Ottawa Chapter Leader]] and has helped to grow her chapter by doing public speaking at OWASP and other places, creating new types of OWASP events for their chapter (workshops, debates, capture the flags trivia nights), starting a mentoring program, and has been heavily promoting OWASP and the use of it's tools in the Canadian Government for years.  She's also working on a new OWASP Project called [[OWASP DevSlop Project|DevSlop]] with [[User:Nicolebecher|Nicole Becher]].&lt;br /&gt;
&lt;br /&gt;
During her 20 years of working in IT Tanya has worn many hats and done many things, including; Web App PenTesting, Technical Training, Custom Apps/Software Development, Network VA, Ethical Hacking, COTS, Incident Response, Enterprise Architect, Project and People Management, and even Tech Support.  She is currently helping the Government of Canada secure their web applications.  &lt;br /&gt;
&lt;br /&gt;
Tanya will talk to anyone, any time, about application security and OWASP.  Find out more of what Tanya's up to on Twitter: @SheHacksPurple&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Tanyajanca&amp;diff=232462</id>
		<title>User:Tanyajanca</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Tanyajanca&amp;diff=232462"/>
				<updated>2017-08-19T04:26:45Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Removed WIA Chair information.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Tanya Janca and the Canadian Parliament.jpg|thumb]]&lt;br /&gt;
Tanya Janca is an application security evangelist, web application penetration tester, trainer, public speaker, ethical hacker, an effective altruist and has been developing software since the late 90’s.  She is an Ottawa Chapter Leader and has helped to grow her chapter by doing public speaking at OWASP and other places, creating new types of OWASP events for their chapter (workshops, debates, capture the flags trivia nights), starting a mentoring program, and has been heavily promoting OWASP and the use of it's tools in the Canadian Government for years.  She's also working on a new OWASP Project: DevSlop.&lt;br /&gt;
&lt;br /&gt;
During her 20 years of working in IT Tanya has worn many hats and done many things, including; Web App PenTesting, Technical Training, Custom Apps/Software Development, Network VA, Ethical Hacking, COTS, Incident Response, Enterprise Architect, Project and People Management, and even Tech Support.  She is currently helping the Government of Canada secure their web applications.  &lt;br /&gt;
&lt;br /&gt;
Tanya will talk to anyone, any time, about application security and OWASP.  Find out more of what Tanya's up to here: @SheHacksPurple&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=WASPY_Awards_2017&amp;diff=231551</id>
		<title>WASPY Awards 2017</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=WASPY_Awards_2017&amp;diff=231551"/>
				<updated>2017-07-11T10:45:38Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: Added links to https://www.owasp.org/index.php/User:Tanyajanca&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:WASPY 2017 Banner.jpg]]&lt;br /&gt;
&lt;br /&gt;
==Purpose of the Awards==&lt;br /&gt;
&lt;br /&gt;
Each year there are many individuals who do amazing work, dedicating countless hours to share, improve, and strengthen the OWASP mission. Some of these individuals are well known to the community while others are not. &lt;br /&gt;
&lt;br /&gt;
'''The purpose of these awards is to bring recognition to those who &amp;quot;FLY UNDER THE RADAR&amp;quot;. These are the individuals who are passionate about OWASP, who contribute hours of their own free time to the organization to help improve the cyber-security world, yet seem to go unrecognized.''' &lt;br /&gt;
&lt;br /&gt;
==Timeline==&lt;br /&gt;
Call for Nominees Opens June 7, 2017  &lt;br /&gt;
&lt;br /&gt;
Call for Nominees Closes June 30, 2017 - CLOSED &lt;br /&gt;
&lt;br /&gt;
Announcement of Nominees per Category July 5, 2017 - DONE &lt;br /&gt;
&lt;br /&gt;
Deadline for Nominee Profile Picture and Bio to be created and added to the Nominees section July 10, 2017 &lt;br /&gt;
&lt;br /&gt;
Voting for Board &amp;amp; Staff Members Opens July 17, 2017 &lt;br /&gt;
&lt;br /&gt;
Voting for Board &amp;amp; Staff Members Closes July 24, 2017  &lt;br /&gt;
&lt;br /&gt;
Winners are Notified July 25, 2017 &lt;br /&gt;
&lt;br /&gt;
Announcement of Winners to the Community July 25, 2017 &lt;br /&gt;
&lt;br /&gt;
Award Ceremony at AppSecUSA 2017 in Orlando, FL September 21-22, 2017 &lt;br /&gt;
&lt;br /&gt;
==Categories==&lt;br /&gt;
The WASPYs celebrate the actors in our community who grow OWASP and drive innovation to the safety and security of the world’s software. This year we are excited to offer three categories.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Best Community Supporter''' - The WASPY for COMMUNITY honors members who create dynamic INTERACTION and LEARNING opportunities for the OWASP Community.  Nominees to the Community WASPY Award create collaborative and inclusive environments and grow the OWASP Community.  WASPYs focus on the unsung heros of the OWASP community.  Chapter Leaders and Community Members should especially consider leaders and volunteers who bring something extra to the environment, help the chapter reach out to new attendees, or carry out the tedious and repetitive tasks that make growing an OWASP Chapter possible.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Best Mission Outreach'''  - The WASPY for Mission Outreach honors community members who help the community GROW.  Growth can happen inside the larger OWASP community or outside it in the broader AppSec and development communities.   Leaders and Members should especially consider volunteers who pushed the boundaries of the audience and reach of OWASP to provide new exposure for OWASP’s projects and chapters.  New leaders and volunteers who help bring more people to your chapter, project, or actively represent OWASP at non-OWASP events, gatherings, and activities to build an active OWASP community are ideal candidates for the Mission Outreach WASPY award.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Best Innovator'''  - The WASPY for Innovation is given to a community member who has contributed to the TECHNICAL advancement of OWASP in the past year.  This advancement is usually through an [[:Category:OWASP Project|OWASP Project]] and can be in the form of code, an application, or anything that materially makes the AppSec community better in a unique way.  WASPYs focus on the unsung heros of the OWASP community who quietly go about making the world a bit better for their work.  Project Leaders and Community Members should especially consider nominating new projects, projects that have recently graduated, and project contributors for this WASPY.&lt;br /&gt;
&lt;br /&gt;
==Rules==&lt;br /&gt;
'''Remember the purpose of these awards is to recognize the UNSUNG HEROS out there, that are barely recognized for their contributions to the OWASP Foundation.''' &lt;br /&gt;
&lt;br /&gt;
1. [https://www.owasp.org/index.php/About_OWASP#2015_Global_Board_Members Board members] may not be nominated &lt;br /&gt;
&lt;br /&gt;
2. [https://www.owasp.org/index.php/About_OWASP#Employees_and_Contractors_of_the_OWASP_Foundation Employees &amp;amp; Contractors] may not be nominated &lt;br /&gt;
&lt;br /&gt;
3. All nominees will remain anonymous until July 3, 2017&lt;br /&gt;
&lt;br /&gt;
4. Anyone can nominate an &amp;quot;unsung hero&amp;quot; who has contributed in some way to OWASP who they feel best fits each category &lt;br /&gt;
&lt;br /&gt;
5. You may only nominate one person per category &lt;br /&gt;
&lt;br /&gt;
=='''And the Nominees Are...'''==&lt;br /&gt;
{| cellpadding=&amp;quot;2&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
! width=&amp;quot;150&amp;quot; align=&amp;quot;center&amp;quot; scope=&amp;quot;col&amp;quot; |Name&lt;br /&gt;
! width=&amp;quot;800&amp;quot; align=&amp;quot;center&amp;quot; scope=&amp;quot;col&amp;quot; |Category &amp;amp; Citation&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |Aatral Arasu&lt;br /&gt;
|'''''Best Community Supporter''''' &lt;br /&gt;
&amp;quot;A great leader always there to help responds to emails quickly loves his work works very hard every day very supportive never loses focus strong willed very technical and willing to do things himself to get the job done when asked for something he will get it to you ASAP constant learner open to suggestions and ideas on how to be better respectful honest caring and I am certain HRC will make it big very soon :)&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Sean Auriti&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Sean has not only worked as a volunteer in the local chapter building community, his code projects are useful to the mission and his outreach efforts have included funding requests for OWASP Foundation to grow its mission. Sean is a great example of a community member.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Nicole Becher&lt;br /&gt;
|&amp;lt;nowiki/&amp;gt;'''''Best Community Supporter'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Nicole has been an amazing chapter leader. She brings knowledge and experience teaching cybersecurity to the Mentor Initiative, WIA Committee, and projects.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Ken Belva&lt;br /&gt;
|&amp;lt;nowiki/&amp;gt;'''''Best Community Supporter'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Ken is a long time chapter leader of the NYC chapter and a former chapter leader of the Brooklyn Chapter. Ken is always willing to step in and volunteer to help with OWASP initiatives and is a frequent participant in OWASP events as both a volunteer and speaker. Ken has spoken at AppSec USA on XSS techniques (&amp;lt;nowiki&amp;gt;https://www.youtube.com/watch?v=G539NwvpL3I&amp;lt;/nowiki&amp;gt;) and is the project lead for the Basic Expression and Lexicon Variation Algorithms project (&amp;lt;nowiki&amp;gt;https://www.owasp.org/index.php/OWASP_Basic_Expression_%26_Lexicon_Variation_Algorithms_(BELVA)_Project)&amp;lt;/nowiki&amp;gt;.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Tony Clarke&lt;br /&gt;
|&amp;lt;nowiki/&amp;gt;'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Tony has selflessly brought the OWASP dublin chapter to great nights. He has nurtured the chapter to be inclusive and open whilst growing the average attendee count to hundreds. He has spread the word across both security industry and developer industry and has also managed to get various organisations to work together such as ISACA, IISF, ISSA and ISC2. He is a great leader and despite detractors has built the chapter and awareness of software security issues in a strong vendor neutral manner to a great place. Tony is a great example of OWASP and industry leadership.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Dinis Cruz&lt;br /&gt;
|&amp;lt;nowiki/&amp;gt;'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Diniz is a fantastic innovator and motivator. As the mastermind and organizer behind the OWASP Summit he has managed to re-energize the OWASP community - many interesting projects would not have happened (or at least, not been that successful) without his passionate work. Besides organizing the event, he also consistently supported project leaders with his experience and ideas.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''2nd Citation:''' Dinis put ridiculous effort (&amp;lt;nowiki&amp;gt;https://github.com/OWASP/owasp-summit-2017/commits?author=DinisCruz&amp;lt;/nowiki&amp;gt;) into the OWASP Summit 2017 and didn't tire promoting this event!&lt;br /&gt;
|-&lt;br /&gt;
|[[User:Dune73|Christian Folini]]&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Christian Folini is very active in the Core Rule Set project community. He responds to a ton of questions submitted by newcomers when they are stuck and he answers expert level questions with stunning detail. He joined Chaim and Walter when they revived the project in 2016 and I heard he had the idea for the famous CRS3 release poster &amp;lt;nowiki&amp;gt;https://modsecurity.org/crs/poster&amp;lt;/nowiki&amp;gt; that was shared all over the net.  I think it's people like him that give OWASP a human face.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[[User:Fuentes.joaquin|Joaquin Fuentes]]&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;In 2015, Joaquin took it upon himself to revive the OWASP Phoenix Chapter. He created a meet-up group to gain broader visibility. Since 2015, the meeting attendance has grown from an average of 15 attendees to over 60! Joaquin dedicates a lot of time and effort into scheduling an impressive variety of presentation topics including safe hacking, vulnerability scanner deep dives, hands on web exploitation CTF, video game hacking and more. I learn something new and cool at every event.&lt;br /&gt;
&lt;br /&gt;
More importantly, Joaquin works hard to foster a friendly, inclusive environment. During our hands-on web exploitation session, Joaquin recruited co-works to assist participants with the Security Shephard challenges so no one felt overwhelmed or impossibly stuck. He always takes the time meet and welcome new members. For example, my 17-year-old son attends meetings with me. He looks up to Joaquin as a mentor for a future information security career because Joaquin encourages his learning and offers career guidance.&lt;br /&gt;
&lt;br /&gt;
I highly recommend Joaquin for a WASPY award!! He is a kind, soft spoken person with a passion for sharing information security and helping others!&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''2nd Citation:''' &amp;quot;He resurrected the Phoenix chapter and has kept it going with great content.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''3rd Citation:''' &amp;quot;For all he has done to build up the Phoenix OWASP community. Prior to Joaquin taking point the community in Phoenix was dead. Meetings weren't happening on a regular basis. The prior leaders had done a great job but I think they had burnt out. Joaquin started the community back up and got corporate support from his employer to facilitate not only regular meetings but great meetings with great content. He also implemented MeetUp. I'm not a consistent attendee because of my work/life schedule but I always know when the meetings are happening and what the subject matter will be because of Joaquin utilizing MeetUp.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''4th Citation:''' &amp;quot;Put simply, due to the efforts of Joaquin Fuentes, the Phoenix chapter has risen from the ashes (some pun intended). Before Joaquin took over the chapter there were consistently between 5-10 persons in attendance, Joaquin himself being one of them, and the chapter only met about every 3 months or so. Since Joaquin took over the chapter, we have had fantastic presenters each month, paid for dinners, along with a collaborative, comfortable, and engaging environment to meet in. Even more impressive the attendance has grown to 60+ consistently. Joaquin isn't even done yet! He is more great ideas and plans for the chapter that will undoubtedly contribute to the continued growth and over all quality of this once fallen chapter. When he speaks of where this chapter has come from and his plans for the future, it is undeniable to all that he does so with the passion that a leader must possess to accomplish that which Joaquin has.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''5th Citation:''' &amp;quot;I am sure someone else will write in with Joaquin's email, but I felt the need to second his name on the list. The events he puts together are top notch, have excellent speakers, always have things to eat, and are generally excellent. I almost never miss them. He is actually so gracious about the entire chapter that I am sure he does not get the credit he deserves... the whole show is put on by just him, I think. Yay Joaquin!&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''6th Citation:''' &amp;quot;A few years ago, the Phoenix (AZ) OWASP group was basically defunct. As the leader of the Phoenix OWASP group, not only has Joaquin helped to resurrect the group, but we've had great presentations on reverse engineering, secure coding, a hands-on CTF contest with Security Shepherd, etc. Joaquin is a very visible member of the security community being an employee at Early Warning, which not only hosts the OWASP meetings, but also is a sponsor and makes a strong showing at CactusCon every year, the biggest security conference in Arizona.&lt;br /&gt;
&lt;br /&gt;
Our local OWASP group is not strong, going from being non-existent a few years ago to now getting a regular attendance of 40-80 people. I've gotten to know Joaquin through OWASP meetings and other security events in the area I have crossed paths with him, and he is a fine representative and evangelist for the OWASP organization.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''7th Citation:''' &amp;quot;Joaquin is the Phoenix OWASP Chapter leader and regularly plans amazing talks with great speakers for the Phoenix Community. Frequently, the Phoenix OWASP talks will have over 50 attendees which Joaquin manages without a problem! Joaquin also pushes for candidates he is interviewing to be familiar with OWASP before their interview.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''8th Citation:''' &amp;quot;Joaquin is the leader for the Phoenix OWASP, and it is clear that through his leadership the Phoenix OWASP thrives. Joaquin organizes all the meetings, and is constantly working with folks to create an excellent sense of community in the Phoenix area.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''9th Citation:''' &amp;quot;Joaquin has taken the Phoenix OWASP chapter that had not been managed for years and brought it back to life. We consistently see 50+ members coming to our Meetups to talk about AppSec related topics. Joaquin is well connected to the InfoSec groups and has had great success in pulling in new speakers, we have already had a few speakers who are prepping their BlackHat and DefCon talks by giving their presentations to our local chapter. Finally Joaquin does a great job by reaching out to the local colleges and supporting CTF activities to garner interest in pen-testing and the OWASP community. He is a true community supporter and fully deserves a WASPY for his efforts...&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''10th Citation:''' &amp;quot;Joaquin has been leading the OWASP Phoenix chapter and due to his initiative, has placed Phoenix on the map as a hub for application security. I would like to nominate him because he is always bringing in new and interesting speakers that provide great content. The most recent OWASP chapter meeting had over 60 attendees!&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''11th Citation:''' &amp;quot;As a leader of Phoenix OWASP chapter, Joaquin strives to organize talks and trainings to make people in the valley learn InfoSec and AppSec from experienced individuals. He has always gone a step ahead to conduct OWASP meetings that are informative and hands on. Right from giving Arizona State University (ASU) students an overview of basic InfoSec and career opportunities to organizing a hands on hacking workshop for people in the community, Joaquin has always demonstrated passion and determination to take Phoenix to a better place in the field of Cyber Security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''12th Citation:''' &amp;quot;I've attended and participated in three OWASP meetings lead by Joaquin. They are always well organized, offer a great learning experience and considerably contribute to the community. His continuous interest and dedication to the Phoenix chapter do not go unnoticed and are appreciated by all who attend.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''13th Citation:''' &amp;quot;Joaquin restarted the OWASP chapter in Phoenix/Scottsdale. Chapter meetings have grown significantly to where there were about 65 attendees at the most recent meeting with hundreds more on the mailing list (I was at the meeting, but I've only heard about the mailing list). As someone who works with him, I know how dedicated he is to the work of IT security and he's been able to attract top-notch speakers for OWASP meetings.'&lt;br /&gt;
&lt;br /&gt;
'''14th Citation:''' &amp;quot;Joaquin had successfully revived the Phoenix OWASP Chapter. Since, the chapter has excelled from zero to filled audience bringing security talent from all around to speak and educate to security professionals on the many facets of security domains.&lt;br /&gt;
&lt;br /&gt;
Additionally, this has provided a great forum to network with the many security professionals around the community and share their knowledge and strengthen the security community. &lt;br /&gt;
&lt;br /&gt;
Joaquin has provided his unselfish time as an OWASP Chapter leader, and has breathed new life into the Chapter.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''15th Citation:''' &amp;quot;Joaquin does a bang up job of running the Phoenix OWASP chapter. He does a great job of raising awareness and bringing folks from the infosec community into the fold.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''16th Citation:''' &amp;quot;Joaquin Fuentes has had a big impact in raising attendance at the Phoenix meetings to more than 100 people monthly. The quality has gotten significantly better under his leadership. He has organized many speakers, including recruiting speakers from out of the area that have significantly developed the knowledge base of the community. Joaquin is a pen testing manager at Early Warning and he shares his professional knowledge to help us all become better in the practice of information security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''17th Citation:''' No citation was submitted&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/User:Brianglas Brian Glas]&lt;br /&gt;
|'''''Best Community Supporter''''' &lt;br /&gt;
&amp;quot;Brian has been paramount in 2 very strategic initiatives for OWASP. He is not only a Project Leader for the OWASP SAMM project but he has been instrumental in revamping the call for data and reorganizing the flagship OWASP Top Ten. Brian continues to support and speak about the benefits of supporting OWASP especially projects and participating in the Summit. Please consider Brian Glas as the Best Community Supporter for this year.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Brendan Gormley&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Throughout the Brendan has not only assisted in making the dublin chapter events happen but taken a lead role. Brendan has organised venues and speakers for these events often going above and beyond to ensure success. Brendan has also been involved in some of the outreach programs the Dublin chapter had been involved in. No task is too big or too small for Brendan and without him I don't believe the Dublin chapter would be what it is.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/User:Tanyajanca Tanya Janca]&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Tanya Janca has been performing “outreach” and “recruitment of women” as her main chapter leader responsibilities for the Ottawa chapter since 2015. The chapter has not only grown by over 500% in that time, but female membership has grown from 2 female members to over 70 (the chapter has grown for many reasons, some of which are her promotional efforts). Activities include starting a mentoring program that matches senior AppSec members of the community with juniors or people who are hoping to get into Application Security; attending all sorts of technology meetups (but especially female-centric ones) to talk about OWASP and personally invite them to attend; bringing OWASP products, concepts and resources to the Canadian Government (and is currently attempting to sway policy to be more application security focused as we speak); as well as performing over 40 public speaking engagements that describe OWASP as “Your new BFF” as part of the application security lesson she has taught. She has also begun speaking at conferences semi-regularly, singing OWASP’s praises as part of every presentation. She also forms female groups to attend events together, to make them more accessible, such as her all-female team for the Ottawa iHack CTP and “Learn by Breaking things” event in June 2017 and her all female CTF team for OWASP Ottawa’s first CTF in 2015. Her claim of being an “application security evangelist” certainly seems fitting.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Jeremy Long&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Jeremy is a dedicated security engineer who contributes to the community as a developer, mentor, contributor and leader. He's one of the smartest people I know - and one of the few who has patience with &amp;quot;the rest of us&amp;quot;. He is generous with his time and knowledge, helping not only to contribute apps and resources, but to build up the community itself.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[[User:Makash|Akash Mahajan]]&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Akash has been backbone of OWASP bangalore chapter he has done lot of work for evangelizing OWASP. For more than 7 years now he has been working with the chapter and mentored lot of folks. No wonder he is called &amp;quot;the web app security guy&amp;quot;.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/Dhiraj_Mishra Dhiraj Mishra]&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Dhiraj Mishra - has been contributed and volunteered to, OWASP Mumbai Student chapter and Mumbai local chapter.&lt;br /&gt;
&lt;br /&gt;
He has endorse students to be part of multiple open community, however been an Sudent Chapter leader for OWASP he has discussed and shared multiple Information Security topics start from the scratch and spreading the idea's and awareness via chapter Meets, he has taken multiple session in NULL as well which runs with OWASP local chapter Mumbai, recently he invited Mozilla Club Mumbai to student chapter so that students can go to their area of interest, he always pushup/boost women in infosec. Apart from this he has taken various sessions in different colleges and have shared knowledge about Cyber Security.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Denise Murtagh-Dunne&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Denise has been a hugely active member of the Dublin chapter and has been involved in all chapter meeting throughout the year and is ever keen to role up her sleeves and get stuck into work that others shy away from. This includes everything from setting up the meeting tools, organising venues, working with sponsors, getting speakers and assisting speakers in the run up and during events. She's been a very positively influence on the community and chapter and has encouraged other people to get involved. She's constantly updating and posting content on our social media accounts and making sure our members get relevant and interesting content. While in full time employment, Denise gives up family time to contribute to the chapter and ensure OWASP Dublin remains a vibrant and relevant group that engages the developer and security community locally.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[[User:Owen_Pendlebury|Owen Pendlebury]]&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Owen Pendlebury has been a key local OWASP volunteer over the last number of years. From being on the local Dublin chapter board to leading the Dublin chapter he regularly hosted and spoke at numerous collaborative and insightful security meetups.&lt;br /&gt;
&lt;br /&gt;
He has also been involved in organising AppSec EU in Rome and more recently co-organised the Belfast conference which was the biggest ever EU conference. As part of organising the conference in Belfast he negotiated that all chapters within Ireland would benefit financially getting a percentage of the conference profits to allow the chapters to bring bigger, better and more collaborative meetings to the Irish OWASP community and grow the communities across the country. &lt;br /&gt;
&lt;br /&gt;
I don’t know where he has found the time but has also been part of the Women in AppSec committee mentoring a number of individuals throughout the year. He took part in the Women in AppSec events in Belfast giving some insightful opinions into how improve attendees career. Owen is an asset that helps to improve Ireland's security community’s capabilities with a real can-do attitude.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Mick Ryan&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Mick always assists with chapter meetings and works to ensure we give the community good quality sessions. Mick assists will all areas including reaching out to potential speakers, getting info and bios from them, arranging dates and venues, posting on social media and the logistics of the meetings and ensuring speakers have the right cables, meetings run to time, that speakers are happy with everything, taking photos to promote the chapter on social media, encouraging people to speak, printing the chapter and getting people to events! Thanks Mick for your contribution in 2017!&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/Sriram Sriram]&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;[https://www.owasp.org/index.php/Sriram Sriram] has been conducting awareness program to the college students. Sriram has created awareness among 12000 Students without the support of anyone. Sriram has been tremendously supporting the OWASP Chapter by giving trainings to various college student,  corporates and various chapters..&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Michelle Simpson&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&amp;quot;Michelle has done an amazing job with the Belfast chapter and works tirelessly to improve the OWASP community and advocate strong app sec practices. This is very evident from the people attending the chapter events, organisations participating and the very successful AppSecEU conference that was held in Belfast in 2017. Michelle put a huge amount of work and effort into planning and preparation for AppSecEU to ensure the conference was of a high calibre. This was a sustained commitment over the majority of 2017 on top of local chapter commitments. I'd like to nominate Michelle for all the hard work and effort she puts into the chapter. Thanks Michelle!&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Steve Springett&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Steve has been a tremendous supporter of the OWASP dependency-check project and leader on the related dependency-track platform. He is quick to respond to community question, answering with insightful and accurate responses assisting the community in their use of the dependency-check suite of tools.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/John_Vargas John Vargas]&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;During the last 9 years John, together with a very small group of volunteers, has been making efforts to keep the chapter of Lima, Peru. Performing activities such as monthly meetings, internal trainings and participating actively in the OWASP Latam Tour. For the chapters in Latin America to keep afloat these activities with few resources is something very complicated and deserves recognition.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Tara Williams&lt;br /&gt;
|'''''Best Community Supporter'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Tara cares about integrity, inclusion and transparency, she is passionate about making OWASP a better place for all members of the community. With her talents in communications, she is getting the word out about OWASP's benefits to community members and attracting new members to chapter meetings, especially identifying successful pathways to transition meetup members to full members.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Aatral Arasu&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
'''&amp;quot;'''A great leader always there to help responds to emails quickly loves his work works very hard every day very supportive never loses focus strong willed very technical and willing to do things himself to get the job done when asked for something he will get it to you ASAP constant learner open to suggestions and ideas on how to be better respectful honest caring and I am certain HRC will make it big very soon :)&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Sean Auriti&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&amp;quot;Sean mentors, is a speaker, leads projects, is an active chapter leader and chapter Treasurer, participating in meetup events and a great representative at global, regional and external events.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Tony Clarke&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&amp;quot;Tony has grown the chapter over the last year to a point where hundreds of people are attending meetings. The meetings are organised in advance now and have a theme. There were some really interesting people speaking at the chapter meetings including Simon Singh, James Lyne, Brian Honan and Jane Franklin. He has also engaged support from local companies with a lot more attending and sponsoring the chapter. There is a real buzz at chapter meetings and they're not just death by PowerPoint which they had been in the past.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[[User:cfrenz|Christopher Frenz]]&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&lt;br /&gt;
'''&amp;quot;'''Christopher Frenz should be nominated for the Best Mission Outreach WASPY for his work as the Project Lead for the OWASP Anti-Ransomware Guide Project and the OWASP Secure Medical Device Deployment Standard Project. In the wake of WannaCry, anti-ransomware guidance has become more pertinent than ever and the project is regularly updated to keep abreast of the latest ransomware adaptations. Chris regularly shares his anti-ransomware knowledge with the security and healthcare communities and is an advocate for organizations conducting mock ransomware incidents. Chris has shared his knowledge of ransomware protections and of pertinent OWASP resources in numerous venues including articles (&amp;lt;nowiki&amp;gt;https://iapp.org/news/a/why-the-wannacry-outbreak-should-be-a-wake-up-call/&amp;lt;/nowiki&amp;gt;) and conference presentations at both the local and international level (&amp;lt;nowiki&amp;gt;https://iapp.org/conference/iapp-canada-privacy-symposium/sessions/?id=a191a000000zrqPAAQ&amp;lt;/nowiki&amp;gt;). A Spanish version of the guidance is also available. In addition, he has worked to call attention to the need for healthcare facilities to improve the security of their medical device implementations and is responsible for authoring version 1 of the OWASP Secure Medical Device Deployment Standard. The project has really worked to raise awareness of these issues and has been covered by CSO magazine (&amp;lt;nowiki&amp;gt;http://www.csoonline.com/article/3188230/security/how-to-securely-deploy-medical-devices.html&amp;lt;/nowiki&amp;gt;) and other news sources. Chris has given interviews on medical device security for the Cloud Security Alliance and others and will be speaking on medical device security at the Defcon BioHacking Village. Chris is always willing to share his knowledge with all who ask and is an active member of the NYC and Brooklyn OWASP chapters.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[[User:Fuentes.joaquin|Joaquin Fuentes]]&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&amp;quot;For all he has done to build up the Phoenix OWASP community. Prior to Joaquin taking point the community in Phoenix was dead. Meetings weren't happening on a regular basis. The prior leaders had done a great job but I think they had burnt out. Joaquin started the community back up and got corporate support from his employer to facilitate not only regular meetings but great meetings with great content. He also implemented MeetUp. I'm not a consistent attendee because of my work/life schedule but I always know when the meetings are happening and what the subject matter will be because of Joaquin utilizing MeetUp.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''2nd Citation:''' &amp;quot;Joaquin has been leading the OWASP Phoenix chapter and due to his initiative, has placed Phoenix on the map as a hub for application security. I would like to nominate him because he is always bringing in new and interesting speakers that provide great content. The most recent OWASP chapter meeting had over 60 attendees!&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''3rd Citation''': &amp;quot;Joaquin Fuentes has had a big impact in raising attendance at the Phoenix meetings to more than 100 people monthly. The quality has gotten significantly better under his leadership. He has organized many speakers, including recruiting speakers from out of the area that have significantly developed the knowledge base of the community. Joaquin is a pen testing manager at Early Warning and he shares his professional knowledge to help us all become better in the practice of information security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''4th Citation''': &amp;quot;My job takes me to many different OWASP Chapters, along with ISSA, CSA, ISACA, etc.&lt;br /&gt;
The Phoenix OWASP Chapter was DEAD before Joaquin volunteered to lead the Chapter a few years ago.&lt;br /&gt;
It is now consistently one of the BEST ITSec community gatherings, and I go out of my way to be in Phoenix for their meetings.&lt;br /&gt;
To put it a different way, at my first Phoenix OWASP meeting there were less than 12 attendees, including myself and the speaker. Last week it was standing room only (75+) *and* there would have been more if Interstate 17 hadn't been closed in both directions at the start of rush-hour.&lt;br /&gt;
Part of the reason Joaquin deserves this award is that he is EXTREMELY knowledgeable about AppSec and many other aspects of data security and he is ALWAYS friendly and willing to share. His day-job is no picnic, but he finds the time to put together great meetings and do it in a way that everybody has a good time.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/User:Tanyajanca Tanya Janca]&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&amp;quot;Tanya has been instrumental in outreach in the Ottawa Ontario Canada region building membership and participation in the local OWASP chapter, as well as building bridges with other local organizations (Python user group, Ruby Rails user group, WIA, etc.). Tanya has also been a driver in getting a mentoring program setup via the Ottawa chapter. She has also encouraged participation in local CTF events, presented at local conferences (BSides, etc). Tanya's enthusiasm, support, and interaction is often contagious (in a good way :) ). Lastly, Tanya is a strong advocate or evangelist for OWASP projects, promoting such as appropriate per audience/presentation (including, but not limited to: ZAP, Top 10, SKF).&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''2nd Citation:''' &amp;quot;Tanya Janca is an excellent ambassador for OWASP. Since her entry into the lead team of the OWASP Ottawa chapter, she has doubled the size of the chapter and developed the chapter into a meeting place for dozens of women interested in Application Security.&lt;br /&gt;
Tanya Janca is an energetic speaker who held a fantastic presentation at AppSecEU in Belfast. &amp;lt;nowiki&amp;gt;https://www.youtube.com/watch?v=mPTmuaC2lOI&amp;lt;/nowiki&amp;gt; She was subsequently invited to the Swiss Cyberstorm Conference where her addition to the rooster was explained in an admiring blogpost &amp;lt;nowiki&amp;gt;https://swisscyberstorm.com/2017/05/23/Introducing_Tany_Janca.html&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
Tanya Janca has the ability to talk security to techies and management alike. She is pushing for the adoption of OWASP practices and project by the government of Canada her employer. Having been nominated for the Government of Canada’s CIO Award for “Excellent in Security” in 2016 she refused to move into the private sector, but continues to support the security community inside the public sector, where her excellent know-how is very important.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''3rd Citation:''' &amp;quot;Tanya Janca has been performing “outreach” and “recruitment of women” as her main chapter leader responsibilities for the Ottawa chapter since 2015. The chapter has not only grown by over 500% in that time, but female membership has grown from 2 female members to over 70 (the chapter has grown for many reasons, some of which are her promotional efforts). Activities include starting a mentoring program that matches senior AppSec members of the community with juniors or people who are hoping to get into Application Security; attending all sorts of technology meetups (but especially female-centric ones) to talk about OWASP and personally invite them to attend; bringing OWASP products, concepts and resources to the Canadian Government (and is currently attempting to sway policy to be more application security focused as we speak); as well as performing over 40 public speaking engagements that describe OWASP as “Your new BFF” as part of the application security lesson she has taught. She has also begun speaking at conferences semi-regularly, singing OWASP’s praises as part of every presentation. She also forms female groups to attend events together, to make them more accessible, such as her all-female team for the Ottawa iHack CTP and “Learn by Breaking things” event in June 2017 and her all female CTF team for OWASP Ottawa’s first CTF in 2015. Her claim of being an “application security evangelist” certainly seems fitting.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Kitisak Jirawannakool&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Web security is notoriously bad in Thailand, so an actives security community is sorely needed. Kitisak is a central figure in that community. He has worked on establishing the OWASP Bangkok chapter for the past six years, organizing meetups, community outreach and engaging with security experts internationally. His work has played a pivotal role in creating IT security awareness in the fast-growing South-East-Asian country.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|James Manico&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&amp;quot;Jim's influence on OWASP materials (and therefore on application security) is amazing - he's cited on nearly every cheat sheet on OWASP Top 10 document. His name is synonymous with application security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''2nd Citation: &amp;quot;'''While Jim may not be the &amp;quot;unsung hero&amp;quot; - he is the first and foremost cheerleader/champion of OWASP. His efforts and contributions are innumerable. As anyone who knows Jim - he is not a reserved individual when touting the resources available via OWASP. He has likely done more then anyone else working with OWASP to bring together, motivate, and get individuals to contribute to OWASP. From the immensely popular checklists to motivating individuals to contribute. OWASP would not be nearly as successful as it has been without Jim.&amp;quot; &lt;br /&gt;
|-&lt;br /&gt;
|Mateo Martinez&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&amp;quot;Mateo is one of the leaders in Latin America more recognized, during the last years his efforts to join the chapters chapter along with other leaders of Latam made that the community grew and that today the Latam Tour 2017 has more than 15 participating countries. He also managed to spread the spirit of owasp and help establish new chapters in the region.&lt;br /&gt;
The effort to maintain more communication between OWASP GLobal and local communities is reflected in each activity that encourages other leaders to ensure that they strive every day to spread Owasp projects and to grow the community.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Mark Miller&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The OWASP Podcast is a effort that is in line with the mission of OWASP raising visability for software security. This is a VERY powerful voice in the community globally and Mark Miller should be applauded for his efforts on this&lt;br /&gt;
&amp;lt;nowiki&amp;gt;https://www.owasp.org/index.php/OWASP_Podcast&amp;lt;/nowiki&amp;gt;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/Dhiraj_Mishra Dhiraj Mishra]&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Dhiraj was nominated for WASPY 2016, his contribution to the community is from past one 'n half year in various areas, start from the projects, local volunteering and what not, he was also listed in OWASP Hall Of Fame.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[[User:Owen_Pendlebury|Owen Pendlebury]]&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&amp;quot;Owen is an active participator in OWASP meetings and has been a great inspiration to me.&lt;br /&gt;
He has shown himself to be a great leader and OWASP advocate.&lt;br /&gt;
Owen has recommended other AppSec communities in which I have become involved in since moving to Dublin. He is an evangelist for women in technology and I have witnessed this first hand.&lt;br /&gt;
I don't hesitate to recommend Owen for this award.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''2nd Citation:''' &amp;quot;Owen has introduced me to the OWASP Community in Ireland and EU. Help me to get involve with Women in AppSec and participate in the AppSec EU event in Belfast. He is a great leader, who enjoys talking about OWASP and the great community behind it.&lt;br /&gt;
I've moved to Ireland a couple of months ago, and getting to know Owen and the OWASP community has completely changed my life, both professionally and personally. &lt;br /&gt;
So, yes, I would like to nominate Owen Pendlebury because he the proof that Women in AppSec is not just a women matter. :)&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/Sriram Sriram Shyam]&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&amp;quot;Sriram has been conducting awareness program to the college students. Sriram has created awareness among 12000 Students without the support of anyone.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[[User:Nwhysel|Noreen Whysel]]&lt;br /&gt;
|'''''Best Mission Outreach'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Noreen is helping each day to improve OWASP members' experiences bringing her expertise and knowledge as a mentor and projects as a Chapter Leader, one member at a time. She understands what members want, how to improve member benefits and is applying that knowledge to improving local and global member experiences from the ground up. Her efforts are multiplied by her sharing of knowledge and grassroots approach creating a membership groundswell.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Aatral Arasu&lt;br /&gt;
|'''''Best Innovator''''' &lt;br /&gt;
&amp;quot;A great leader always there to help responds to emails quickly loves his work works very hard every day very supportive never loses focus strong willed very technical and willing to do things himself to get the job done when asked for something he will get it to you ASAP constant learner open to suggestions and ideas on how to be better respectful honest caring and I am certain HRC will make it big very soon :)&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Sean Auriti&lt;br /&gt;
|'''''Best Innovator''''' &lt;br /&gt;
&amp;quot;Sean leads the BLT Project and is a Team Leader for the Learning Gateway project. He has helped improve the quality of web experiences, including OWASP.org .&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Glenn &amp;amp; Riccardo ten Cate&lt;br /&gt;
|'''''Best Innovator'''''&lt;br /&gt;
&amp;quot;I am hereby nominating the brothers Glenn &amp;amp; Riccardo ten Cate from the Netherlands for the WASPY award in this category. They are known for their work on the open-source project SKF (Security Knowledge Framework). These are two guys who are dedicated to spreading security knowledge trough the means OWASP has to offer. You might have encountered them talking at seminars, promoting their project and OWASP, or different companies where they teach development teams how to integrate the OWASP core principles in their workflow using their project. Not only professional development teams but also students of security can only be amazed at the sheer knowledge they gathered and contribute to the global OWASP community trough open source. The sheer effort they put in this project teaches, guides, structures and shows by example how to test and write secure applications by design. There is no other software out there that does this. And that is why they deserve this nomination for best innovator 2017.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Mark Deenihan&lt;br /&gt;
|'''''Best Innovator''''' &lt;br /&gt;
&amp;quot;Mark for his constant devotion and work on the OWASP security shepherd project and continuing to develop it and teach people globally about app sec.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Seba Deleersnyder&lt;br /&gt;
|'''''Best Innovator''''' &lt;br /&gt;
&amp;quot;One of the main projects to date is SAMM. Seba with the support of project colliders has made this a flagship project of OWASP. The level of maturity and the number of improvements obtained indicates that this project is one of the most mature and a great projection to the future.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[[User:cfrenz|Christopher Frenz]]&lt;br /&gt;
|'''''Best Innovator''''' &lt;br /&gt;
&amp;quot;Chris' projects are opening doors for OWASP in the standards development and getting the word out about important IoT with his Medical Device Deployment Standard: &amp;lt;nowiki&amp;gt;https://www.owasp.org/index.php/OWASP_Secure_Medical_Device_Deployment_Standard&amp;lt;/nowiki&amp;gt; which already has a Turkish translation and attracted attention from the Turkish public health department. He has delivered presentations at meetups, and presenting to the IDESG, www.idesg.org in July. He has a &amp;quot;soup label&amp;quot; tool that gives simple guidance for the implementation of the OSMDDS. This is not Chris' first project but it is surely one of the best OWASP innovations of the year.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[[User:Fuentes.joaquin|Joaquin Fuentes]]&lt;br /&gt;
|'''''Best Innovator''''' &lt;br /&gt;
&amp;quot;Joaquin has been leading the OWASP Phoenix chapter and due to his initiative, has placed Phoenix on the map as a hub for application security. I would like to nominate him because he is always bringing in new and interesting speakers that provide great content. The most recent OWASP chapter meeting had over 60 attendees!&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''2nd Citation:''' &amp;quot;Joaquin Fuentes has had a big impact in raising attendance at the Phoenix meetings to more than 100 people monthly. The quality has gotten significantly better under his leadership. He has organized many speakers, including recruiting speakers from out of the area that have significantly developed the knowledge base of the community. Joaquin is a pen testing manager at Early Warning and he shares his professional knowledge to help us all become better in the practice of information security.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Evin Hernandez&lt;br /&gt;
|'''''Best Innovator''''' &lt;br /&gt;
&amp;quot;Evins focus on the core of the information security platform with Virtual Village has provided the global community with a place to experiment and leverage for testing... &amp;lt;nowiki&amp;gt;https://www.owasp.org/index.php/OWASP_Virtual_Village_Project&amp;lt;/nowiki&amp;gt;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Jeremy Long&lt;br /&gt;
|'''''Best Innovator''''' &lt;br /&gt;
&amp;quot;Considering how often projects have a great start and plateau, we should recognize the ongoing effort and dedication given to one of the Flagship projects in our community.&lt;br /&gt;
Jeremy Long has continued to not only maintain the Dependency Check project but develop and improve it each year.&lt;br /&gt;
This year he added Improvements in the core dependency-check platform in terms of code quality, achieved 100% for the CII Best Practices for dependency-check, continued to develop the ODC community with several contributors submitting PRs, and over the last several months he's been working on platform maturity and will be releasing 2.0.0 in the first half of July 2017.&lt;br /&gt;
After 2.0 is released he has planned work on Python support and expanding the tool by integrating additional data-sources such as Artifactory, Redhat Victim's, OSS-Index, etc.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''2nd Citation:''' &amp;quot;Jeremy has been an avid contributor/leader for the OWASP dependency-check project. Under his leadership the project has garnered substantial community support in terms of pull requests, improved code quality via Sonarcloud, Coverity, Codacy, and CII Best Practices. While the last six months have been primarily around code quality and bug fixes; these improvements are setting the dependency-check project up for major enhancements over the coming months!&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Daniel Miessler&lt;br /&gt;
|'''''Best Innovator'''''&lt;br /&gt;
&amp;quot;Daniel seems to be everywhere at once - despite have a full-time job, he is leading or co-leading several OWASP projects, has created ideas for groups out of thin air, and has performed work in much needed areas.&lt;br /&gt;
This year, Daniel has lead or co-lead the Internet of Things security project, completed an IoT: Medical Devices attack surface overview, and created the Game Security project.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/Dhiraj_Mishra Dhiraj Mishra]&lt;br /&gt;
|'''''Best Innovator'''''&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Dhiraj is one of the top contributor in OWASP Cheat Sheet Project, which have security guidance in an easy read format, his contribution for SQL Injection WAF Bypass and XSS Evasion - OWASP, was mostly recommended and used by Cyber Security professional, dhiraj has contributed to Benchmark project by contributing SQLi/XSS fuzz vectors as initial contribution towards adding support for WAF/RASP scoring and many such projects.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Bernhard Mueller&lt;br /&gt;
|'''''Best Innovator'''''&lt;br /&gt;
&amp;quot;During the last 18 months Bernhard has been spearheading the OWASP Mobile Testing Guide Project. He has invested several man-months of writing, editing, reviewing, rallying authors, and pushing the project into new directions. This also resulted in the novel agile book writing process and book production pipeline which enables OWASP to produce a professional tech book. The project has produced a security standard and early-release ebook, and is on track become one of OWASP's main flagship projects.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|Steve Springett&lt;br /&gt;
|'''''Best Innovator'''''&lt;br /&gt;
&amp;quot;Steve's work on dependency-track is fantastic - he's moved forward to address the next round of issues, with an innovative solution all companies can leverage.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|thc202&lt;br /&gt;
|'''''Best Innovator'''''&lt;br /&gt;
&amp;quot;Simon Bennets &amp;quot;wingman&amp;quot; in the ZAP project, by now even the top committer in the project! (&amp;lt;nowiki&amp;gt;https://github.com/zaproxy/zaproxy/graphs/contributors&amp;lt;/nowiki&amp;gt;) So &amp;quot;unsung of&amp;quot; that I do not even know his real name!&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Results==&lt;br /&gt;
Coming July 25, 2017&lt;br /&gt;
&lt;br /&gt;
==Sponsorship Opportunities==&lt;br /&gt;
The support from our sponsors, is what makes these awards truly successful!&lt;br /&gt;
&lt;br /&gt;
Sponsorships coming soon!&lt;br /&gt;
&lt;br /&gt;
==Communication==&lt;br /&gt;
# June 7, 2017 Email to the Leaders &amp;amp; Community list. Posted to the OWASP [https://owasp.blogspot.com/2017/06/nominations-are-now-being-accepted-for.html Blog]&lt;br /&gt;
# June 30, 2017 Email to the Leaders &amp;amp; Community list.&lt;br /&gt;
# July 5, 2017 Email to the Nominees&lt;br /&gt;
# July 5, 2017 Email to the Leaders &amp;amp; Community list, and Blog post announcing the nominees have been announced.&lt;br /&gt;
&lt;br /&gt;
=='''Past WASPY Awards'''==&lt;br /&gt;
[https://www.owasp.org/index.php/WASPY_Awards_2016 2016]&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/WASPY_Awards_2015 2015] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/WASPY_Awards_2014 2014] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/WASPY_Awards_2013 2013] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/WASPY_Awards_2012 2012] &amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Tanyajanca&amp;diff=231507</id>
		<title>User:Tanyajanca</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Tanyajanca&amp;diff=231507"/>
				<updated>2017-07-10T15:23:39Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Tanya Janca and the Canadian Parliament.jpg|thumb]]&lt;br /&gt;
Tanya Janca is an application security evangelist, web application penetration tester, trainer, public speaker, ethical hacker, an effective altruist and has been developing software since the late 90’s.  She is the current Chair of OWASP WIA (Women in AppSec), Ottawa Chapter Leader and has helped to grow her chapter by doing public speaking at OWASP and other places, creating new types of OWASP events for their chapter (workshops, debates, capture the flags trivia nights), starting a mentoring program, and has been heavily promoting OWASP and the use of it's tools in the Canadian Government for years.  She's also working on a new OWASP Project: DevSlop.&lt;br /&gt;
&lt;br /&gt;
During her 20 years of working in IT Tanya has worn many hats and done many things, including; Web App PenTesting, Technical Training, Custom Apps/Software Development, Network VA, Ethical Hacking, COTS, Incident Response, Enterprise Architect, Project and People Management, and even Tech Support.  She is currently helping the Government of Canada secure their web applications.  &lt;br /&gt;
&lt;br /&gt;
Tanya will talk to anyone, any time, about application security and OWASP.  Find out more of what Tanya's up to here: @SheHacksPurple&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Tanya_Janca_and_the_Canadian_Parliament.jpg&amp;diff=231506</id>
		<title>File:Tanya Janca and the Canadian Parliament.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Tanya_Janca_and_the_Canadian_Parliament.jpg&amp;diff=231506"/>
				<updated>2017-07-10T15:23:26Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Tanya Janca and the Canadian Parliament&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Tanyajanca&amp;diff=231504</id>
		<title>User:Tanyajanca</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Tanyajanca&amp;diff=231504"/>
				<updated>2017-07-10T15:18:32Z</updated>
		
		<summary type="html">&lt;p&gt;Tanyajanca: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Tanya Janca is an application security evangelist, web application penetration tester, trainer, public speaker, ethical hacker, an effective altruist and has been developing software since the late 90’s.  She is the current Chair of OWASP WIA (Women in AppSec), Ottawa Chapter Leader and has helped to grow her chapter by doing public speaking at OWASP and other places, creating new types of OWASP events for their chapter (workshops, debates, capture the flags trivia nights), starting a mentoring program, and has been heavily promoting OWASP and the use of it's tools in the Canadian Government for years.  She's also working on a new OWASP Project: DevSlop.&lt;br /&gt;
&lt;br /&gt;
During her 20 years of working in IT Tanya has worn many hats and done many things, including; Web App PenTesting, Technical Training, Custom Apps/Software Development, Network VA, Ethical Hacking, COTS, Incident Response, Enterprise Architect, Project and People Management, and even Tech Support.  She is currently helping the Government of Canada secure their web applications.  &lt;br /&gt;
&lt;br /&gt;
Tanya will talk to anyone, any time, about application security and OWASP.  Find out more of what Tanya's up to here: @SheHacksPurple&lt;/div&gt;</summary>
		<author><name>Tanyajanca</name></author>	</entry>

	</feed>