<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Thesp0nge</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Thesp0nge"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Thesp0nge"/>
		<updated>2026-04-30T08:35:34Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Orizon_Project&amp;diff=229568</id>
		<title>Category:OWASP Orizon Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Orizon_Project&amp;diff=229568"/>
				<updated>2017-05-11T15:15:02Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;right&amp;quot; | [[Image:OWASP Inactive Banner.jpg|800px| link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Inactive_Projects]] &lt;br /&gt;
| align=&amp;quot;right&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==OWASP Orizon Project==&lt;br /&gt;
&lt;br /&gt;
OWASP Orizon is a source code security scanner designed to spot vulnerabilities in J2EE web applications, Android code and generally speaking in Java written source code.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is a source code static analyzer tool designed to spot security issues in Java applications.&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon mission is to provide people an opensource tool, helping them in reviewing:&lt;br /&gt;
&lt;br /&gt;
* single Java classes&lt;br /&gt;
* Java standalone tools packed in JAR files&lt;br /&gt;
* web applications packed in EAR / WAR files&lt;br /&gt;
* Android APK applications&lt;br /&gt;
&lt;br /&gt;
It was a dark and stormy night in Milan, Italy. It was 2006 and I felt the need of something helping me in reviewing other people java source code. So Owasp Orizon born and grew up as security tool trying to parse Java source code, building an Abstract Syntax Tree and spot for unsafe calls in the code.&lt;br /&gt;
&lt;br /&gt;
In the very beginning Owasp Orizon was a sort of enhanced grep tool. In 2008, I started supporting PHP programming language but the initial boost disappeared. After being in love with other programming languages and technolgies, eight years later, in 2017 I kickstarted the project again from scratch.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Orizon is an opensource tool. It is licensed under the [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License].&lt;br /&gt;
&lt;br /&gt;
== Quick Start ==&lt;br /&gt;
&lt;br /&gt;
See project [https://github.com/thesp0nge/owasp-orizon GitHub home page] &lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&lt;br /&gt;
[https://owasporizon.wordpress.com Blog]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thesp0nge/owasp-orizon  Code] | [https://github.com/thesp0nge/owasp-orizon/releases Binaries]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thesp0nge/owasp-orizon/issues Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Paolo Perego&amp;lt;br/&amp;gt;&lt;br /&gt;
[mailto:thesp0nge@owasp.org email] [https://twitter.com/thesp0nge/ twitter] [https://codiceinsicuro.it blog ]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [Spring 2017] - [http://owaspsummit.org/Working-Sessions/Project-Summit/Owasp-Orizon-Reboot.html Owasp Orizon kickstart session]&lt;br /&gt;
* [13 September 2016] - Paolo Perego take back project leadership, kickstarting Owasp Orizon again&lt;br /&gt;
* [February, 2014] - Greg Disney-Leugers adopted the OWASP Orizon project.&lt;br /&gt;
* [November 2009] - we started moving from current release to the next major bump (v2.0) that will happen next June 2010 during Owasp AppSEC conference in Stockholm.&lt;br /&gt;
&lt;br /&gt;
== Roadmap and Getting Involved==&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon kickstart is scheduled during the upcoming [http://owaspsummit.org/Working-Sessions/Project-Summit/Owasp-Orizon-Reboot.html Owasp Summit 2017]&lt;br /&gt;
&lt;br /&gt;
Some intended milestones to be putted in roadmap are:&lt;br /&gt;
&lt;br /&gt;
* Spring 2017 - Defining the team and overall goals&lt;br /&gt;
* Autumn 2017 - First alpha release&lt;br /&gt;
* Winter 2017 - Second alpha release&lt;br /&gt;
* January 2018 - First beta&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Project Information:template Orizon Project}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Orizon_Project&amp;diff=221288</id>
		<title>Category:OWASP Orizon Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Orizon_Project&amp;diff=221288"/>
				<updated>2016-09-13T09:33:29Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Licensing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Orizon Project==&lt;br /&gt;
&lt;br /&gt;
OWASP Orizon is a source code security scanner designed to spot vulnerabilities in J2EE web applications, Android code and generally speaking in Java written source code.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is a code review tool intended to be used from security specialist to perform white box assessment. Orizon exposes also a set of APIs that can be used within a security tool to provide code review services.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Orizon is an opensource tool. It is licensed under the [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Start ==&lt;br /&gt;
&lt;br /&gt;
See project [https://github.com/thesp0nge/owasp-orizon GitHub home page] &lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&lt;br /&gt;
[https://owasporizon.wordpress.com Blog]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thesp0nge/owasp-orizon  Code] | [https://github.com/thesp0nge/owasp-orizon/releases Binaries]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thesp0nge/owasp-orizon/issues Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Paolo Perego&amp;lt;br/&amp;gt;&lt;br /&gt;
[mailto:thesp0nge@owasp.org email] [https://twitter.com/thesp0nge/ twitter] [https://codiceinsicuro.it blog ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [13 September 2016] - Paolo Perego take back project leadership, kickstarting Owasp Orizon again&lt;br /&gt;
* [February, 2014] - Greg Disney-Leugers adopted the OWASP Orizon project.&lt;br /&gt;
* [November 2009] - we started moving from current release to the next major bump (v2.0) that will happen next June 2010 during Owasp AppSEC conference in Stockholm.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
Available online is an  [http://downloads.sourceforge.net/orizon/The_Owasp_Orizon_Project_Internals_v2.2.ppt?use_mirror=osdn Orizon presentation] given at  [http://www.owasp.org/index.php/OWASP_AppSec_Europe_2008_-_Belgium OWASP AppSec EU 2008] in Ghent, May 2008.&lt;br /&gt;
&lt;br /&gt;
 '''Owasp Orizon Internals @ Owasp AppSec NY 2008, New York 22-25th September 2008'''&lt;br /&gt;
[http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference Orizon@AppSec NY 2008]&lt;br /&gt;
&lt;br /&gt;
 '''Owasp Orizon Internals @ Owasp AppSec EU 2008, Ghent 21-22nd May 2008'''&lt;br /&gt;
[http://www.owasp.org/index.php/AppSecEU08_The_OWASP_ORIZON_project Orizon@AppSec EU 2008]&lt;br /&gt;
&lt;br /&gt;
 '''Owasp Orizon Internals @ Owasp Day Italy 2008, Rome 31st March 2008'''&lt;br /&gt;
[http://www.owasp.org/images/5/54/Owaspday2Perego.ppt Orizon@Owasp Day in Italy]&lt;br /&gt;
&lt;br /&gt;
 '''OWASP Orizon Project @ SMAU eAcademy, Milan 4-7th October 2006'''&lt;br /&gt;
I will talk to [http://www.webb.it SMAU eAcademy2006] next Saturday 7th October 2006 about code review and safe coding. [http://webb.it/event/eventview/5772/1/0,0/code_review_e_principi_di_programmazione_sicura Here] you can find more information (for now, only in Italian). The last part of the speech will be about introducing the Orizon project and giving a development roadmap.&lt;br /&gt;
&lt;br /&gt;
A slideshare space is available to for the presentations used in Owasp [http://www.slideshare.net/thesp0nge | conferences]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Orizon is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Paolo Perego - former project leader&lt;br /&gt;
* Steven Evans&lt;br /&gt;
* Andres Riancho&lt;br /&gt;
* Dinis Cruz&lt;br /&gt;
* Mike Duncan&lt;br /&gt;
* prashant k v&lt;br /&gt;
* Alessio Marziali&lt;br /&gt;
* Jason Li&lt;br /&gt;
* Nishi Kumar&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008 OWASP Summer of Code 2008]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of Orizon, the priorities are:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
Orizon wants you!&lt;br /&gt;
&lt;br /&gt;
The model we follow is the OpenBSD one. Anyone will be free about sending opinions, criticism and patches. If an user will provide a good number of patches showing us he (or she) really wants to collaborate to the project, than he (or she) will be added to Owasp orizon core team.&lt;br /&gt;
&lt;br /&gt;
If you are a skilled Java developer why don't you consider writing a bunch of code for Orizon? Or, consider joining the project for documentation, advertising, blog maintenance, etc.&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Orizon Project useful. Please contribute to the project by volunteering for one of the tasks, or by sending your comments, questions, and suggestions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Project Information:template Orizon Project}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Orizon_Project&amp;diff=221285</id>
		<title>Category:OWASP Orizon Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Orizon_Project&amp;diff=221285"/>
				<updated>2016-09-13T08:22:33Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Project Resources */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Orizon Project==&lt;br /&gt;
&lt;br /&gt;
OWASP Orizon is a source code security scanner designed to spot vulnerabilities in J2EE web applications, Android code and generally speaking in Java written source code.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is a code review tool intended to be used from security specialist to perform white box assessment. Orizon exposes also a set of APIs that can be used within a security tool to provide code review services.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP XXX is free to use. It is licensed under the GNU General Public License version 3.0 (GPLv3).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Start ==&lt;br /&gt;
&lt;br /&gt;
See project [https://github.com/thesp0nge/owasp-orizon GitHub home page] &lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&lt;br /&gt;
[https://owasporizon.wordpress.com Blog]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thesp0nge/owasp-orizon  Code] | [https://github.com/thesp0nge/owasp-orizon/releases Binaries]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thesp0nge/owasp-orizon/issues Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Paolo Perego&amp;lt;br/&amp;gt;&lt;br /&gt;
[mailto:thesp0nge@owasp.org email] [https://twitter.com/thesp0nge/ twitter] [https://codiceinsicuro.it blog ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [13 September 2016] - Paolo Perego take back project leadership, kickstarting Owasp Orizon again&lt;br /&gt;
* [February, 2014] - Greg Disney-Leugers adopted the OWASP Orizon project.&lt;br /&gt;
* [November 2009] - we started moving from current release to the next major bump (v2.0) that will happen next June 2010 during Owasp AppSEC conference in Stockholm.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
Available online is an  [http://downloads.sourceforge.net/orizon/The_Owasp_Orizon_Project_Internals_v2.2.ppt?use_mirror=osdn Orizon presentation] given at  [http://www.owasp.org/index.php/OWASP_AppSec_Europe_2008_-_Belgium OWASP AppSec EU 2008] in Ghent, May 2008.&lt;br /&gt;
&lt;br /&gt;
 '''Owasp Orizon Internals @ Owasp AppSec NY 2008, New York 22-25th September 2008'''&lt;br /&gt;
[http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference Orizon@AppSec NY 2008]&lt;br /&gt;
&lt;br /&gt;
 '''Owasp Orizon Internals @ Owasp AppSec EU 2008, Ghent 21-22nd May 2008'''&lt;br /&gt;
[http://www.owasp.org/index.php/AppSecEU08_The_OWASP_ORIZON_project Orizon@AppSec EU 2008]&lt;br /&gt;
&lt;br /&gt;
 '''Owasp Orizon Internals @ Owasp Day Italy 2008, Rome 31st March 2008'''&lt;br /&gt;
[http://www.owasp.org/images/5/54/Owaspday2Perego.ppt Orizon@Owasp Day in Italy]&lt;br /&gt;
&lt;br /&gt;
 '''OWASP Orizon Project @ SMAU eAcademy, Milan 4-7th October 2006'''&lt;br /&gt;
I will talk to [http://www.webb.it SMAU eAcademy2006] next Saturday 7th October 2006 about code review and safe coding. [http://webb.it/event/eventview/5772/1/0,0/code_review_e_principi_di_programmazione_sicura Here] you can find more information (for now, only in Italian). The last part of the speech will be about introducing the Orizon project and giving a development roadmap.&lt;br /&gt;
&lt;br /&gt;
A slideshare space is available to for the presentations used in Owasp [http://www.slideshare.net/thesp0nge | conferences]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Orizon is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Paolo Perego - former project leader&lt;br /&gt;
* Steven Evans&lt;br /&gt;
* Andres Riancho&lt;br /&gt;
* Dinis Cruz&lt;br /&gt;
* Mike Duncan&lt;br /&gt;
* prashant k v&lt;br /&gt;
* Alessio Marziali&lt;br /&gt;
* Jason Li&lt;br /&gt;
* Nishi Kumar&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008 OWASP Summer of Code 2008]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of Orizon, the priorities are:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
Orizon wants you!&lt;br /&gt;
&lt;br /&gt;
The model we follow is the OpenBSD one. Anyone will be free about sending opinions, criticism and patches. If an user will provide a good number of patches showing us he (or she) really wants to collaborate to the project, than he (or she) will be added to Owasp orizon core team.&lt;br /&gt;
&lt;br /&gt;
If you are a skilled Java developer why don't you consider writing a bunch of code for Orizon? Or, consider joining the project for documentation, advertising, blog maintenance, etc.&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Orizon Project useful. Please contribute to the project by volunteering for one of the tasks, or by sending your comments, questions, and suggestions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Project Information:template Orizon Project}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Orizon_Project&amp;diff=221284</id>
		<title>Category:OWASP Orizon Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Orizon_Project&amp;diff=221284"/>
				<updated>2016-09-13T08:21:49Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Orizon Project==&lt;br /&gt;
&lt;br /&gt;
OWASP Orizon is a source code security scanner designed to spot vulnerabilities in J2EE web applications, Android code and generally speaking in Java written source code.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is a code review tool intended to be used from security specialist to perform white box assessment. Orizon exposes also a set of APIs that can be used within a security tool to provide code review services.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP XXX is free to use. It is licensed under the GNU General Public License version 3.0 (GPLv3).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Start ==&lt;br /&gt;
&lt;br /&gt;
See project [https://github.com/thesp0nge/owasp-orizon GitHub home page] &lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&lt;br /&gt;
[https://owasporizon.wordpress.com Blog]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thesp0nge/owasp-orizon  Code] | [https://github.com/thesp0nge/owasp-orizon/releases Binaries&lt;br /&gt;
&lt;br /&gt;
[https://github.com/thesp0nge/owasp-orizon/issues Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Paolo Perego&amp;lt;br/&amp;gt;&lt;br /&gt;
[mailto:thesp0nge@owasp.org email] [https://twitter.com/thesp0nge/ twitter] [https://codiceinsicuro.it blog ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [13 September 2016] - Paolo Perego take back project leadership, kickstarting Owasp Orizon again&lt;br /&gt;
* [February, 2014] - Greg Disney-Leugers adopted the OWASP Orizon project.&lt;br /&gt;
* [November 2009] - we started moving from current release to the next major bump (v2.0) that will happen next June 2010 during Owasp AppSEC conference in Stockholm.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
Available online is an  [http://downloads.sourceforge.net/orizon/The_Owasp_Orizon_Project_Internals_v2.2.ppt?use_mirror=osdn Orizon presentation] given at  [http://www.owasp.org/index.php/OWASP_AppSec_Europe_2008_-_Belgium OWASP AppSec EU 2008] in Ghent, May 2008.&lt;br /&gt;
&lt;br /&gt;
 '''Owasp Orizon Internals @ Owasp AppSec NY 2008, New York 22-25th September 2008'''&lt;br /&gt;
[http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference Orizon@AppSec NY 2008]&lt;br /&gt;
&lt;br /&gt;
 '''Owasp Orizon Internals @ Owasp AppSec EU 2008, Ghent 21-22nd May 2008'''&lt;br /&gt;
[http://www.owasp.org/index.php/AppSecEU08_The_OWASP_ORIZON_project Orizon@AppSec EU 2008]&lt;br /&gt;
&lt;br /&gt;
 '''Owasp Orizon Internals @ Owasp Day Italy 2008, Rome 31st March 2008'''&lt;br /&gt;
[http://www.owasp.org/images/5/54/Owaspday2Perego.ppt Orizon@Owasp Day in Italy]&lt;br /&gt;
&lt;br /&gt;
 '''OWASP Orizon Project @ SMAU eAcademy, Milan 4-7th October 2006'''&lt;br /&gt;
I will talk to [http://www.webb.it SMAU eAcademy2006] next Saturday 7th October 2006 about code review and safe coding. [http://webb.it/event/eventview/5772/1/0,0/code_review_e_principi_di_programmazione_sicura Here] you can find more information (for now, only in Italian). The last part of the speech will be about introducing the Orizon project and giving a development roadmap.&lt;br /&gt;
&lt;br /&gt;
A slideshare space is available to for the presentations used in Owasp [http://www.slideshare.net/thesp0nge | conferences]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Orizon is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Paolo Perego - former project leader&lt;br /&gt;
* Steven Evans&lt;br /&gt;
* Andres Riancho&lt;br /&gt;
* Dinis Cruz&lt;br /&gt;
* Mike Duncan&lt;br /&gt;
* prashant k v&lt;br /&gt;
* Alessio Marziali&lt;br /&gt;
* Jason Li&lt;br /&gt;
* Nishi Kumar&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008 OWASP Summer of Code 2008]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of Orizon, the priorities are:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
Orizon wants you!&lt;br /&gt;
&lt;br /&gt;
The model we follow is the OpenBSD one. Anyone will be free about sending opinions, criticism and patches. If an user will provide a good number of patches showing us he (or she) really wants to collaborate to the project, than he (or she) will be added to Owasp orizon core team.&lt;br /&gt;
&lt;br /&gt;
If you are a skilled Java developer why don't you consider writing a bunch of code for Orizon? Or, consider joining the project for documentation, advertising, blog maintenance, etc.&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Orizon Project useful. Please contribute to the project by volunteering for one of the tasks, or by sending your comments, questions, and suggestions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Project Information:template Orizon Project}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188874</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188874"/>
				<updated>2015-02-02T11:12:59Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* 2015 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. Please note, this is not a page for an '''appsec conference''', this page is about an application security strategy for the Italian chapter in order to give a boost for activities and to be used year by year to measure how things went in our Country.&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
Goals for 2015&lt;br /&gt;
&lt;br /&gt;
* Date an opensource project&lt;br /&gt;
* Build a local meetup network&lt;br /&gt;
* Communication boost&lt;br /&gt;
* Fill the gap with developers&lt;br /&gt;
* Setup a new application security conference here in Italy&lt;br /&gt;
&lt;br /&gt;
=== Date an opensource project ===&lt;br /&gt;
&lt;br /&gt;
In order to build a culture of security, filling the gap with developers we want to adopt opensource projects, doing code review and penetration tests over it, providing developers security feedbacks to raise the bar for attackers.&lt;br /&gt;
&lt;br /&gt;
==== Stuff to be done ====&lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/_ikki Luca Carettoni @_ikki] proposes a formal engagement process to adopt an opensource project, making assessments and giving feedbacks. We are evaluating how to procede, creating a framework to #fillthegap.&lt;br /&gt;
We are also wondering about creating some whitepapers to help development team introducing appsec.&lt;br /&gt;
&lt;br /&gt;
Popular projects that are candidate to be adopted are:&lt;br /&gt;
* [http://symfony.com/ Symfony]&lt;br /&gt;
* [http://rubyonrails.org Ruby on rails]&lt;br /&gt;
* [http://angular.js Angular.js]&lt;br /&gt;
* more to come&lt;br /&gt;
&lt;br /&gt;
=== Build a local meetup network ===&lt;br /&gt;
&lt;br /&gt;
In Italy, application security specialists don't meet each other and, more important, they don't meet developers and stakeholders in informal meetups to spread the #appsec credo. There are some focused security events (Infosecurity, Security Summit) but they are organized by security guys for other security guys and there are more formal state-of-art event in the Italian panorama.&lt;br /&gt;
&lt;br /&gt;
We feel the need of creating informal meetups were appsec guys gather each other java people, php people, ruby people, .Net people, UX people, entrepreneurs in order to build strong security basements for people make the real web.&lt;br /&gt;
&lt;br /&gt;
We hope to start meetups up in Spring 2015 (around April 2015).&lt;br /&gt;
Meetup will be monthly based.&lt;br /&gt;
 &lt;br /&gt;
==== Local meetup leader ====&lt;br /&gt;
&lt;br /&gt;
Local meetup leader is a person in charge of plan, organise and keep #appsec hype high on his neighborhood/city. For big cities like Milano, Torino, Roma, Napoli, ... there will be of course more leaders that '''must''' collaborate each other.&lt;br /&gt;
&lt;br /&gt;
==== Stuff to be done ====&lt;br /&gt;
&lt;br /&gt;
We must create a whitepaper document describing some general rules about how to organize a local meetup. Where to organize, who to invite, how to document the event (photo, talks recording), how to do media coverage, how to advertise the event, where to put infos, slidedecks, ...&lt;br /&gt;
&lt;br /&gt;
=== Communication boost ===&lt;br /&gt;
&lt;br /&gt;
People who wants to use IRC to chat with Owasp Italy members can use irc server chat.freenode.net on channel #owasp-italy&lt;br /&gt;
&lt;br /&gt;
=== Fill the gap with developers ===&lt;br /&gt;
&lt;br /&gt;
There are some very interesting conferences here in Italy for developers. We have to spread the security culture, submitting a talk and trying to reach them.&lt;br /&gt;
&lt;br /&gt;
* [http://2015.phpday.it/ PHP Day, May 15th-16th, Verona]&lt;br /&gt;
* [http://2015.jsday.it/ Js Day, May 15th-16th, Verona]&lt;br /&gt;
* [http://rubyday.it Ruby Day, TBA, TBA]&lt;br /&gt;
&lt;br /&gt;
=== Setup a new application security conference here in Italy ===&lt;br /&gt;
&lt;br /&gt;
TBA&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188764</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188764"/>
				<updated>2015-01-30T11:05:01Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. Please note, this is not a page for an '''appsec conference''', this page is about an application security strategy for the Italian chapter in order to give a boost for activities and to be used year by year to measure how things went in our Country.&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
Goals for 2015&lt;br /&gt;
&lt;br /&gt;
* Date an opensource project&lt;br /&gt;
* Build a local meetup network&lt;br /&gt;
* Communication boost&lt;br /&gt;
&lt;br /&gt;
=== Date an opensource project ===&lt;br /&gt;
&lt;br /&gt;
In order to build a culture of security, filling the gap with developers we want to adopt opensource projects, doing code review and penetration tests over it, providing developers security feedbacks to raise the bar for attackers.&lt;br /&gt;
&lt;br /&gt;
==== Stuff to be done ====&lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/_ikki Luca Carettoni @_ikki] proposes a formal engagement process to adopt an opensource project, making assessments and giving feedbacks. We are evaluating how to procede, creating a framework to #fillthegap.&lt;br /&gt;
We are also wondering about creating some whitepapers to help development team introducing appsec.&lt;br /&gt;
&lt;br /&gt;
Popular projects that are candidate to be adopted are:&lt;br /&gt;
* [http://symfony.com/ Symfony]&lt;br /&gt;
* [http://rubyonrails.org Ruby on rails]&lt;br /&gt;
* [http://angular.js Angular.js]&lt;br /&gt;
* more to come&lt;br /&gt;
&lt;br /&gt;
=== Build a local meetup network ===&lt;br /&gt;
&lt;br /&gt;
In Italy, application security specialists don't meet each other and, more important, they don't meet developers and stakeholders in informal meetups to spread the #appsec credo. There are some focused security events (Infosecurity, Security Summit) but they are organized by security guys for other security guys and there are more formal state-of-art event in the Italian panorama.&lt;br /&gt;
&lt;br /&gt;
We feel the need of creating informal meetups were appsec guys gather each other java people, php people, ruby people, .Net people, UX people, entrepreneurs in order to build strong security basements for people make the real web.&lt;br /&gt;
&lt;br /&gt;
We hope to start meetups up in Spring 2015 (around April 2015).&lt;br /&gt;
Meetup will be monthly based.&lt;br /&gt;
 &lt;br /&gt;
==== Local meetup leader ====&lt;br /&gt;
&lt;br /&gt;
Local meetup leader is a person in charge of plan, organise and keep #appsec hype high on his neighborhood/city. For big cities like Milano, Torino, Roma, Napoli, ... there will be of course more leaders that '''must''' collaborate each other.&lt;br /&gt;
&lt;br /&gt;
==== Stuff to be done ====&lt;br /&gt;
&lt;br /&gt;
We must create a whitepaper document describing some general rules about how to organize a local meetup. Where to organize, who to invite, how to document the event (photo, talks recording), how to do media coverage, how to advertise the event, where to put infos, slidedecks, ...&lt;br /&gt;
&lt;br /&gt;
=== Communication boost ===&lt;br /&gt;
&lt;br /&gt;
People who wants to use IRC to chat with Owasp Italy members can use irc server chat.freenode.net on channel #owasp-italy&lt;br /&gt;
&lt;br /&gt;
=== Fill the gap with developers ===&lt;br /&gt;
&lt;br /&gt;
There are some very interesting conferences here in Italy for developers. We have to spread the security culture, submitting a talk and trying to reach them.&lt;br /&gt;
&lt;br /&gt;
* [http://2015.phpday.it/ PHP Day, May 15th-16th, Verona]&lt;br /&gt;
* [http://2015.jsday.it/ Js Day, May 15th-16th, Verona]&lt;br /&gt;
* [http://rubyday.it Ruby Day, TBA, TBA]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188672</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188672"/>
				<updated>2015-01-28T11:02:50Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Build a local meetup network */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. Please note, this is not a page for an '''appsec conference''', this page is about an application security strategy for the Italian chapter in order to give a boost for activities and to be used year by year to measure how things went in our Country.&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
Goals for 2015&lt;br /&gt;
&lt;br /&gt;
* Date an opensource project&lt;br /&gt;
* Build a local meetup network&lt;br /&gt;
* Communication boost&lt;br /&gt;
&lt;br /&gt;
=== Date an opensource project ===&lt;br /&gt;
&lt;br /&gt;
In order to build a culture of security, filling the gap with developers we want to adopt opensource projects, doing code review and penetration tests over it, providing developers security feedbacks to raise the bar for attackers.&lt;br /&gt;
&lt;br /&gt;
==== Stuff to be done ====&lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/_ikki Luca Carettoni @_ikki] proposes a formal engagement process to adopt an opensource project, making assessments and giving feedbacks. We are evaluating how to procede, creating a framework to #fillthegap.&lt;br /&gt;
We are also wondering about creating some whitepapers to help development team introducing appsec.&lt;br /&gt;
&lt;br /&gt;
Popular projects that are candidate to be adopted are:&lt;br /&gt;
* [http://symfony.com/ Symfony]&lt;br /&gt;
* [http://rubyonrails.org Ruby on rails]&lt;br /&gt;
* [http://angular.js Angular.js]&lt;br /&gt;
* more to come&lt;br /&gt;
&lt;br /&gt;
=== Build a local meetup network ===&lt;br /&gt;
&lt;br /&gt;
In Italy, application security specialists don't meet each other and, more important, they don't meet developers and stakeholders in informal meetups to spread the #appsec credo. There are some focused security events (Infosecurity, Security Summit) but they are organized by security guys for other security guys and there are more formal state-of-art event in the Italian panorama.&lt;br /&gt;
&lt;br /&gt;
We feel the need of creating informal meetups were appsec guys gather each other java people, php people, ruby people, .Net people, UX people, entrepreneurs in order to build strong security basements for people make the real web.&lt;br /&gt;
&lt;br /&gt;
We hope to start meetups up in Spring 2015 (around April 2015).&lt;br /&gt;
Meetup will be monthly based.&lt;br /&gt;
 &lt;br /&gt;
==== Local meetup leader ====&lt;br /&gt;
&lt;br /&gt;
Local meetup leader is a person in charge of plan, organise and keep #appsec hype high on his neighborhood/city. For big cities like Milano, Torino, Roma, Napoli, ... there will be of course more leaders that '''must''' collaborate each other.&lt;br /&gt;
&lt;br /&gt;
==== Stuff to be done ====&lt;br /&gt;
&lt;br /&gt;
We must create a whitepaper document describing some general rules about how to organize a local meetup. Where to organize, who to invite, how to document the event (photo, talks recording), how to do media coverage, how to advertise the event, where to put infos, slidedecks, ...&lt;br /&gt;
&lt;br /&gt;
=== Communication boost ===&lt;br /&gt;
&lt;br /&gt;
People who wants to use IRC to chat with Owasp Italy members can use irc server chat.freenode.net on channel #owasp-italy&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188671</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188671"/>
				<updated>2015-01-28T11:01:11Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Build a local meetup network */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. Please note, this is not a page for an '''appsec conference''', this page is about an application security strategy for the Italian chapter in order to give a boost for activities and to be used year by year to measure how things went in our Country.&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
Goals for 2015&lt;br /&gt;
&lt;br /&gt;
* Date an opensource project&lt;br /&gt;
* Build a local meetup network&lt;br /&gt;
* Communication boost&lt;br /&gt;
&lt;br /&gt;
=== Date an opensource project ===&lt;br /&gt;
&lt;br /&gt;
In order to build a culture of security, filling the gap with developers we want to adopt opensource projects, doing code review and penetration tests over it, providing developers security feedbacks to raise the bar for attackers.&lt;br /&gt;
&lt;br /&gt;
==== Stuff to be done ====&lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/_ikki Luca Carettoni @_ikki] proposes a formal engagement process to adopt an opensource project, making assessments and giving feedbacks. We are evaluating how to procede, creating a framework to #fillthegap.&lt;br /&gt;
We are also wondering about creating some whitepapers to help development team introducing appsec.&lt;br /&gt;
&lt;br /&gt;
Popular projects that are candidate to be adopted are:&lt;br /&gt;
* [http://symfony.com/ Symfony]&lt;br /&gt;
* [http://rubyonrails.org Ruby on rails]&lt;br /&gt;
* [http://angular.js Angular.js]&lt;br /&gt;
* more to come&lt;br /&gt;
&lt;br /&gt;
=== Build a local meetup network ===&lt;br /&gt;
&lt;br /&gt;
In Italy, application security specialists don't meet each other and, more important, they don't meet developers and stakeholders in informal meetups to spread the #appsec credo. There are some focused security events (Infosecurity, Security Summit) but they are organized by security guys for other security guys and there are more formal state-of-art event in the Italian panorama.&lt;br /&gt;
&lt;br /&gt;
We feel the need of creating informal meetups were appsec guys gather each other java people, php people, ruby people, .Net people, UX people, entrepreneurs in order to build strong security basements for people make the real web.&lt;br /&gt;
&lt;br /&gt;
==== Local meetup leader ====&lt;br /&gt;
&lt;br /&gt;
Local meetup leader is a person in charge of plan, organise and keep #appsec hype high on his neighborhood/city. For big cities like Milano, Torino, Roma, Napoli, ... there will be of course more leaders that '''must''' collaborate each other.&lt;br /&gt;
&lt;br /&gt;
==== Stuff to be done ====&lt;br /&gt;
&lt;br /&gt;
We must create a whitepaper document describing some general rules about how to organize a local meetup. Where to organize, who to invite, how to document the event (photo, talks recording), how to do media coverage, how to advertise the event, where to put infos, slidedecks, ...&lt;br /&gt;
&lt;br /&gt;
=== Communication boost ===&lt;br /&gt;
&lt;br /&gt;
People who wants to use IRC to chat with Owasp Italy members can use irc server chat.freenode.net on channel #owasp-italy&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188670</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188670"/>
				<updated>2015-01-28T11:00:11Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Build a local meetup network */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. Please note, this is not a page for an '''appsec conference''', this page is about an application security strategy for the Italian chapter in order to give a boost for activities and to be used year by year to measure how things went in our Country.&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
Goals for 2015&lt;br /&gt;
&lt;br /&gt;
* Date an opensource project&lt;br /&gt;
* Build a local meetup network&lt;br /&gt;
* Communication boost&lt;br /&gt;
&lt;br /&gt;
=== Date an opensource project ===&lt;br /&gt;
&lt;br /&gt;
In order to build a culture of security, filling the gap with developers we want to adopt opensource projects, doing code review and penetration tests over it, providing developers security feedbacks to raise the bar for attackers.&lt;br /&gt;
&lt;br /&gt;
==== Stuff to be done ====&lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/_ikki Luca Carettoni @_ikki] proposes a formal engagement process to adopt an opensource project, making assessments and giving feedbacks. We are evaluating how to procede, creating a framework to #fillthegap.&lt;br /&gt;
We are also wondering about creating some whitepapers to help development team introducing appsec.&lt;br /&gt;
&lt;br /&gt;
Popular projects that are candidate to be adopted are:&lt;br /&gt;
* [http://symfony.com/ Symfony]&lt;br /&gt;
* [http://rubyonrails.org Ruby on rails]&lt;br /&gt;
* [http://angular.js Angular.js]&lt;br /&gt;
* more to come&lt;br /&gt;
&lt;br /&gt;
=== Build a local meetup network ===&lt;br /&gt;
&lt;br /&gt;
In Italy, application security specialists don't meet each other and, more important, they don't meet developers and stakeholders in informal meetups to spread the #appsec credo. There are some focused security events (Infosecurity, Security Summit) but they are organized by security guys for other security guys and there are more formal state-of-art event in the Italian panorama.&lt;br /&gt;
&lt;br /&gt;
We feel the need of creating informal meetups were appsec guys gather each other java people, php people, ruby people, .Net people, UX people, entrepreneurs in order to build strong security basements for people make the real web.&lt;br /&gt;
&lt;br /&gt;
==== Local meetup leader ====&lt;br /&gt;
&lt;br /&gt;
Local meetup leader is a person in charge of plan, organise and keep #appsec hype high on his neighborhood/city. For big cities like Milano, Torino, Roma, Napoli, ... there will be of course more leaders that '''must''' collaborate each other.&lt;br /&gt;
&lt;br /&gt;
==== Need to be done ====&lt;br /&gt;
&lt;br /&gt;
We must create a whitepaper document describing some general rules about how to organize a local meetup. Where to organize, who to invite, how to document the event (photo, talks recording), how to do media coverage, how to advertise the event, where to put infos, slidedecks, ...&lt;br /&gt;
&lt;br /&gt;
=== Communication boost ===&lt;br /&gt;
&lt;br /&gt;
People who wants to use IRC to chat with Owasp Italy members can use irc server chat.freenode.net on channel #owasp-italy&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188669</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188669"/>
				<updated>2015-01-28T10:55:46Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Date an opensource project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. Please note, this is not a page for an '''appsec conference''', this page is about an application security strategy for the Italian chapter in order to give a boost for activities and to be used year by year to measure how things went in our Country.&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
Goals for 2015&lt;br /&gt;
&lt;br /&gt;
* Date an opensource project&lt;br /&gt;
* Build a local meetup network&lt;br /&gt;
* Communication boost&lt;br /&gt;
&lt;br /&gt;
=== Date an opensource project ===&lt;br /&gt;
&lt;br /&gt;
In order to build a culture of security, filling the gap with developers we want to adopt opensource projects, doing code review and penetration tests over it, providing developers security feedbacks to raise the bar for attackers.&lt;br /&gt;
&lt;br /&gt;
==== Stuff to be done ====&lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/_ikki Luca Carettoni @_ikki] proposes a formal engagement process to adopt an opensource project, making assessments and giving feedbacks. We are evaluating how to procede, creating a framework to #fillthegap.&lt;br /&gt;
We are also wondering about creating some whitepapers to help development team introducing appsec.&lt;br /&gt;
&lt;br /&gt;
Popular projects that are candidate to be adopted are:&lt;br /&gt;
* [http://symfony.com/ Symfony]&lt;br /&gt;
* [http://rubyonrails.org Ruby on rails]&lt;br /&gt;
* [http://angular.js Angular.js]&lt;br /&gt;
* more to come&lt;br /&gt;
&lt;br /&gt;
=== Build a local meetup network ===&lt;br /&gt;
&lt;br /&gt;
In Italy, application security specialists don't meet each other and, more important, they don't meet developers and stakeholders in informal meetups to spread the #appsec credo. There are some focused security events (Infosecurity, Security Summit) but they are organized by security guys for other security guys and there are more formal state-of-art event in the Italian panorama.&lt;br /&gt;
&lt;br /&gt;
We feel the need of creating informal meetups were appsec guys gather each other java people, php people, ruby people, .Net people, UX people, entrepreneurs in order to build strong security basements for people make the real web.&lt;br /&gt;
&lt;br /&gt;
=== Communication boost ===&lt;br /&gt;
&lt;br /&gt;
People who wants to use IRC to chat with Owasp Italy members can use irc server chat.freenode.net on channel #owasp-italy&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188668</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188668"/>
				<updated>2015-01-28T10:44:39Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* 2015 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. Please note, this is not a page for an '''appsec conference''', this page is about an application security strategy for the Italian chapter in order to give a boost for activities and to be used year by year to measure how things went in our Country.&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
Goals for 2015&lt;br /&gt;
&lt;br /&gt;
* Date an opensource project&lt;br /&gt;
* Build a local meetup network&lt;br /&gt;
* Communication boost&lt;br /&gt;
&lt;br /&gt;
=== Date an opensource project ===&lt;br /&gt;
&lt;br /&gt;
In order to build a culture of security, filling the gap with developers we want to adopt opensource projects, doing code review and penetration tests over it, providing developers security feedbacks to raise the bar for attackers.&lt;br /&gt;
&lt;br /&gt;
=== Build a local meetup network ===&lt;br /&gt;
&lt;br /&gt;
In Italy, application security specialists don't meet each other and, more important, they don't meet developers and stakeholders in informal meetups to spread the #appsec credo. There are some focused security events (Infosecurity, Security Summit) but they are organized by security guys for other security guys and there are more formal state-of-art event in the Italian panorama.&lt;br /&gt;
&lt;br /&gt;
We feel the need of creating informal meetups were appsec guys gather each other java people, php people, ruby people, .Net people, UX people, entrepreneurs in order to build strong security basements for people make the real web.&lt;br /&gt;
&lt;br /&gt;
=== Communication boost ===&lt;br /&gt;
&lt;br /&gt;
People who wants to use IRC to chat with Owasp Italy members can use irc server chat.freenode.net on channel #owasp-italy&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188667</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188667"/>
				<updated>2015-01-28T10:37:27Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. Please note, this is not a page for an '''appsec conference''', this page is about an application security strategy for the Italian chapter in order to give a boost for activities and to be used year by year to measure how things went in our Country.&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
Goals for 2015&lt;br /&gt;
&lt;br /&gt;
* adopt 5 popular opensource projects and perform reviews and be in touch with developers to raise security level&lt;br /&gt;
* organize at least 5 local meetups per year in most popular cities&lt;br /&gt;
* boost communications between subscribers promoting an IRC channel to talk about appsec in Italian&lt;br /&gt;
&lt;br /&gt;
=== Communications ===&lt;br /&gt;
&lt;br /&gt;
People who wants to use IRC to chat with Owasp Italy members can use irc server chat.freenode.net on channel #owasp-italy&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188666</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188666"/>
				<updated>2015-01-28T10:29:34Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. Please note, this is not a page for an '''appsec conference''', this page is about an application security strategy for the Italian chapter in order to give a boost for activities and to be used year by year to measure how things went in our Country.&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
In 2015 we want to boost Owasp Italian chapter, to give it new strength.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* adopt 5 popular opensource projects and perform reviews and be in touch with developers to raise security level&lt;br /&gt;
* organize at least 5 local meetups per year in most popular cities&lt;br /&gt;
* boost communications between subscribers promoting an IRC channel to talk about appsec in Italian&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188450</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188450"/>
				<updated>2015-01-23T15:36:13Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* 2015 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. This agenda was born in 2015 with the goal to revamp Italian chapter and boost activities over our country.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
In 2015 we want to boost Owasp Italian chapter, to give it new strength.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* adopt 5 popular opensource projects and perform reviews and be in touch with developers to raise security level&lt;br /&gt;
* organize at least 5 local meetups per year in most popular cities&lt;br /&gt;
* boost communications between subscribers promoting an IRC channel to talk about appsec in Italian&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188405</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188405"/>
				<updated>2015-01-22T12:04:45Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. This agenda was born in 2015 with the goal to revamp Italian chapter and boost activities over our country.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
* adopt 5 popular opensource projects and perform reviews and be in touch with developers to raise security level&lt;br /&gt;
* organize at least 5 local meetups per year in most popular cities&lt;br /&gt;
* boost communications between subscribers promoting an IRC channel to talk about appsec in Italian&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188404</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188404"/>
				<updated>2015-01-22T12:03:12Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Security Agenda for Owasp Italian chapter. This agenda was born in 2015 with the goal to revamp Italian chapter and boost activities over our country.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
* adopt 5 popular opensource projects and perform reviews and be in touch with developers to raise security level&lt;br /&gt;
* organize at least 5 local meetups per year in most popular cities&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188403</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188403"/>
				<updated>2015-01-22T12:02:17Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Owasp Italy Appsec Agenda =&lt;br /&gt;
&lt;br /&gt;
This is the Application Security Agenda for Owasp Italian chapter&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;br /&gt;
&lt;br /&gt;
* adopt 5 popular opensource projects and perform reviews and be in touch with developers to raise security level&lt;br /&gt;
* organize at least 5 local meetups per year in most popular cities&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188402</id>
		<title>Owasp Italy Appsec agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Owasp_Italy_Appsec_agenda&amp;diff=188402"/>
				<updated>2015-01-22T11:59:23Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: Created page with &amp;quot;= Owasp Italy Appsec Agenda =  == 2015 ==&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Owasp Italy Appsec Agenda =&lt;br /&gt;
&lt;br /&gt;
== 2015 ==&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Thesp0nge&amp;diff=188401</id>
		<title>User:Thesp0nge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Thesp0nge&amp;diff=188401"/>
				<updated>2015-01-22T11:54:13Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Paolo was born in 1976 in Milan, Italy. Since he was 5, he started disassembling toys trying to understand their internals... it was very rare he was able to put the pieces back in their place. So his infancy was full of broken toys... but at least he discovered what's inside a little car moving by itself.&lt;br /&gt;
Let's call this Paolo's life phase: 'Breaking the law'&lt;br /&gt;
&lt;br /&gt;
When he discovered computers, Paolo learnt also to repair software he broke. He started patching buffer overflows, format bugs and other crappy C programs. It was 1996, he discovered Linux, the networking and the kernel land. It was the time Pink Floyd were in loop in Paolo's walkman.&lt;br /&gt;
Let's call this Paolo's life phase: 'So your instruction pointer is full of 0x41?'&lt;br /&gt;
&lt;br /&gt;
Nowadays Paolo's interest in reviewing and fixing broken code turn him in an application security specialist for a Italian company in Media &amp;amp; Broadcasting. It has a technical blog in Italian you can find here: [https://codiceinsicuro.it codiceinsicuro.it]. He is involved in Owasp as Project Leader of [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Orizon Owasp Orizon (a code review engine)] and [http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Ruby Owasp Esapi for Ruby Owasp ESAPI for Ruby porting]. He is also in the Owasp Italian chapter board. It's the time that Pearl Jam and old school metal music fill Paolo's mp3 player, he is an husband, a proud father, and a black belt Taekwon-do ITF martial artist.&lt;br /&gt;
Let's call this Paolo's life phase: 'Stay hungry, stay foolish'&lt;br /&gt;
&lt;br /&gt;
You can reach me by email: thesp0nge_at_owasp.org or you can add thesp0nge_at_gmail.com as GTalk buddy.&lt;br /&gt;
&lt;br /&gt;
Here it is my Linkedin [http://www.linkedin.com/in/thesp0nge profile]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=176716</id>
		<title>OWASP Ruby on Rails and friends Security Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=176716"/>
				<updated>2014-06-10T08:31:14Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{:Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide}} &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175319</id>
		<title>Projects/OWASP Ruby on Rails and friends Security Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175319"/>
				<updated>2014-05-20T09:17:42Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Classifications */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Ruby on Rails and friends Security Guide==&lt;br /&gt;
&lt;br /&gt;
Real text will be here soon...&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Real description will be here...&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Ruby on Rails and friends Security Guide? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide  provides:&lt;br /&gt;
&lt;br /&gt;
* an hardening guide for Sinatra, Padrino and Ruby on Rails applications&lt;br /&gt;
* tips on how to harden nginx, apache and mod_passenger installations&lt;br /&gt;
* ... &lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Paolo Perego (thesp0nge@owasp.org)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_ESAPI_Ruby]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* no ohloh information available right now&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width25%;&amp;quot; |  &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Owasp Ruby on Rails and friends security guide is proudly hosted on [https://github.com/OWASP/RoR-and-Friends-Security-Guide github].&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
[https://lists.owasp.org/mailman/listinfo/owasp_ruby_on_rails_and_friends_security_guide Sign up here]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [14 May 2014] Migrating Project template and [https://github.com/OWASP/RoR-and-Friends-Security-Guide github repository created]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project will be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
    {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; When the guide will be ready?&lt;br /&gt;
: I'm planning to start the outline on Summer 2014. I guess a beta will eventually will be ready later in winter '14.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Paolo Perego&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
None at the moment&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of OWASP Ruby on Rails and friends Security Guid, the priorities are:&lt;br /&gt;
* define a checklist about hardening your (apache|nginx)+mod_passenger installation&lt;br /&gt;
* define a checklist about hardening your models with popular ORMs (ActiveRecords, Datamapper, ...)&lt;br /&gt;
* define a checklist about write a secure Sinatra, Padrino and Ruby on Rails application&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Ruby on Rails and friends Security Guide is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175034</id>
		<title>Projects/OWASP Ruby on Rails and friends Security Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175034"/>
				<updated>2014-05-14T15:02:26Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Ruby on Rails and friends Security Guide==&lt;br /&gt;
&lt;br /&gt;
Real text will be here soon...&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Real description will be here...&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Ruby on Rails and friends Security Guide? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide  provides:&lt;br /&gt;
&lt;br /&gt;
* an hardening guide for Sinatra, Padrino and Ruby on Rails applications&lt;br /&gt;
* tips on how to harden nginx, apache and mod_passenger installations&lt;br /&gt;
* ... &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Paolo Perego (thesp0nge@owasp.org)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_ESAPI_Ruby]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* no ohloh information available right now&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Owasp Ruby on Rails and friends security guide is proudly hosted on [https://github.com/OWASP/RoR-and-Friends-Security-Guide github].&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp_ruby_on_rails_and_friends_security_guide&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [14 May 2014] Migrating Project template and [https://github.com/OWASP/RoR-and-Friends-Security-Guide github repository created]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project will be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; When the guide will be ready?&lt;br /&gt;
: I'm planning to start the outline on Summer 2014. I guess a beta will eventually will be ready later in winter '14.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Paolo Perego&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
None at the moment&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of OWASP Ruby on Rails and friends Security Guid, the priorities are:&lt;br /&gt;
* define a checklist about hardening your (apache|nginx)+mod_passenger installation&lt;br /&gt;
* define a checklist about hardening your models with popular ORMs (ActiveRecords, Datamapper, ...)&lt;br /&gt;
* define a checklist about write a secure Sinatra, Padrino and Ruby on Rails application&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Ruby on Rails and friends Security Guide is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175033</id>
		<title>Projects/OWASP Ruby on Rails and friends Security Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175033"/>
				<updated>2014-05-14T15:01:52Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Quick Download */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Ruby on Rails and friends Security Guide==&lt;br /&gt;
&lt;br /&gt;
Real text will be here soon...&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Real description will be here...&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Ruby on Rails and friends Security Guide? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide  provides:&lt;br /&gt;
&lt;br /&gt;
* an hardening guide for Sinatra, Padrino and Ruby on Rails applications&lt;br /&gt;
* tips on how to harden nginx, apache and mod_passenger installations&lt;br /&gt;
* ... &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Paolo Perego (thesp0nge@owasp.org)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_ESAPI_Ruby]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* no ohloh information available right now&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Owasp Ruby on Rails and friends security guide is proudly hosted on [https://github.com/OWASP/RoR-and-Friends-Security-Guide github].&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp_ruby_on_rails_and_friends_security_guide&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [14 May 2014] Migrating Project template &lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project will be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; When the guide will be ready?&lt;br /&gt;
: I'm planning to start the outline on Summer 2014. I guess a beta will eventually will be ready later in winter '14.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Paolo Perego&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
None at the moment&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of OWASP Ruby on Rails and friends Security Guid, the priorities are:&lt;br /&gt;
* define a checklist about hardening your (apache|nginx)+mod_passenger installation&lt;br /&gt;
* define a checklist about hardening your models with popular ORMs (ActiveRecords, Datamapper, ...)&lt;br /&gt;
* define a checklist about write a secure Sinatra, Padrino and Ruby on Rails application&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Ruby on Rails and friends Security Guide is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175032</id>
		<title>Projects/OWASP Ruby on Rails and friends Security Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175032"/>
				<updated>2014-05-14T15:01:23Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Quick Download */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Ruby on Rails and friends Security Guide==&lt;br /&gt;
&lt;br /&gt;
Real text will be here soon...&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Real description will be here...&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Ruby on Rails and friends Security Guide? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide  provides:&lt;br /&gt;
&lt;br /&gt;
* an hardening guide for Sinatra, Padrino and Ruby on Rails applications&lt;br /&gt;
* tips on how to harden nginx, apache and mod_passenger installations&lt;br /&gt;
* ... &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Paolo Perego (thesp0nge@owasp.org)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_ESAPI_Ruby]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* no ohloh information available right now&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Owasp Ruby on Rails and friends security guide is proudly hosted on [github](https://github.com/OWASP/RoR-and-Friends-Security-Guide).&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp_ruby_on_rails_and_friends_security_guide&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [14 May 2014] Migrating Project template &lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project will be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; When the guide will be ready?&lt;br /&gt;
: I'm planning to start the outline on Summer 2014. I guess a beta will eventually will be ready later in winter '14.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Paolo Perego&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
None at the moment&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of OWASP Ruby on Rails and friends Security Guid, the priorities are:&lt;br /&gt;
* define a checklist about hardening your (apache|nginx)+mod_passenger installation&lt;br /&gt;
* define a checklist about hardening your models with popular ORMs (ActiveRecords, Datamapper, ...)&lt;br /&gt;
* define a checklist about write a secure Sinatra, Padrino and Ruby on Rails application&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Ruby on Rails and friends Security Guide is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175029</id>
		<title>Projects/OWASP Ruby on Rails and friends Security Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175029"/>
				<updated>2014-05-14T14:41:08Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Ruby on Rails and friends Security Guide==&lt;br /&gt;
&lt;br /&gt;
Real text will be here soon...&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Real description will be here...&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Ruby on Rails and friends Security Guide? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide  provides:&lt;br /&gt;
&lt;br /&gt;
* an hardening guide for Sinatra, Padrino and Ruby on Rails applications&lt;br /&gt;
* tips on how to harden nginx, apache and mod_passenger installations&lt;br /&gt;
* ... &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Paolo Perego (thesp0nge@owasp.org)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_ESAPI_Ruby]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* no ohloh information available right now&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp_ruby_on_rails_and_friends_security_guide&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [14 May 2014] Migrating Project template &lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project will be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; When the guide will be ready?&lt;br /&gt;
: I'm planning to start the outline on Summer 2014. I guess a beta will eventually will be ready later in winter '14.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Paolo Perego&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
None at the moment&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of OWASP Ruby on Rails and friends Security Guid, the priorities are:&lt;br /&gt;
* define a checklist about hardening your (apache|nginx)+mod_passenger installation&lt;br /&gt;
* define a checklist about hardening your models with popular ORMs (ActiveRecords, Datamapper, ...)&lt;br /&gt;
* define a checklist about write a secure Sinatra, Padrino and Ruby on Rails application&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Ruby on Rails and friends Security Guide is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175025</id>
		<title>Projects/OWASP Ruby on Rails and friends Security Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide&amp;diff=175025"/>
				<updated>2014-05-14T14:14:51Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Ruby on Rails and friends Security Guide==&lt;br /&gt;
&lt;br /&gt;
Real text will be here soon...&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Real description will be here...&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Ruby on Rails and friends Security Guide? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide  provides:&lt;br /&gt;
&lt;br /&gt;
* an hardening guide for Sinatra, Padrino and Ruby on Rails applications&lt;br /&gt;
* tips on how to harden nginx, apache and mod_passenger installations&lt;br /&gt;
* ... &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Paolo Perego (thesp0nge@owasp.org)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_ESAPI_Ruby]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* no ohloh information available right now&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp_ruby_on_rails_and_friends_security_guide&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [14 May 2014] Migrating Project template &lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project will be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; When the guide will be ready?&lt;br /&gt;
: I'm planning to start the outline on Summer 2014. I guess a beta will eventually will be ready later in winter '14.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Ruby on Rails and friends Security Guide is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Paolo Perego&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
None at the moment&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of OWASP Ruby on Rails and friends Security Guid, the priorities are:&lt;br /&gt;
* define a checklist about hardening your (apache|nginx)+mod_passenger installation&lt;br /&gt;
* define a checklist about hardening your models with popular ORMs (ActiveRecords, Datamapper, ...)&lt;br /&gt;
* define a checklist about write a secure Sinatra, Padrino and Ruby on Rails application&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Ruby on Rails and friends Security Guide is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Ruby_on_Rails_and_friends_Security_Guide}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Source_Code_Analysis_Tools&amp;diff=155304</id>
		<title>Source Code Analysis Tools</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Source_Code_Analysis_Tools&amp;diff=155304"/>
				<updated>2013-07-10T10:39:44Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Open Source or Free Tools Of This Type */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Source Code Analysis tools are designed to analyze source code and/or compiled version of code in order to help find security flaws. Ideally, such tools would automatically find security flaws with a high degree of confidence that what is found is indeed a flaw. However, this is beyond the state of the art for many types of application security flaws. Thus, such tools frequently serve as aids for an analyst to help them zero in on security relevant portions of code so they can find flaws more efficiently, rather than a tool that simply finds flaws automatically.&lt;br /&gt;
&lt;br /&gt;
Some tools are starting to move into the IDE. For the types of problems that can be detected during the software development phase itself, this is a powerful phase within the development lifecycle to employ such tools, as it provides immediate feedback to the developer on issues they might be introducing into the code during code development itself. This immediate feedback is very useful as compared to finding vulnerabilities much later in the development cycle.&lt;br /&gt;
&lt;br /&gt;
==Strengths and Weaknesses of such tools==&lt;br /&gt;
&lt;br /&gt;
=== Strengths ===&lt;br /&gt;
* Scales Well (Can be run on lots of software, and can be repeatedly (like in nightly builds))&lt;br /&gt;
* For things that such tools can automatically find with high confidence, such as buffer overflows, SQL Injection Flaws, etc. they are great.&lt;br /&gt;
&lt;br /&gt;
=== Weaknesses ===&lt;br /&gt;
* Many types of security vulnerabilities are very difficult to find automatically, such as authentication problems, access control issues, insecure use of cryptography, etc. The current state of the art only allows such tools to automatically find a relatively small percentage of application security flaws. Tools of this type are getting better, however.&lt;br /&gt;
* High numbers of false positives.&lt;br /&gt;
* Frequently can't find configuration issues, since they are not represented in the code.&lt;br /&gt;
* Difficult to 'prove' that an identified security issue is an actual vulnerability.&lt;br /&gt;
* Many of these tools have difficulty analyzing code that can't be compiled. Analysts frequently can't compile code because they don't have the right libraries, all the compilation instructions, all the code, etc.&lt;br /&gt;
&lt;br /&gt;
==Important Selection Criteria==&lt;br /&gt;
&lt;br /&gt;
* Requirement: Must support your language, but not usually a key factor once it does.&lt;br /&gt;
&lt;br /&gt;
* Types of Vulnerabilities it can detect (Out of the OWASP Top Ten?) (plus more?)&lt;br /&gt;
* Does it require a fully buildable set of source?&lt;br /&gt;
* Can it run against binaries instead of source?&lt;br /&gt;
* Can it be integrated into the developer's IDE?&lt;br /&gt;
* License cost for the tool. (Some are sold per user, per org, per app, per line of code analyzed. Consulting licenses are frequently different than end user licenses.)&lt;br /&gt;
&lt;br /&gt;
==OWASP Tools Of This Type==&lt;br /&gt;
* [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&lt;br /&gt;
* [[OWASP_LAPSE_Project | OWASP LAPSE Project]]&lt;br /&gt;
* [[OWASP O2 Platform]]&lt;br /&gt;
&lt;br /&gt;
==Open Source or Free Tools Of This Type==&lt;br /&gt;
&lt;br /&gt;
* [http://www.stachliu.com/resources/tools/google-hacking-diggity-project/attack-tools/ Google CodeSearchDiggity] - Utilizes Google Code Search to identifies vulnerabilities in open source code projects hosted by Google Code, MS CodePlex, SourceForge, Github, and more. The tool comes with over 130 default searches that identify SQL injection, cross-site scripting (XSS), insecure remote and local file includes, hard-coded passwords, and much more.  ''Essentially, Google CodeSearchDiggity provides a source code security analysis of nearly every single open source code project in existence – simultaneously.'' &lt;br /&gt;
* [http://findbugs.sourceforge.net/ FindBugs] - Find Bugs (including some security flaws) in Java Programs&lt;br /&gt;
* [http://msdn.microsoft.com/en-us/library/bb429476(VS.80).aspx FxCop] (Microsoft) - FxCop is an application that analyzes managed code assemblies (code that targets the .NET Framework common language runtime) and reports information about the assemblies, such as possible design, localization, performance, and security improvements.&lt;br /&gt;
* [http://pmd.sourceforge.net/ PMD] - PMD scans Java source code and looks for potential code problems (this is a code quality tool that does not focus on security issues)&lt;br /&gt;
* [http://msdn.microsoft.com/en-us/library/ms933794.aspx PreFast] (Microsoft) - PREfast is a static analysis tool that identifies defects in C/C++ programs&lt;br /&gt;
* [https://www.fortify.com/ssa-elements/threat-intelligence/rats.html RATS] (Fortify) - Scans C, C++, Perl, PHP and Python source code for security problems like buffer overflows and TOCTOU (Time Of Check, Time Of Use) race conditions&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_SWAAT_Project OWASP SWAAT Project] - Simplistic Beta Tool - Languages: Java, JSP, ASP .Net, and PHP&lt;br /&gt;
* [http://www.dwheeler.com/flawfinder/ Flawfinder] Flawfinder - Scans C and C++&lt;br /&gt;
* [http://sourceforge.net/projects/rips-scanner/ RIPS] - RIPS is a static source code analyzer for vulnerabilities in PHP web applications&lt;br /&gt;
* [http://brakemanscanner.org/ Brakeman] - Brakeman is an open source vulnerability scanner specifically designed for Ruby on Rails applications&lt;br /&gt;
* [http://rubygems.org/gems/codesake-dawn Codesake Dawn] - Codesake Dawn is an open source security source code analyzer designed for Sinatra, Padrino and Ruby on Rails applications. It can work also for non web application wrote in Ruby programming language &lt;br /&gt;
* [http://sourceforge.net/projects/visualcodegrepp/ VCG] - Scans C/C++, Java, C# and PL/SQL for security issues and for comments which may indicate defective code. The config files can be used to carry out additional checks for banned functions or functions which commonly cause security issues.&lt;br /&gt;
&lt;br /&gt;
==Commercial Tools from OWASP Members Of This Type==&lt;br /&gt;
&lt;br /&gt;
These vendors have decided to support OWASP by becoming [[Membership|members]]. OWASP appreciates the support from these organizations, but cannot endorse any commercial products or services.&lt;br /&gt;
&lt;br /&gt;
* [http://www-01.ibm.com/software/rational/products/appscan/source/ IBM Security AppScan Source Edition] (formerly Ounce)&lt;br /&gt;
* [http://www.armorize.com/codesecure/ Static Source Code Analysis with CodeSecure™] (Armorize Technologies)&lt;br /&gt;
* [http://www.checkmarx.com/technology/static-code-analysis-sca/ Static Code Analysis] (Checkmarx)&lt;br /&gt;
* [https://www.fortify.com/products/hpfssc/source-code-analyzer.html Source Code Analysis] (HP/Fortify)&lt;br /&gt;
* [http://www.veracode.com/ Veracode] (Veracode)&lt;br /&gt;
&lt;br /&gt;
==Other Well Known Commercial Tools Of This Type==&lt;br /&gt;
&lt;br /&gt;
* [http://www.coverity.com/products/static-analysis.html Static Analysis] (Coverity)&lt;br /&gt;
* [http://www.klocwork.com/products/insight.asp Insight] (KlocWork)&lt;br /&gt;
* [http://www.parasoft.com/jsp/capabilities/static_analysis.jsp?itemId=547 Parasoft Test] (Parasoft)&lt;br /&gt;
&lt;br /&gt;
==More Info==&lt;br /&gt;
&lt;br /&gt;
* TODO: add comments from: http://lists.owasp.org/pipermail/owasp-dotnet/2006-August/000002.html&lt;br /&gt;
* [[Appendix_A:_Testing_Tools | Appendix A: Testing Tools]]&lt;br /&gt;
* [http://samate.nist.gov/index.php/Source_Code_Security_Analyzers NIST's list of Source Code Security Analysis Tools]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP .NET Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Ruby_on_Rails_Cheatsheet&amp;diff=153609</id>
		<title>Ruby on Rails Cheatsheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Ruby_on_Rails_Cheatsheet&amp;diff=153609"/>
				<updated>2013-06-13T15:52:34Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Tools */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;DRAFT CHEAT SHEET - WORK IN PROGRESS&lt;br /&gt;
&lt;br /&gt;
= Introduction =&lt;br /&gt;
&lt;br /&gt;
This ''Cheatsheet'' intends to provide quick basic Ruby on Rails security tips for developers. It complements, augments or emphasizes points brought up in the [http://guides.rubyonrails.org/security.html rails security guide] from rails core.&lt;br /&gt;
&lt;br /&gt;
The Rails framework abstracts developers from quite a bit of tedious work and provides the means to accomplish complex tasks quickly and with ease. New developers, those unfamiliar with the inner-workings of Rails, likely need a basic set of guidelines to secure fundamental aspects of their application. The intended purpose of this doc is to be that guide.&lt;br /&gt;
&lt;br /&gt;
= Items =&lt;br /&gt;
== Command Injection == &lt;br /&gt;
&lt;br /&gt;
Ruby offers a function called “eval” which will dynamically build new Ruby code based on Strings.  It also has a number of ways to call system commands.&lt;br /&gt;
 &lt;br /&gt;
   eval(&amp;quot;ruby code here&amp;quot;)&lt;br /&gt;
   System(&amp;quot;os command here&amp;quot;)&lt;br /&gt;
   `ls -al /`   (backticks contain os command)&lt;br /&gt;
   Kernel.exec(&amp;quot;os command here&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
While the power of these commands is quite useful, extreme care should be taken when using them in a Rails based application.  Usually, its just a bad idea.  If need be, a whitelist of possible values should be used and any input should be validated as thoroughly as possible.  The Ruby Security Reviewer's Guide has a  [http://code.google.com/p/ruby-security/wiki/Guide#Good_ol%27_shell_injection section on injection]  and there are a number of OWASP references for it, starting at the top:  [https://www.owasp.org/index.php/Command_Injection Command Injection].&lt;br /&gt;
&lt;br /&gt;
== SQL Injection == &lt;br /&gt;
&lt;br /&gt;
Ruby on Rails is often used with an ORM called ActiveRecord, though it is flexible and can be used with other data sources.  Typically very simple Rails applications use methods on the Rails models to query data.  Many use cases protect for SQL Injection out of the box.  However, it is possible to write code that allows for SQL Injection.  &lt;br /&gt;
&lt;br /&gt;
Here is an example (Rails 2.X style):&lt;br /&gt;
&lt;br /&gt;
    @projects = Project.find(:all, :conditions =&amp;gt; “name like #{params[:name]}”)&lt;br /&gt;
&lt;br /&gt;
A Rails 3.X example:&lt;br /&gt;
&lt;br /&gt;
    name = params[:name]&lt;br /&gt;
    @projects = Project.where(“name like ‘“ + name + “‘“);&lt;br /&gt;
&lt;br /&gt;
In both of these cases, the statement is injectable because the name parameter is not escaped.  &lt;br /&gt;
&lt;br /&gt;
Here is the idiom for building this kind of statement:&lt;br /&gt;
&lt;br /&gt;
    @projects = Project.find(:all, :conditions =&amp;gt; [ “name like ?”, “#{params[:name]}”] )&lt;br /&gt;
&lt;br /&gt;
An AREL based solution:&lt;br /&gt;
&lt;br /&gt;
    @projects = Project.where(&amp;quot;name like ?&amp;quot;, &amp;quot;%#{params[:name]}%&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
Use caution not to build SQL statements based on user controlled input.  A list of more realistic and detailed examples is here: [http://rails-sqli.org rails-sqli.org].  OWASP has extensive information about [https://www.owasp.org/index.php/SQL_Injection SQL Injection].&lt;br /&gt;
&lt;br /&gt;
== Cross-site Scripting (XSS) == &lt;br /&gt;
&lt;br /&gt;
By default, in Rails 3.0 protection against XSS comes as the default behavior.  When string data is shown in views, it is escaped prior to being sent back to the browser.  This goes a long way, but there are common cases where developers bypass this protection - for example to enable rich text editing.  In the event that you want to pass variables to the front end with tags intact, it is tempting to do the following in your .erb file (ruby markup).&lt;br /&gt;
&lt;br /&gt;
    &amp;lt;%= raw @product.name %&amp;gt;   &lt;br /&gt;
    &amp;lt;%= @product.name.html_safe %&amp;gt;       These are examples of how NOT to do it!&lt;br /&gt;
    &amp;lt;%= content_tag @product.name %&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Unfortunately, any field that uses raw like this will be a potential XSS target.  Note that there are also widespread misunderstandings about html_safe.  [http://stackoverflow.com/questions/4251284/raw-vs-html-safe-vs-h-to-unescape-html This writeup] describes the underlying SafeBuffer mechanism in detail.  Other tags that change the way strings are prepared for output can introduce similar issues, including content_tag.&lt;br /&gt;
&lt;br /&gt;
If you must accept HTML content from users, consider a markup language for rich text in an application (Examples include:  markdown and textile) and disallow HTML tags. This helps ensures that the input accepted doesn’t include HTML content that could be malicious. If you cannot restrict your users from entering HTML, consider implementing content security policy to disallow the execution of any javascript. And finally, consider using the #sanitize method that let's you whitelist allowed tags. Be careful, this method has been shown to be flawed numerous times and will never be a complete solution.&lt;br /&gt;
&lt;br /&gt;
An often overlooked XSS attack vector is the href value of a link:&lt;br /&gt;
&lt;br /&gt;
    &amp;lt;%= link_to “Personal Website”, @user.website %&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If @user.website contains a link that starts with “javascript:”, the content will execute when a user clicks the generated link:&lt;br /&gt;
&lt;br /&gt;
    &amp;lt;a href=”javascript:alert(‘Haxored’)”&amp;gt;Personal Website&amp;lt;/a&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP provides more general information about XSS in a top level page: [https://www.owasp.org/index.php/Cross-site_Scripting_%28XSS%29 OWASP Cross Site Scripting].&lt;br /&gt;
&lt;br /&gt;
== Sessions ==&lt;br /&gt;
&lt;br /&gt;
By default, Ruby on Rails uses a Cookie based session store.  What that means is that unless you change something, the session will not expire on the server.  That means that some default applications may be vulnerable to replay attacks.  It also means that sensitive information should never be put in the session.&lt;br /&gt;
&lt;br /&gt;
The best practice is to use a database based session, which thankfully is very easy with Rails:&lt;br /&gt;
&lt;br /&gt;
    Project::Application.config.session_store :active_record_store&lt;br /&gt;
&lt;br /&gt;
There is an [https://www.owasp.org/index.php/Session_Management_Cheat_Sheet OWASP Session Management Cheat Sheet].&lt;br /&gt;
&lt;br /&gt;
== Authentication == &lt;br /&gt;
&lt;br /&gt;
Generally speaking, Rails does not provide authentication by itself.  However, most developers using Rails leverage libraries such as Devise or AuthLogic to provide authentication.  To enable authentication with Devise, one simply has to put the following in a controller:&lt;br /&gt;
&lt;br /&gt;
    class ProjectController &amp;lt; ApplicationController&lt;br /&gt;
        before_filter :authenticate_user&lt;br /&gt;
&lt;br /&gt;
As with other methods, this supports exceptions.  Note that by default Devise only requires 6 characters for a password.  The minimum can be changed in:  /config/initializers/devise.rb&lt;br /&gt;
&lt;br /&gt;
    config.password_length = 8..128&lt;br /&gt;
&lt;br /&gt;
There are several possible ways to enforce complexity.  One is to put a Validator in the user model.&lt;br /&gt;
      &lt;br /&gt;
    validate :password_complexity&lt;br /&gt;
    def password_complexity&lt;br /&gt;
       if password.present? and not password.match(/\A(?=.*[a-z])(?=.*[A-Z])(?=.*\d).+\z/)&lt;br /&gt;
           errors.add :password, &amp;quot;must include at least one lowercase letter, one uppercase letter, and one digit&amp;quot;&lt;br /&gt;
       end&lt;br /&gt;
    end&lt;br /&gt;
&lt;br /&gt;
There is an [https://www.owasp.org/index.php/Authentication_Cheat_Sheet OWASP Authentication Cheat Sheet].&lt;br /&gt;
&lt;br /&gt;
== Insecure Direct Object Reference or Forceful Browsing == &lt;br /&gt;
&lt;br /&gt;
By default, Ruby on Rails apps use a RESTful uri structure.  That means that paths are often intuitive and guessable.  To protect against a user trying to access or modify data that belongs to another user, it is important to specifically control actions.  Out of the gate on a vanilla Rails application, there is no such built in protection.  It is possible to do this by hand at the controller level.  &lt;br /&gt;
&lt;br /&gt;
It is also possible, and probably recommended, to consider resource-based access control libraries such as [https://github.com/ryanb/cancan cancan] to do this. This ensures that all operations on a database object are authorized by the business logic of the application.&lt;br /&gt;
&lt;br /&gt;
More general information about this class of vulnerability is in the [https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Direct_Object_References OWASP Top 10 Page].&lt;br /&gt;
&lt;br /&gt;
== CSRF (Cross Site Request Forgery) ==&lt;br /&gt;
&lt;br /&gt;
Ruby on Rails has specific, built in support for CSRF tokens.  To enable it, or ensure that it is enabled, find the base ApplicationController and look for a directive such as the following:&lt;br /&gt;
&lt;br /&gt;
    class ApplicationController &amp;lt; ActionController::Base&lt;br /&gt;
        protect_from_forgery&lt;br /&gt;
&lt;br /&gt;
Note that the syntax for this type of control includes a way to add exceptions.  Exceptions may be useful for API’s or other reasons - but should be reviewed and consciously included.  In the example below, the Rails ProjectController will not provide CSRF protection for the show method.&lt;br /&gt;
&lt;br /&gt;
   class ProjectController &amp;lt; ApplicationController&lt;br /&gt;
       protect_from_forgery :except =&amp;gt; :show&lt;br /&gt;
&lt;br /&gt;
Also note that by default Rails does not provide CSRF protection for any HTTP GET request.&lt;br /&gt;
&lt;br /&gt;
There is a top level OWASP page for [https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29 CSRF].&lt;br /&gt;
&lt;br /&gt;
== Mass Assignment and Strong Parameters == &lt;br /&gt;
&lt;br /&gt;
Although the major issue with Mass Assignment has been fixed by default in base Rails specifically when generating new projects, it still applies to older and upgraded projects so it is important to understand the issue and to ensure that only attributes that are intended to be modifiable are exposed.&lt;br /&gt;
&lt;br /&gt;
When working with a model, the attributes on the model will not be accessible to forms being posted unless a programmer explicitly indicates that:&lt;br /&gt;
&lt;br /&gt;
    class Project &amp;lt; ActiveRecord::Base&lt;br /&gt;
        attr_accessible :name, :admin&lt;br /&gt;
    end&lt;br /&gt;
&lt;br /&gt;
With the admin attribute accessible based on the example above, the following could work:&lt;br /&gt;
&lt;br /&gt;
    curl -d “project[name]=triage&amp;amp;project[admin]=1” host:port/projects&lt;br /&gt;
&lt;br /&gt;
Review accessible attributes to ensure that they should be accessible.  If you are working in Rails &amp;lt; 3.2.3 you should ensure that your attributes are whitelisted with the following:&lt;br /&gt;
&lt;br /&gt;
    config.active_record.whitelist_attributes = true&lt;br /&gt;
&lt;br /&gt;
In Rails 4.0 strong parameters will be the recommended approach for handling attribute visibility. It is also possible to use the strong_parameters gem with Rails 3.x, and the strong_parameters_rails2 gem for Rails 2.3.x applications.&lt;br /&gt;
&lt;br /&gt;
== Redirects and Forwards == &lt;br /&gt;
&lt;br /&gt;
Web applications often require the ability to dynamically redirect users based on client-supplied data. To clarify, dynamic redirection usually entails the client including a URL in a parameter within a request to the application. Once received by the application, the user is redirected to the URL specified in the request. For example:&lt;br /&gt;
&lt;br /&gt;
http://www.example.com/redirect?url=http://www.example_commerce_site.com/checkout&lt;br /&gt;
&lt;br /&gt;
The above request would redirect the user to http://www.example.com/checkout.  The security concern associated with this functionality is leveraging an organization’s trusted brand to phish users and trick them into visiting a malicious site, in our example, “badhacker.com”.  Example:&lt;br /&gt;
&lt;br /&gt;
http://www.example.com/redirect?url=http://badhacker.com&lt;br /&gt;
&lt;br /&gt;
The most basic, but restrictive protection is to use the :only_path option. Setting this to true will essentially strip out any host information.&lt;br /&gt;
&lt;br /&gt;
    redirect_to params[:url], :only_path =&amp;gt; true&lt;br /&gt;
&lt;br /&gt;
If matching user input against a list of approved sites or TLDs against regular expression is a must, it makes sense to leverage a library such as URI.parse() to obtain the host and then take the host value and match it against regular expression patterns. Those regular expressions must, at a minimum, have anchors or there is a greater chance of an attacker bypassing the validation routine.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
    require ‘uri’&lt;br /&gt;
    host = URI.parse(“#{params[:url]}”).host&lt;br /&gt;
    validation_routine(host) if host    # this can be vulnerable to javascript://trusted.com/%0Aalert(0) so check .scheme and .port too&lt;br /&gt;
    def validation_routine(host)&lt;br /&gt;
        # Validation routine where we use  \A and \z as anchors *not* ^ and $&lt;br /&gt;
        # you could also check the host value against a whitelist&lt;br /&gt;
    end&lt;br /&gt;
&lt;br /&gt;
Also blind redirecting to user input parameter can lead to XSS. Example:&lt;br /&gt;
    redirect_to params[:to]&lt;br /&gt;
    &lt;br /&gt;
    http://example.com/redirect?to[status]=200&amp;amp;to[protocol]=javascript:alert(0)//&lt;br /&gt;
&lt;br /&gt;
The obvious fix for this type of vulnerability is to restrict to specific Top-Level Domains (TLDs), statically define specific sites, or map a key to it’s value. Example:&lt;br /&gt;
&lt;br /&gt;
    ACCEPTABLE_URLS = {&lt;br /&gt;
        ‘our_app_1’ =&amp;gt; “https://www.example_commerce_site.com/checkout”,&lt;br /&gt;
        ‘our_app_2’ =&amp;gt; “https://www.example_user_site.com/change_settings”&lt;br /&gt;
    }&lt;br /&gt;
&lt;br /&gt;
http://www.example.com/redirect?url=our_app_1&lt;br /&gt;
&lt;br /&gt;
   def redirect&lt;br /&gt;
       url = ACCEPTABLE_URLS[“#{params[:url]}”]&lt;br /&gt;
       redirect_to url if url&lt;br /&gt;
   end&lt;br /&gt;
&lt;br /&gt;
There is a more general OWASP resource about [https://www.owasp.org/index.php/Unvalidated_Redirects_and_Forwards_Cheat_Sheet Unvalidated Redirects and Forwards].&lt;br /&gt;
&lt;br /&gt;
== Dynamic Render Paths == &lt;br /&gt;
&lt;br /&gt;
In Rails, controller actions and views can dynamically determine which view or partial to render by calling the “render” method. If user input is used in or for the template name, an attacker could cause the application to render an arbitrary view, such as an administrative page.&lt;br /&gt;
&lt;br /&gt;
Care should be taken when using user input to determine which view to render. If possible, avoid any user input in the name or path to the view.&lt;br /&gt;
&lt;br /&gt;
== Cross Origin Resource Sharing ==&lt;br /&gt;
&lt;br /&gt;
Occasionally, a need arises to share resources with another domain. For example, a file-upload function that sends data via an AJAX request to another domain. In these cases, the same-origin rules followed by web browsers must be bent. Modern browsers, in compliance with HTML5 standards, will allow this to occur but in order to do this; a couple precautions must be taken.&lt;br /&gt;
&lt;br /&gt;
When using a nonstandard HTTP construct, such as an atypical Content-Type header, for example, the following applies:&lt;br /&gt;
&lt;br /&gt;
The receiving site should whitelist only those domains allowed to make such requests as well as set the Access-Control-Allow-Origin header in both the response to the OPTIONS request and POST request. This is because the OPTIONS request is sent first, in order to determine if the remote or receiving site allows the requesting domain. Next, a second request, a POST request, is sent. Once again, the header must be set in order for the transaction to be shown as successful.&lt;br /&gt;
&lt;br /&gt;
When standard HTTP constructs are used:&lt;br /&gt;
&lt;br /&gt;
The request is sent and the browser, upon receiving a response, inspects the response headers in order to determine if the response can and should be processed.&lt;br /&gt;
&lt;br /&gt;
Whitelist in Rails:&lt;br /&gt;
&lt;br /&gt;
Gemfile&lt;br /&gt;
    gem 'rack-cors', :require =&amp;gt; 'rack/cors'&lt;br /&gt;
&lt;br /&gt;
config/application.rb&lt;br /&gt;
    module Sample&lt;br /&gt;
        class Application &amp;lt; Rails::Application&lt;br /&gt;
            config.middleware.use Rack::Cors do&lt;br /&gt;
                allow do&lt;br /&gt;
                    origins 'someserver.example.com'&lt;br /&gt;
                    resource %r{/users/\d+.json},&lt;br /&gt;
                        :headers =&amp;gt; ['Origin', 'Accept', 'Content-Type'],&lt;br /&gt;
                        :methods =&amp;gt; [:post, :get]&lt;br /&gt;
                end&lt;br /&gt;
            end&lt;br /&gt;
        end&lt;br /&gt;
    end&lt;br /&gt;
&lt;br /&gt;
== Security-related headers ==&lt;br /&gt;
&lt;br /&gt;
To set a header value, simply access the response.headers object as a hash inside your controller (often in a before/after_filter).&lt;br /&gt;
&lt;br /&gt;
  response.headers['X-header-name'] = 'value'&lt;br /&gt;
&lt;br /&gt;
'''Rails 4''' provides the &amp;quot;default_headers&amp;quot; functionality that will automatically apply the values supplied. This works for most headers in almost all cases.&lt;br /&gt;
&lt;br /&gt;
  ActionDispatch::Response.default_headers = {	  	&lt;br /&gt;
    'X-Frame-Options' =&amp;gt; 'DENY', 	&lt;br /&gt;
    'X-Content-Type-Options' =&amp;gt; 'nosniff',	  	&lt;br /&gt;
    'X-XSS-Protection' =&amp;gt; '1;'&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
Strict transport security is a special case, it is set in an environment file (e.g. production.rb)&lt;br /&gt;
&lt;br /&gt;
  config.force_ssl = true&lt;br /&gt;
&lt;br /&gt;
For those not on the edge, there is a library ([https://github.com/twitter/secureheaders secure_headers]) for the same behavior with content security policy abstraction provided. It will automatically apply logic based on the user agent to produce a concise set of headers.&lt;br /&gt;
&lt;br /&gt;
== Business Logic Bugs ==&lt;br /&gt;
&lt;br /&gt;
Any application in any technology can contain business logic errors that result in security bugs.  Business logic bugs are difficult to impossible to detect using automated tools.  The best ways to prevent business logic security bugs are to do code review, pair program and write unit tests.&lt;br /&gt;
&lt;br /&gt;
== Attack Surface == &lt;br /&gt;
&lt;br /&gt;
Generally speaking, Rails avoids open redirect and path traversal types of vulnerabilities because of its /config/routes.rb file which dictates what URL’s should be accessible and handled by which controllers.  The routes file is a great place to look when thinking about the scope of the attack surface.  An example might be as follows:&lt;br /&gt;
&lt;br /&gt;
    match ':controller(/:action(/:id(.:format)))' # this is an example of what NOT to do&lt;br /&gt;
&lt;br /&gt;
In this case, this route allows any public method on any controller to be called as an action.  As a developer, you want to make sure that users can only reach the controller methods intended and in the way intended.&lt;br /&gt;
&lt;br /&gt;
== Sensitive Files == &lt;br /&gt;
&lt;br /&gt;
Many Ruby on Rails apps are open source and hosted on publicly available source code repositories.  Whether that is the case or the code is committed to a corporate source control system, there are certain files that should be either excluded or carefully managed.&lt;br /&gt;
&lt;br /&gt;
    /config/database.yml                 -  May contain production credentials.&lt;br /&gt;
    /config/initializers/secret_token.rb -  Contains a secret used to hash session cookie.&lt;br /&gt;
    /db/seeds.rb                         -  May contain seed data including bootstrap admin user.&lt;br /&gt;
    /db/development.sqlite3              -  May contain real data. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Encryption == &lt;br /&gt;
&lt;br /&gt;
Rails uses OS encryption.  Generally speaking, it is always a bad idea to write your own encryption.&lt;br /&gt;
&lt;br /&gt;
Devise by default uses bcrypt for password hashing, which is an appropriate solution.  Typically, the following config causes the 10 stretches for production:  /config/initializers/devise.rb&lt;br /&gt;
&lt;br /&gt;
    config.stretches = Rails.env.test? ? 1 : 10&lt;br /&gt;
&lt;br /&gt;
= Updating Rails and Having a Process for Updating Dependencies = &lt;br /&gt;
&lt;br /&gt;
In early 2013, a number of critical vulnerabilities were identified in the Rails Framework.  Organizations that had fallen behind current versions had more trouble updating and harder decisions along the way, including patching the source code for the framework itself.&lt;br /&gt;
&lt;br /&gt;
An additional concern with Ruby applications in general is that most libraries (gems) are not signed by their authors.  It is literally impossible to build a Rails based project with libraries that come from trusted sources.  One good practice might be to audit the gems you are using.&lt;br /&gt;
&lt;br /&gt;
In general, it is important to have a process for updating dependencies.  An example process might define three mechanisms for triggering an update of response: &lt;br /&gt;
* Every month/quarter dependencies in general are updated.&lt;br /&gt;
* Every week important security vulnerabilities are taken into account and potentially trigger an update.&lt;br /&gt;
* In EXCEPTIONAL conditions, emergency updates may need to be applied.&lt;br /&gt;
&lt;br /&gt;
= Tools =&lt;br /&gt;
&lt;br /&gt;
Use [http://brakemanscanner.org/ brakeman], an open source code analysis tool for Rails applications, to identify many potential issues.  It will not necessarily produce comprehensive security findings, but it can find easily exposed issues.  A great way to see potential issues in Rails is to review the brakeman documentation of warning types.&lt;br /&gt;
&lt;br /&gt;
There are emerging tools that can be used to track security issues in dependency sets, like https://gemcanary.com/ and https://gemnasium.com/.&lt;br /&gt;
&lt;br /&gt;
Another area of tooling is the security testing tool [http://gauntlt.org Gauntlt] which is built on cucumber and uses gherkin syntax to define attack files.&lt;br /&gt;
&lt;br /&gt;
Launched in May 2013 and very similiar to brakeman scanner, the [http://rubygems.org/gems/codesake-dawn codesake-dawn] rubygem is a static analyzer for security issues that work with Rails, Sinatra and Padrino web applications. Version 0.60 has more than 30 ruby specific cve security checks and future releases custom checks against Cross Site Scripting and SQL Injections will be added&lt;br /&gt;
&lt;br /&gt;
= Authors and Primary Editors = &lt;br /&gt;
Matt Konda - mkonda [at] jemurai.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Neil Matatall neil [at] matatall.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Ken Johnson cktricky [at] gmail.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Justin Collins justin [at] presidentbeef.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Jon Rose - jrose400 [at] gmail.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Lance Vaughn - lance [at] cabforward.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Jon Claudius - jonathan.claudius [at] gmail.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Jim Manico jim [at] owasp.org&amp;lt;br/&amp;gt;&lt;br /&gt;
Aaron Bedra aaron [at] aaronbedra.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Egor Homakov homakov [at] gmail.com&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Related Articles and References = &lt;br /&gt;
&lt;br /&gt;
* [http://guides.rubyonrails.org/security.html The Official Rails Security Guide]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Ruby_on_Rails_Security_Guide_V2 OWASP Ruby on Rails Security Guide]&lt;br /&gt;
* [http://code.google.com/p/ruby-security/wiki/Guide The Ruby Security Reviewers Guide]&lt;br /&gt;
* [https://groups.google.com/forum/?fromgroups#!forum/rubyonrails-security The Ruby on Rails Security Mailing List]&lt;br /&gt;
* [http://blog.codeclimate.com/blog/2013/03/27/rails-insecure-defaults/ Rails Insecure Defaults]&lt;br /&gt;
&lt;br /&gt;
= Other Cheatsheets =&lt;br /&gt;
{{Cheatsheet_Navigation}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Cheatsheets]]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/Owasp_Esapi_Ruby&amp;diff=106517</id>
		<title>Projects/Owasp Esapi Ruby</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/Owasp_Esapi_Ruby&amp;diff=106517"/>
				<updated>2011-03-09T13:22:37Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Project About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = Owasp Esapi Ruby&lt;br /&gt;
| project_home_page = Category:OWASP Enterprise Security API&lt;br /&gt;
| project_description = The Owasp Esapi Ruby is a port for outstanding release quality Owasp Esapi project to the Ruby programming language. The idea is to build a Ruby gem (the standard ruby library archive format) containing the Esapi concepts implemented in Ruby classes so people using Ruby in their Rails application can have security into them.&lt;br /&gt;
| project_license = [http://en.wikipedia.org/wiki/BSD_license BSD license]&lt;br /&gt;
| leader_name1 = Paolo Perego&lt;br /&gt;
| leader_email1 = thesp0nge@owasp.org&lt;br /&gt;
| leader_username1 = thesp0nge&lt;br /&gt;
| contributor_name1 = Kuai Hinojosa &lt;br /&gt;
| contributor_email1 =  kuai.hinojosa@owasp.org&lt;br /&gt;
| contributor_username1 = Webappsecguy  &lt;br /&gt;
| contributor_name2 = Sal Scotto&lt;br /&gt;
| contributor_email2 = sal.scotto@gmail.com&lt;br /&gt;
| contributor_username2 =&lt;br /&gt;
| contributor_name3 = Paco Schiaffella&lt;br /&gt;
| contributor_email3 = schiaffella@gmail.com&lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link =&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-esapi-ruby&lt;br /&gt;
| project_road_map = http://www.owasp.org/index.php/Projects/Owasp_Esapi_Ruby/Roadmap&lt;br /&gt;
| links_url1 = http://github.com/thesp0nge/owasp-esapi-ruby&lt;br /&gt;
| links_name1 = Github (source code) &lt;br /&gt;
| links_url2 = http://thesp0nge.github.com/owasp-esapi-ruby/&lt;br /&gt;
| links_name2 = The home page&lt;br /&gt;
| release_1 = &lt;br /&gt;
| release_2 = &lt;br /&gt;
| release_3 =&lt;br /&gt;
| release_4 =&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/Owasp_Esapi_Ruby/Releases/Current&amp;diff=106516</id>
		<title>Projects/Owasp Esapi Ruby/Releases/Current</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/Owasp_Esapi_Ruby/Releases/Current&amp;diff=106516"/>
				<updated>2011-03-09T13:22:05Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: Created page with &amp;quot;[https://rubygems.org/gems/owasp-esapi-ruby/versions/0.30.0 v0.30.0]&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[https://rubygems.org/gems/owasp-esapi-ruby/versions/0.30.0 v0.30.0]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/Owasp_Esapi_Ruby&amp;diff=106515</id>
		<title>Projects/Owasp Esapi Ruby</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/Owasp_Esapi_Ruby&amp;diff=106515"/>
				<updated>2011-03-09T13:21:31Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Project About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = Owasp Esapi Ruby&lt;br /&gt;
| project_home_page = Category:OWASP Enterprise Security API&lt;br /&gt;
| project_description = The Owasp Esapi Ruby is a port for outstanding release quality Owasp Esapi project to the Ruby programming language. The idea is to build a Ruby gem (the standard ruby library archive format) containing the Esapi concepts implemented in Ruby classes so people using Ruby in their Rails application can have security into them.&lt;br /&gt;
| project_license = [http://en.wikipedia.org/wiki/BSD_license BSD license]&lt;br /&gt;
| leader_name1 = Paolo Perego&lt;br /&gt;
| leader_email1 = thesp0nge@owasp.org&lt;br /&gt;
| leader_username1 = thesp0nge&lt;br /&gt;
| contributor_name1 = Kuai Hinojosa &lt;br /&gt;
| contributor_email1 =  kuai.hinojosa@owasp.org&lt;br /&gt;
| contributor_username1 = Webappsecguy  &lt;br /&gt;
| contributor_name2 = Sal Scotto&lt;br /&gt;
| contributor_email2 = sal.scotto@gmail.com&lt;br /&gt;
| contributor_username2 =&lt;br /&gt;
| contributor_name3 = Paco Schiaffella&lt;br /&gt;
| contributor_email3 = schiaffella@gmail.com&lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link =&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-esapi-ruby&lt;br /&gt;
| project_road_map = http://www.owasp.org/index.php/Projects/Owasp_Esapi_Ruby/Roadmap&lt;br /&gt;
| links_url1 = http://github.com/thesp0nge/owasp-esapi-ruby&lt;br /&gt;
| links_name1 = Github (source code) &lt;br /&gt;
| links_url2 = http://thesp0nge.github.com/owasp-esapi-ruby/&lt;br /&gt;
| links_name2 = The home page&lt;br /&gt;
| release_1 = [https://rubygems.org/gems/owasp-esapi-ruby/versions/0.30.0 v0.30.0]&lt;br /&gt;
| release_2 = &lt;br /&gt;
| release_3 =&lt;br /&gt;
| release_4 =&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/Owasp_Esapi_Ruby&amp;diff=105237</id>
		<title>Projects/Owasp Esapi Ruby</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/Owasp_Esapi_Ruby&amp;diff=105237"/>
				<updated>2011-02-16T08:19:07Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Project About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = Owasp Esapi Ruby&lt;br /&gt;
| project_home_page = Category:OWASP Enterprise Security API&lt;br /&gt;
| project_description = The Owasp Esapi Ruby is a port for outstanding release quality Owasp Esapi project to the Ruby programming language. The idea is to build a Ruby gem (the standard ruby library archive format) containing the Esapi concepts implemented in Ruby classes so people using Ruby in their Rails application can have security into them.&lt;br /&gt;
| project_license = [http://en.wikipedia.org/wiki/BSD_license BSD license]&lt;br /&gt;
| leader_name1 = Paolo Perego&lt;br /&gt;
| leader_email1 = thesp0nge@owasp.org&lt;br /&gt;
| leader_username1 = thesp0nge&lt;br /&gt;
| contributor_name1 = Kuai Hinojosa &lt;br /&gt;
| contributor_email1 =  kuai.hinojosa@owasp.org&lt;br /&gt;
| contributor_username1 = Webappsecguy  &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 =&lt;br /&gt;
| contributor_name3 = Paco Schiaffella&lt;br /&gt;
| contributor_email3 = schiaffella@gmail.com&lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = Sal Scotto&lt;br /&gt;
| contributor_email4 = sal.scotto@gmail.com&lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link =&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-esapi-ruby&lt;br /&gt;
| project_road_map = http://www.owasp.org/index.php/Projects/Owasp_Esapi_Ruby/Roadmap&lt;br /&gt;
| links_url1 = http://github.com/thesp0nge/owasp-esapi-ruby&lt;br /&gt;
| links_name1 = Github (source code) &lt;br /&gt;
| links_url2 = http://thesp0nge.github.com/owasp-esapi-ruby/&lt;br /&gt;
| links_name2 = The home page&lt;br /&gt;
| release_1 = &lt;br /&gt;
| release_2 = &lt;br /&gt;
| release_3 =&lt;br /&gt;
| release_4 =&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/Owasp_Esapi_Ruby&amp;diff=105118</id>
		<title>Projects/Owasp Esapi Ruby</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/Owasp_Esapi_Ruby&amp;diff=105118"/>
				<updated>2011-02-15T12:30:15Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Project About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = Owasp Esapi Ruby&lt;br /&gt;
| project_home_page = Category:OWASP Enterprise Security API&lt;br /&gt;
| project_description = The Owasp Esapi Ruby is a port for outstanding release quality Owasp Esapi project to the Ruby programming language. The idea is to build a Ruby gem (the standard ruby library archive format) containing the Esapi concepts implemented in Ruby classes so people using Ruby in their Rails application can have security into them.&lt;br /&gt;
| project_license = [http://en.wikipedia.org/wiki/BSD_license BSD license]&lt;br /&gt;
| leader_name1 = Paolo Perego&lt;br /&gt;
| leader_email1 = thesp0nge@owasp.org&lt;br /&gt;
| leader_username1 = thesp0nge&lt;br /&gt;
| contributor_name1 = Kuai Hinojosa &lt;br /&gt;
| contributor_email1 =  kuai.hinojosa@owasp.org&lt;br /&gt;
| contributor_username1 = Webappsecguy  &lt;br /&gt;
| contributor_name2 = Daniele Bellucci&lt;br /&gt;
| contributor_email2 = daniele.bellucci@gmail.com &lt;br /&gt;
| contributor_username2 =&lt;br /&gt;
| contributor_name3 = Paco Schiaffella&lt;br /&gt;
| contributor_email3 = schiaffella@gmail.com&lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = Sal Scotto&lt;br /&gt;
| contributor_email4 = sal.scotto@gmail.com&lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link =&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-esapi-ruby&lt;br /&gt;
| project_road_map = http://www.owasp.org/index.php/Projects/Owasp_Esapi_Ruby/Roadmap&lt;br /&gt;
| links_url1 = http://github.com/thesp0nge/owasp-esapi-ruby&lt;br /&gt;
| links_name1 = Github (source code) &lt;br /&gt;
| links_url2 = http://thesp0nge.github.com/owasp-esapi-ruby/&lt;br /&gt;
| links_name2 = The home page&lt;br /&gt;
| release_1 = &lt;br /&gt;
| release_2 = &lt;br /&gt;
| release_3 =&lt;br /&gt;
| release_4 =&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011/Open_letter_to_WebAppSec_Tool_and_Services_vendors:_Release_your_schemas_and_allow_automation&amp;diff=104042</id>
		<title>Summit 2011/Open letter to WebAppSec Tool and Services vendors: Release your schemas and allow automation</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011/Open_letter_to_WebAppSec_Tool_and_Services_vendors:_Release_your_schemas_and_allow_automation&amp;diff=104042"/>
				<updated>2011-02-07T09:08:55Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: /* Signed by */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;BR&amp;gt;__TOC__&amp;lt;BR&amp;gt;&lt;br /&gt;
'''IMPORTANT DISCLAIMER: THIS LETTER IS NOT AN OFFICIAL OWASP POSITION. THE OWNERSHIP OF ITS REQUEST BELONGS TO THE NAMES UNDER THE 'SIGNED BY' SECTION'''&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
{{:Summit_2011/Open_letter_to_WebAppSec_Tool_and_Services_vendors:_Release_your_schemas_and_allow_automation/Letter_Content}}&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
==Signed by==&lt;br /&gt;
* Dinis Cruz - Application Security Consultant - Independent&lt;br /&gt;
* Sebastien Deleersnyder - Managing Technical Consultant - SAIT Zenitel&lt;br /&gt;
* Jim Manico - CEO - Infrared Security&lt;br /&gt;
* Alexander Meisel - CTO - art of defence&lt;br /&gt;
* Sven Vetsch - Senior Security Tester - Dreamlab Technologies&lt;br /&gt;
* Daniel Cuthbert - Assessment Manager - SensePost&lt;br /&gt;
* Eoin Keary - EMEIA Attack &amp;amp; Penetration Senior Manager - Ernst &amp;amp; Young&lt;br /&gt;
* Anurag Agarwal - Founder - MyAppSecurity&lt;br /&gt;
* Zaki Akhmad - Security Analyst - indocisc&lt;br /&gt;
* Sebastien Gioria - Head of Security and IT Audit - Groupe Y&lt;br /&gt;
* Paolo Perego - Application Security Specialist - armoredcode.com&lt;br /&gt;
&lt;br /&gt;
Please use the format: {Name - Role - Company}&lt;br /&gt;
&lt;br /&gt;
==Vendors that commit to deliver the requested materials==&lt;br /&gt;
* art of defence&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Thesp0nge&amp;diff=103336</id>
		<title>User:Thesp0nge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Thesp0nge&amp;diff=103336"/>
				<updated>2011-02-04T11:08:40Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Paolo was born in 1976 in Milan, Italy. Since he was 5, he started disassembling toys trying to understand their internals... it was very rare he was able to put the pieces back in their place. So his infancy was full of broken toys... but at least he discovered what's inside a little car moving by itself.&lt;br /&gt;
Let's call this Paolo's life phase: 'Breaking the law'&lt;br /&gt;
&lt;br /&gt;
When he discovered computers, Paolo learnt also to repair software he broke. He started patching buffer overflows, format bugs and other crappy C programs. It was 1996, he discovered Linux, the networking and the kernel land. It was the time Pink Floyd were in loop in Paolo's walkman.&lt;br /&gt;
Let's call this Paolo's life phase: 'So your instruction pointer is full of 0x41?'&lt;br /&gt;
&lt;br /&gt;
Nowadays Paolo's interest in reviewing and fixing broken code turn him in an application security specialist. He wrote software for an Italian web agency, and he has a side project as Independent Software Vendor as [http://www.armoredcode.com armoredcode.com]. He is involved in Owasp as Project Leader of [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Orizon Owasp Orizon (a code review engine)] and [http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Ruby Owasp Esapi for Ruby Owasp ESAPI for Ruby porting]. He is also in the Owasp Italian chapter board. It's the time that Pearl Jam and old school metal music fill Paolo's mp3 player, he is an husband, a proud father, a guitarist and he is close from being black belt Taekwon-do ITF martial artists.&lt;br /&gt;
Let's call this Paolo's life phase: 'Stay hungry, stay foolish'&lt;br /&gt;
&lt;br /&gt;
You can reach me by email: thesp0nge_at_owasp.org or you can add thesp0nge_at_gmail.com as GTalk buddy.&lt;br /&gt;
&lt;br /&gt;
Here it is my Linkedin [http://www.linkedin.com/in/thesp0nge profile]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Thesp0nge&amp;diff=103335</id>
		<title>User:Thesp0nge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Thesp0nge&amp;diff=103335"/>
				<updated>2011-02-04T11:07:51Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Paolo was born in 1976 in Milan, Italy. Since he was 5, he started disassembling toys trying to understand their internals... it was very rare he was able to put the pieces back in their place. So his infancy was full of broken toys... but at least he discovered what's inside a little car moving by itself.&lt;br /&gt;
Let's call this Paolo's life phase: 'Breaking the law'&lt;br /&gt;
&lt;br /&gt;
When he discovered computers, Paolo learnt also to repair software he broke. He started patching buffer overflows, format bugs and other crappy C programs. It was 1996, he discovered Linux, the networking and the kernel land. It was the time Pink Floyd were in loop in Paolo's walkman.&lt;br /&gt;
Let's call this Paolo's life phase: 'So your instruction pointer is full of 0x41?'&lt;br /&gt;
&lt;br /&gt;
Nowadays Paolo's interest in reviewing and fixing broken code turn him in an application security specialist. He wrote software for an Italian web agency, and he has a side project as Independent Software Vendor as [armoredcode.com]. He is involved in Owasp as Project Leader of [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Orizon Owasp Orizon (a code review engine)] and [http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Ruby Owasp Esapi for Ruby Owasp ESAPI for Ruby porting]. He is also in the Owasp Italian chapter board. It's the time that Pearl Jam and old school metal music fill Paolo's mp3 player, he is an husband, a proud father, a guitarist and he is close from being black belt Taekwon-do ITF martial artists.&lt;br /&gt;
Let's call this Paolo's life phase: 'Stay hungry, stay foolish'&lt;br /&gt;
&lt;br /&gt;
You can reach me by email: thesp0nge_at_owasp.org or you can add thesp0nge_at_gmail.com as GTalk buddy.&lt;br /&gt;
&lt;br /&gt;
Here it is my Linkedin [http://www.linkedin.com/in/thesp0nge profile]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session039&amp;diff=103112</id>
		<title>Summit 2011 Working Sessions/Session039</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session039&amp;diff=103112"/>
				<updated>2011-02-02T18:30:33Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Summit 2011 Working Sessions test tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name1 = Dinis Cruz&lt;br /&gt;
| summit_session_attendee_email1 = dinis.cruz@owasp.org&lt;br /&gt;
| summit_session_attendee_username1 = &lt;br /&gt;
| summit_session_attendee_company1=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name2 = Matthew Chalmers&lt;br /&gt;
| summit_session_attendee_email2 = matthew.chalmers@owasp.org&lt;br /&gt;
| summit_session_attendee_username2 = &lt;br /&gt;
| summit_session_attendee_company2=[http://www.rockwellautomation.com/ http://www.rockwellautomation.com/lib/images/ralogo_web.gif]&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name3 = Mateo Martinez&lt;br /&gt;
| summit_session_attendee_email3 = mateo.martinez@owasp.org&lt;br /&gt;
| summit_session_attendee_username3 = &lt;br /&gt;
| summit_session_attendee_company3=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name4 = Jeremy Long&lt;br /&gt;
| summit_session_attendee_email4 = jeremy.long@owasp.org&lt;br /&gt;
| summit_session_attendee_username4 = &lt;br /&gt;
| summit_session_attendee_company4=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name5 = Matteo Meucci&lt;br /&gt;
| summit_session_attendee_email5 = matteo.meucci@owasp.org&lt;br /&gt;
| summit_session_attendee_username5 = &lt;br /&gt;
| summit_session_attendee_company5= Minded Security&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name6 = Seba Deleersnyder&lt;br /&gt;
| summit_session_attendee_email6 = seba@owasp.org&lt;br /&gt;
| summit_session_attendee_username6 = &lt;br /&gt;
| summit_session_attendee_company6= SAIT Zenitel&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name7 = Daniel Brzozowski&lt;br /&gt;
| summit_session_attendee_email7 = daniel@brzozowski.biz&lt;br /&gt;
| summit_session_attendee_username7 = Daniel Brzozowski&lt;br /&gt;
| summit_session_attendee_company7=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name8 = Paolo Perego &lt;br /&gt;
| summit_session_attendee_email8 = thesp0nge@owasp.org&lt;br /&gt;
| summit_session_attendee_username8 = thesp0nge&lt;br /&gt;
| summit_session_attendee_company8= Armoredcode.com&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name9 = &lt;br /&gt;
| summit_session_attendee_email9 = &lt;br /&gt;
| summit_session_attendee_username9 = &lt;br /&gt;
| summit_session_attendee_company9=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name10 = &lt;br /&gt;
| summit_session_attendee_email10 = &lt;br /&gt;
| summit_session_attendee_username10 = &lt;br /&gt;
| summit_session_attendee_company10=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name11 = &lt;br /&gt;
| summit_session_attendee_email11 = &lt;br /&gt;
| summit_session_attendee_username11 = &lt;br /&gt;
| summit_session_attendee_company11=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name12 = &lt;br /&gt;
| summit_session_attendee_email12 = &lt;br /&gt;
| summit_session_attendee_username12 = &lt;br /&gt;
| summit_session_attendee_company12=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name13 = &lt;br /&gt;
| summit_session_attendee_email13 = &lt;br /&gt;
| summit_session_attendee_username13 = &lt;br /&gt;
| summit_session_attendee_company13=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name14 = &lt;br /&gt;
| summit_session_attendee_email14 = &lt;br /&gt;
| summit_session_attendee_username14 = &lt;br /&gt;
| summit_session_attendee_company14=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14= &lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name15 = &lt;br /&gt;
| summit_session_attendee_email15 = &lt;br /&gt;
| summit_session_attendee_username15 = &lt;br /&gt;
| summit_session_attendee_company15=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name16 = &lt;br /&gt;
| summit_session_attendee_email16 = &lt;br /&gt;
| summit_session_attendee_username16 = &lt;br /&gt;
| summit_session_attendee_company16=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name17 = &lt;br /&gt;
| summit_session_attendee_email17 = &lt;br /&gt;
| summit_session_attendee_username17 = &lt;br /&gt;
| summit_session_attendee_company17=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name18 = &lt;br /&gt;
| summit_session_attendee_email18 = &lt;br /&gt;
| summit_session_attendee_username18 = &lt;br /&gt;
| summit_session_attendee_company18=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name19 = &lt;br /&gt;
| summit_session_attendee_email19 = &lt;br /&gt;
| summit_session_attendee_username19 = &lt;br /&gt;
| summit_session_attendee_company19=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name20 = &lt;br /&gt;
| summit_session_attendee_email20 = &lt;br /&gt;
| summit_session_attendee_username20 = &lt;br /&gt;
| summit_session_attendee_company20=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| summit_track_logo = [[Image:T._university.jpg]] &lt;br /&gt;
| summit_ws_logo = [[Image:WS._university.jpg]]&lt;br /&gt;
| summit_session_name = OWASP Certification&lt;br /&gt;
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session039&lt;br /&gt;
| mailing_list =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| short_working_session_description= This session aims to establish the model by which an certification/exam based on OWASP materials could be created. The topics of discussion will include: &lt;br /&gt;
* What is a workable/acceptable certification model for OWASP's Community?&lt;br /&gt;
* What types of certification should there be?&lt;br /&gt;
* What would a CC-licensed certification exam look like (as executed by others)?&lt;br /&gt;
* Since OWASP is not interested or able to administer certifications itself who could run/administer such CC certifications/exams?&lt;br /&gt;
* What should OWASP's official position be on entities that provide OWASP based certifications?&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| related_project_name1 = &lt;br /&gt;
| related_project_url_1 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name2 = &lt;br /&gt;
| related_project_url_2 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name3 = &lt;br /&gt;
| related_project_url_3 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name4 = &lt;br /&gt;
| related_project_url_4 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name5 = &lt;br /&gt;
| related_project_url_5 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name1 = Determine whether certification would have value for OWASP's Community&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name2 = Determine a model by which certification based on OWASP materials could succeed&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name3 = Determine a model for creation and distribution of a CC-licensed certification exam based on OWASP materials&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name4 = (if agreed) Determine a model for supporting the administration of certification based on OWASP Materials&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name5 =  &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_date_and_time = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| discussion_model = participants and attendees&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_resources = Projector, whiteboards, markers, Internet connectivity, power&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_additional_details = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name1 = A business plan for evaluation by the community at large.&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name2 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name3 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name4 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name5 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name6 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name7 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name8 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name1 = &lt;br /&gt;
| summit_session_leader_email1 = &lt;br /&gt;
| summit_session_leader_username1 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name2 = &lt;br /&gt;
| summit_session_leader_email2 = &lt;br /&gt;
| summit_session_leader_username2 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name3 = &lt;br /&gt;
| summit_session_leader_email3 = &lt;br /&gt;
| summit_session_leader_username3 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_leader_name1 =&lt;br /&gt;
| operational_leader_email1 =&lt;br /&gt;
| operational_leader_username1 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| meeting_notes = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| session_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Session039&lt;br /&gt;
| session_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Working_Sessions/Session039&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session089&amp;diff=103111</id>
		<title>Summit 2011 Working Sessions/Session089</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session089&amp;diff=103111"/>
				<updated>2011-02-02T18:29:32Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Summit 2011 Working Sessions test tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name1 = Dinis Cruz&lt;br /&gt;
| summit_session_attendee_email1 = dinis.cruz@owasp.org&lt;br /&gt;
| summit_session_attendee_username1 = &lt;br /&gt;
| summit_session_attendee_company1= Dinis.cruz&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name2 = Matthew Chalmers&lt;br /&gt;
| summit_session_attendee_email2 = matthew.chalmers@owasp.org&lt;br /&gt;
| summit_session_attendee_username2 = &lt;br /&gt;
| summit_session_attendee_company2=[http://www.rockwellautomation.com/ http://www.rockwellautomation.com/lib/images/ralogo_web.gif]&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name3 = Mateo Martinez&lt;br /&gt;
| summit_session_attendee_email3 = mateo.martinez@owasp.org&lt;br /&gt;
| summit_session_attendee_username3 = &lt;br /&gt;
| summit_session_attendee_company3=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name4 = Jeremy Long&lt;br /&gt;
| summit_session_attendee_email4 = jeremy.long@owasp.org&lt;br /&gt;
| summit_session_attendee_username4 = &lt;br /&gt;
| summit_session_attendee_company4=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name5 = Matteo Meucci&lt;br /&gt;
| summit_session_attendee_email5 = matteo.meucci@owasp.org&lt;br /&gt;
| summit_session_attendee_username5 = &lt;br /&gt;
| summit_session_attendee_company5= Minded Security&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name6 = Paolo Perego&lt;br /&gt;
| summit_session_attendee_email6 = thesp0nge@owasp.org&lt;br /&gt;
| summit_session_attendee_username6 = thesp0nge&lt;br /&gt;
| summit_session_attendee_company6= Armoredcode.com&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name7 = &lt;br /&gt;
| summit_session_attendee_email7 = &lt;br /&gt;
| summit_session_attendee_username7 = &lt;br /&gt;
| summit_session_attendee_company7=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name8 = &lt;br /&gt;
| summit_session_attendee_email8 = &lt;br /&gt;
| summit_session_attendee_username8 = &lt;br /&gt;
| summit_session_attendee_company8=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name9 = &lt;br /&gt;
| summit_session_attendee_email9 = &lt;br /&gt;
| summit_session_attendee_username9 = &lt;br /&gt;
| summit_session_attendee_company9=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name10 = &lt;br /&gt;
| summit_session_attendee_email10 = &lt;br /&gt;
| summit_session_attendee_username10 = &lt;br /&gt;
| summit_session_attendee_company10=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name11 = &lt;br /&gt;
| summit_session_attendee_email11 = &lt;br /&gt;
| summit_session_attendee_username11 = &lt;br /&gt;
| summit_session_attendee_company11=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name12 = &lt;br /&gt;
| summit_session_attendee_email12 = &lt;br /&gt;
| summit_session_attendee_username12 = &lt;br /&gt;
| summit_session_attendee_company12=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name13 = &lt;br /&gt;
| summit_session_attendee_email13 = &lt;br /&gt;
| summit_session_attendee_username13 = &lt;br /&gt;
| summit_session_attendee_company13=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name14 = &lt;br /&gt;
| summit_session_attendee_email14 = &lt;br /&gt;
| summit_session_attendee_username14 = &lt;br /&gt;
| summit_session_attendee_company14=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14= &lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name15 = &lt;br /&gt;
| summit_session_attendee_email15 = &lt;br /&gt;
| summit_session_attendee_username15 = &lt;br /&gt;
| summit_session_attendee_company15=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name16 = &lt;br /&gt;
| summit_session_attendee_email16 = &lt;br /&gt;
| summit_session_attendee_username16 = &lt;br /&gt;
| summit_session_attendee_company16=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name17 = &lt;br /&gt;
| summit_session_attendee_email17 = &lt;br /&gt;
| summit_session_attendee_username17 = &lt;br /&gt;
| summit_session_attendee_company17=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name18 = &lt;br /&gt;
| summit_session_attendee_email18 = &lt;br /&gt;
| summit_session_attendee_username18 = &lt;br /&gt;
| summit_session_attendee_company18=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name19 = &lt;br /&gt;
| summit_session_attendee_email19 = &lt;br /&gt;
| summit_session_attendee_username19 = &lt;br /&gt;
| summit_session_attendee_company19=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name20 = &lt;br /&gt;
| summit_session_attendee_email20 = &lt;br /&gt;
| summit_session_attendee_username20 = &lt;br /&gt;
| summit_session_attendee_company20=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| summit_track_logo = [[Image:T._university.jpg]] &lt;br /&gt;
| summit_ws_logo = [[Image:WS._university.jpg]]&lt;br /&gt;
| summit_session_name = OWASP Exams&lt;br /&gt;
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session089&lt;br /&gt;
| mailing_list =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| short_working_session_description= This session aims to establish the model by which the OWASP community can create and distribute CC-licensed exams for use by educators and trainers. The purpose of the exams is to improve the effectiveness of OWASP training through the use of exams as a means of measurement and  student progress tracking. The session will include discussion of CC-licensed exam creation, exam usage, numbers and types of exams and means by which the exams usage can be popularized and expanded. The session will also include a learning center and an exam center with pre-populated content so that session members can experience one possible model for training and exam usage and base discussion on that experience. Session members can also review an alpha CC-licensed exam and help to improve and extend the exam questions. &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| related_project_name1 = OWASP Exams Project&lt;br /&gt;
| related_project_url_1 = http://www.owasp.org/index.php/OWASP_Exams_Project&lt;br /&gt;
&lt;br /&gt;
| related_project_name2 = &lt;br /&gt;
| related_project_url_2 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name3 = &lt;br /&gt;
| related_project_url_3 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name4 = &lt;br /&gt;
| related_project_url_4 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name5 = &lt;br /&gt;
| related_project_url_5 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name1= Establish model for CC-licensed exams creation&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name2 = Establish model for CC-licensed exams distribution and usage&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name3 = Establish a first CC-licensed exam to test the concept (an alpha will be brought to the working session)&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name4 = Try OWASP training and exam end-to-end to experience and improve training and exam usage scenarios&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name5 =  &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_date_and_time = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| discussion_model = participants and attendees&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_resources = Projector, whiteboards, markers, Internet connectivity, power&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_additional_details = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name1 = A business plan for evaluation by the community at large. What is the investment, schedule, metrics, benefit…&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name2 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name3 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name4 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name5 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name6 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name7 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name8 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name1 = Jason Taylor&lt;br /&gt;
| summit_session_leader_email1 = jason.taylor@owasp.org&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name2 = &lt;br /&gt;
| summit_session_leader_email2 = &lt;br /&gt;
| summit_session_leader_username2 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name3 = &lt;br /&gt;
| summit_session_leader_email3 = &lt;br /&gt;
| summit_session_leader_username3 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_leader_name1 =&lt;br /&gt;
| operational_leader_email1 =&lt;br /&gt;
| operational_leader_username1 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| meeting_notes = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| session_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Session089&lt;br /&gt;
| session_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Working_Sessions/Session089&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session002&amp;diff=103110</id>
		<title>Summit 2011 Working Sessions/Session002</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session002&amp;diff=103110"/>
				<updated>2011-02-02T18:27:20Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Summit 2011 Working Sessions test tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name1 = John Wilander&lt;br /&gt;
| summit_session_attendee_email1 = john.wilander@owasp.org&lt;br /&gt;
| summit_session_attendee_username1 = John.wilander&lt;br /&gt;
| summit_session_attendee_company1=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name2 = Michael Coates&lt;br /&gt;
| summit_session_attendee_email2 = Michael.Coates@owasp.org&lt;br /&gt;
| summit_session_attendee_username2 = MichaelCoates&lt;br /&gt;
| summit_session_attendee_company2=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name3 =&lt;br /&gt;
| summit_session_attendee_email3 = &lt;br /&gt;
| summit_session_attendee_username3 = &lt;br /&gt;
| summit_session_attendee_company3=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name4 = Stefano Di Paola&lt;br /&gt;
| summit_session_attendee_email4 = &lt;br /&gt;
| summit_session_attendee_username4 =&lt;br /&gt;
| summit_session_attendee_company4=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name5 = Isaac Dawson&lt;br /&gt;
| summit_session_attendee_email5 = &lt;br /&gt;
| summit_session_attendee_username5 =&lt;br /&gt;
| summit_session_attendee_company5= Veracode&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name6 = Chris Eng&lt;br /&gt;
| summit_session_attendee_email6 = ceng@veracode.com&lt;br /&gt;
| summit_session_attendee_username6= &lt;br /&gt;
| summit_session_attendee_company6= Veracode&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name7 = Nishi Kumar&lt;br /&gt;
| summit_session_attendee_email7 = nishi.kumar@owasp.org&lt;br /&gt;
| summit_session_attendee_username7= &lt;br /&gt;
| summit_session_attendee_company7= FIS&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name8 = Elke Roth-Mandutz&lt;br /&gt;
| summit_session_attendee_email8 = elke.roth-mandutz@ohm-hochschule.de&lt;br /&gt;
| summit_session_attendee_username8= &lt;br /&gt;
| summit_session_attendee_company8=GSO-University of Applied Science&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name9 = Giorgio Fedon&lt;br /&gt;
| summit_session_attendee_email9 = &lt;br /&gt;
| summit_session_attendee_username9= gfedon&lt;br /&gt;
| summit_session_attendee_company9=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name10 = Paolo Perego&lt;br /&gt;
| summit_session_attendee_email10 = thesp0nge@owasp.org&lt;br /&gt;
| summit_session_attendee_username10= thesp0nge&lt;br /&gt;
| summit_session_attendee_company10= Armoredcode.com&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name11 = &lt;br /&gt;
| summit_session_attendee_email11 = &lt;br /&gt;
| summit_session_attendee_username11= &lt;br /&gt;
| summit_session_attendee_company11=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name12 = &lt;br /&gt;
| summit_session_attendee_email12 = &lt;br /&gt;
| summit_session_attendee_username12= &lt;br /&gt;
| summit_session_attendee_company12 =&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name13 = &lt;br /&gt;
| summit_session_attendee_email13 = &lt;br /&gt;
| summit_session_attendee_username13 = &lt;br /&gt;
| summit_session_attendee_company13=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name14 = &lt;br /&gt;
| summit_session_attendee_email14 = &lt;br /&gt;
| summit_session_attendee_username14= &lt;br /&gt;
| summit_session_attendee_company14=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14= &lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name15 = &lt;br /&gt;
| summit_session_attendee_email15 = &lt;br /&gt;
| summit_session_attendee_username15= &lt;br /&gt;
| summit_session_attendee_company15=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name16 = &lt;br /&gt;
| summit_session_attendee_email16 = &lt;br /&gt;
| summit_session_attendee_username16= &lt;br /&gt;
| summit_session_attendee_company16=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name17 = &lt;br /&gt;
| summit_session_attendee_email17 = &lt;br /&gt;
| summit_session_attendee_username17= &lt;br /&gt;
| summit_session_attendee_company17=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name18 = &lt;br /&gt;
| summit_session_attendee_email18 = &lt;br /&gt;
| summit_session_attendee_username18= &lt;br /&gt;
| summit_session_attendee_company18=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name19 = &lt;br /&gt;
| summit_session_attendee_email19 = &lt;br /&gt;
| summit_session_attendee_username19= &lt;br /&gt;
| summit_session_attendee_company19=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name20 = &lt;br /&gt;
| summit_session_attendee_email20 = &lt;br /&gt;
| summit_session_attendee_username20= &lt;br /&gt;
| summit_session_attendee_company20=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| summit_track_logo = [[Image:T._browser_security.jpg]]&lt;br /&gt;
| summit_ws_logo = [[Image:WS._browser_security.jpg]]&lt;br /&gt;
| summit_session_name = HTML5 Security&lt;br /&gt;
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session002&lt;br /&gt;
| mailing_list = https://groups.google.com/group/owasp-summit-browsersec&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| short_working_session_description= &lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| related_project_name1 = Browser Security Track - main page&lt;br /&gt;
| related_project_url_1 = http://www.owasp.org/index.php/Category:Summit_2011_Browser_Security_Track&lt;br /&gt;
&lt;br /&gt;
| related_project_name2 = Google Group for the Browser Security Track&lt;br /&gt;
| related_project_url_2 = https://groups.google.com/group/owasp-summit-browsersec&lt;br /&gt;
&lt;br /&gt;
| related_project_name3 = &lt;br /&gt;
| related_project_url_3 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name4 = &lt;br /&gt;
| related_project_url_4 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name5 = &lt;br /&gt;
| related_project_url_5 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name1= '''Handle autofocus in a unified and secure way'''.&amp;lt;noinclude&amp;gt; Make sure SOP applies for autofocus usage in frame/iframe'd websites. Re-discuss necessity for (future) attributes like this.&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name2 = '''Discuss necessity and capability for the HTML5 form controls'''.&amp;lt;noinclude&amp;gt; Do we need a non-SOP formaction attribute and why? &amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name3 = &amp;lt;noinclude&amp;gt;'''Goal I''':&amp;lt;/noinclude&amp;gt;  Initiate and create documentation and references for developers that address security issues. &amp;lt;noinclude&amp;gt;Html5sec.org is a start but impossible to continue or extend large scale without vendor help&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name4 = &amp;lt;noinclude&amp;gt;'''Goal II''':&amp;lt;/noinclude&amp;gt;Discuss and heavily restrict SVG capabilities - especially when deployed in CSS backgrounds and &amp;lt;img&amp;gt; tags. &amp;lt;noinclude&amp;gt;Mainly Opera and Mozilla are addressed here.&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name5 =   '''Long Term Goal(s)''': Provide a working and easy to use as well as vendor supported HTML5 compliant filter software such as HTMLPurifier. &amp;lt;noinclude&amp;gt;Browser vendors should participate in creating security software and filters - not undermine them as we could experience in the last decade.&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_date_and_time = Tuesday, 09 February &amp;lt;br&amp;gt; Time: TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| discussion_model = The working form will most probably be short presentations to frame the topic and then round table discussions. Depending on number of attendees we'll break into groups.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_resources = Projector, whiteboards, markers, Internet connectivity, power&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_additional_details = &amp;lt;br&amp;gt;&lt;br /&gt;
  &lt;br /&gt;
[[Image:Html5_mario_hackvertor.jpg‎‎]]&lt;br /&gt;
&lt;br /&gt;
===Co-chair Mario Heiderich===&lt;br /&gt;
Mario Heiderich works as a researcher for the Ruhr-University in Bochum, Germany and currently focuses on HTML5, SVG security and security implications of the ES5 specification draft. Mario invoked the [http://html5sec.org/ HTML5 security cheat-sheet] and maintains the [http://php-ids.org/ PHPIDS filter rules]. In his spare time he delivers trainings and security consultancy for larger German and international companies. He is also one of the co-authors of [http://www.amazon.com/Web-Application-Obfuscation-WAFs-Evasion-Filters-alert/dp/1597496049 Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-'] – a book on how an attacker would bypass different types of security controls including IDS/IPS.&lt;br /&gt;
&lt;br /&gt;
===Co-chair Gareth Heyes===&lt;br /&gt;
Gareth &amp;quot;Gaz&amp;quot; Heyes calls himself Chief Conspiracy theorist and is affiliated with Microsoft. He is the designer and developer behind [http://www.owasp.org/index.php/OWASP_JavaScript_Sandboxes#tab=JSReg JSReg] – a Javascript sandbox which converts code using regular expressions; [http://www.owasp.org/index.php/OWASP_JavaScript_Sandboxes#tab=HTMLReg HTMLReg] &amp;amp; [http://www.owasp.org/index.php/OWASP_JavaScript_Sandboxes#tab=CSSReg CSSReg] – converters of malicious HTML/CSS into a safe form of HTML. He is also one of the co-authors of [http://www.amazon.com/Web-Application-Obfuscation-WAFs-Evasion-Filters-alert/dp/1597496049 Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-'] – a book on how an attacker would bypass different types of security controls including IDS/IPS.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name1 =  Browser Security Report&lt;br /&gt;
|summit_session_deliverable_url_1 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name2 = Browser Security Priority Report&lt;br /&gt;
|summit_session_deliverable_url_2 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name3 = &lt;br /&gt;
|summit_session_deliverable_url_3 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name4 = &lt;br /&gt;
|summit_session_deliverable_url_4 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name5 = &lt;br /&gt;
|summit_session_deliverable_url_5 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name6 = &lt;br /&gt;
|summit_session_deliverable_url_6 =&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name7 = &lt;br /&gt;
|summit_session_deliverable_url_7 =&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name8 = &lt;br /&gt;
|summit_session_deliverable_url_8 =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name1 = Mario Heiderich&lt;br /&gt;
| summit_session_leader_email1 = &lt;br /&gt;
| summit_session_leader_username1 =&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name2 = Gareth Heyes&lt;br /&gt;
| summit_session_leader_email2 = gazheyes@gmail.com&lt;br /&gt;
| summit_session_leader_username2 = Gareth Heyes&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name3 =&lt;br /&gt;
| summit_session_leader_email3 = &lt;br /&gt;
| summit_session_leader_username3 =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_leader_name1 = John Wilander&lt;br /&gt;
| operational_leader_email1 = john.wilander@owasp.org&lt;br /&gt;
| operational_leader_username1 = John.wilander&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| meeting_notes = &lt;br /&gt;
|-&lt;br /&gt;
| session_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Session002&lt;br /&gt;
| session_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Working_Sessions/Session002&lt;br /&gt;
}}&lt;br /&gt;
&amp;lt;/includeonly&amp;gt;&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session056&amp;diff=103109</id>
		<title>Summit 2011 Working Sessions/Session056</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session056&amp;diff=103109"/>
				<updated>2011-02-02T18:25:36Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Summit 2011 Working Sessions test tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name1 = Stefano Di Paola&lt;br /&gt;
| summit_session_attendee_email1 = stefano@owasp.org&lt;br /&gt;
| summit_session_attendee_username1 = &lt;br /&gt;
| summit_session_attendee_company1= Minded Security&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name2 = Dan Cornell&lt;br /&gt;
| summit_session_attendee_email2 = dan@denimgroup.com&lt;br /&gt;
| summit_session_attendee_username2 = &lt;br /&gt;
| summit_session_attendee_company2=Denim Group&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name3 = Jeremy Long&lt;br /&gt;
| summit_session_attendee_email3 = jeremy.long@owasp.org&lt;br /&gt;
| summit_session_attendee_username3 = &lt;br /&gt;
| summit_session_attendee_company3=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name4 = Paolo Perego &lt;br /&gt;
| summit_session_attendee_email4 = thesp0nge@owasp.org&lt;br /&gt;
| summit_session_attendee_username4 = &lt;br /&gt;
| summit_session_attendee_company4= Armoredcode.com&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name5 = &lt;br /&gt;
| summit_session_attendee_email5 = &lt;br /&gt;
| summit_session_attendee_username5 = &lt;br /&gt;
| summit_session_attendee_company5=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name6 = &lt;br /&gt;
| summit_session_attendee_email6 = &lt;br /&gt;
| summit_session_attendee_username6 = &lt;br /&gt;
| summit_session_attendee_company6=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name7 = &lt;br /&gt;
| summit_session_attendee_email7 = &lt;br /&gt;
| summit_session_attendee_username7 = &lt;br /&gt;
| summit_session_attendee_company7=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name8 = &lt;br /&gt;
| summit_session_attendee_email8 = &lt;br /&gt;
| summit_session_attendee_username8 = &lt;br /&gt;
| summit_session_attendee_company8=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name9 = &lt;br /&gt;
| summit_session_attendee_email9 = &lt;br /&gt;
| summit_session_attendee_username9 = &lt;br /&gt;
| summit_session_attendee_company9=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name10 = &lt;br /&gt;
| summit_session_attendee_email10 = &lt;br /&gt;
| summit_session_attendee_username10 = &lt;br /&gt;
| summit_session_attendee_company10=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name11 = &lt;br /&gt;
| summit_session_attendee_email11 = &lt;br /&gt;
| summit_session_attendee_username11 = &lt;br /&gt;
| summit_session_attendee_company11=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name12 = &lt;br /&gt;
| summit_session_attendee_email12 = &lt;br /&gt;
| summit_session_attendee_username12 = &lt;br /&gt;
| summit_session_attendee_company12=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name13 = &lt;br /&gt;
| summit_session_attendee_email13 = &lt;br /&gt;
| summit_session_attendee_username13 = &lt;br /&gt;
| summit_session_attendee_company13=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name14 = &lt;br /&gt;
| summit_session_attendee_email14 = &lt;br /&gt;
| summit_session_attendee_username14 = &lt;br /&gt;
| summit_session_attendee_company14=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14= &lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name15 = &lt;br /&gt;
| summit_session_attendee_email15 = &lt;br /&gt;
| summit_session_attendee_username15 = &lt;br /&gt;
| summit_session_attendee_company15=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name16 = &lt;br /&gt;
| summit_session_attendee_email16 = &lt;br /&gt;
| summit_session_attendee_username16 = &lt;br /&gt;
| summit_session_attendee_company16=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name17 = &lt;br /&gt;
| summit_session_attendee_email17 = &lt;br /&gt;
| summit_session_attendee_username17 = &lt;br /&gt;
| summit_session_attendee_company17=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name18 = &lt;br /&gt;
| summit_session_attendee_email18 = &lt;br /&gt;
| summit_session_attendee_username18 = &lt;br /&gt;
| summit_session_attendee_company18=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name19 = &lt;br /&gt;
| summit_session_attendee_email19 = &lt;br /&gt;
| summit_session_attendee_username19 = &lt;br /&gt;
| summit_session_attendee_company19=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name20 = &lt;br /&gt;
| summit_session_attendee_email20 = &lt;br /&gt;
| summit_session_attendee_username20 = &lt;br /&gt;
| summit_session_attendee_company20=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| summit_track_logo = [[Image:T._metrics.jpg]]&lt;br /&gt;
| summit_ws_logo = [[Image:WS._metrics.jpg]]&lt;br /&gt;
| summit_session_name = Tools Interoperability (Data Instrumentation)&lt;br /&gt;
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session056&lt;br /&gt;
| mailing_list =&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| short_working_session_description=&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| related_project_name1 = &lt;br /&gt;
| related_project_url_1 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name2 = &lt;br /&gt;
| related_project_url_2 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name3 = &lt;br /&gt;
| related_project_url_3 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name4 = &lt;br /&gt;
| related_project_url_4 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name5 = &lt;br /&gt;
| related_project_url_5 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name1= &lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name2 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name3 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name4 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name5 =  &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_date_and_time = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| discussion_model = participants and attendees&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_resources = Projector, whiteboards, markers, Internet connectivity, power&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_additional_details = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name1 = &lt;br /&gt;
A standard schema for describing application security risks of all types, with a place for all relevant information – whether derived statically, dynamically, manually, or architecturally.&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name2 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name3 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name4 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name5 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name6 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name7 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name8 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name1 = Dinis Cruz&lt;br /&gt;
| summit_session_leader_email1 = dinis.cruz@owasp.org&lt;br /&gt;
| summit_session_leader_username1 = Dinis.cruz&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name2 = &lt;br /&gt;
| summit_session_leader_email2 = &lt;br /&gt;
| summit_session_leader_username2 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name3 = &lt;br /&gt;
| summit_session_leader_email3 = &lt;br /&gt;
| summit_session_leader_username3 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_leader_name1 =&lt;br /&gt;
| operational_leader_email1 =&lt;br /&gt;
| operational_leader_username1 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| meeting_notes = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| session_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Session056&lt;br /&gt;
| session_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Working_Sessions/Session056&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session063&amp;diff=103060</id>
		<title>Summit 2011 Working Sessions/Session063</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session063&amp;diff=103060"/>
				<updated>2011-02-02T16:23:26Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Summit 2011 Working Sessions test tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name1 = Nishi Kumar&lt;br /&gt;
| summit_session_attendee_email1 = nishi.kumar@owasp.org&lt;br /&gt;
| summit_session_attendee_username1 = &lt;br /&gt;
| summit_session_attendee_company1= FIS&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name2 = Jason Taylor&lt;br /&gt;
| summit_session_attendee_email2 = jtaylor@securityinnovation.com&lt;br /&gt;
| summit_session_attendee_username2 = &lt;br /&gt;
| summit_session_attendee_company2=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name3 = Steven van der Baan&lt;br /&gt;
| summit_session_attendee_email3 = steven.van.der.baan@owasp.org&lt;br /&gt;
| summit_session_attendee_username3 = &lt;br /&gt;
| summit_session_attendee_company3=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name4 = Sherif Koussa&lt;br /&gt;
| summit_session_attendee_email4 = sherif.koussa@owasp.org&lt;br /&gt;
| summit_session_attendee_username4 = &lt;br /&gt;
| summit_session_attendee_company4=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name5 = Daniel Brzozowski&lt;br /&gt;
| summit_session_attendee_email5 = daniel@brzozowski.biz&lt;br /&gt;
| summit_session_attendee_username5 = Daniel Brzozowski&lt;br /&gt;
| summit_session_attendee_company5=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name6 = Anurag Agarwal&lt;br /&gt;
| summit_session_attendee_email6 = anurag@myappsecurity.com&lt;br /&gt;
| summit_session_attendee_username6 = Anurag Agarwal&lt;br /&gt;
| summit_session_attendee_company6=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name7 = Giorgio Fedon&lt;br /&gt;
| summit_session_attendee_email7 = &lt;br /&gt;
| summit_session_attendee_username7 = gfedon&lt;br /&gt;
| summit_session_attendee_company7=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name8 = Achim Hoffmann&lt;br /&gt;
| summit_session_attendee_email8 = achim@owasp.org&lt;br /&gt;
| summit_session_attendee_username8 = Achim&lt;br /&gt;
| summit_session_attendee_company8= &lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name9 = Paolo Perego&lt;br /&gt;
| summit_session_attendee_email9 = thesp0nge@owasp.org&lt;br /&gt;
| summit_session_attendee_username9 = thesp0nge&lt;br /&gt;
| summit_session_attendee_company9=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name10 = &lt;br /&gt;
| summit_session_attendee_email10 = &lt;br /&gt;
| summit_session_attendee_username10 = &lt;br /&gt;
| summit_session_attendee_company10=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name11 = &lt;br /&gt;
| summit_session_attendee_email11 = &lt;br /&gt;
| summit_session_attendee_username11 = &lt;br /&gt;
| summit_session_attendee_company11=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name12 = &lt;br /&gt;
| summit_session_attendee_email12 = &lt;br /&gt;
| summit_session_attendee_username12 = &lt;br /&gt;
| summit_session_attendee_company12=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name13 = &lt;br /&gt;
| summit_session_attendee_email13 = &lt;br /&gt;
| summit_session_attendee_username13 = &lt;br /&gt;
| summit_session_attendee_company13=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name14 = &lt;br /&gt;
| summit_session_attendee_email14 = &lt;br /&gt;
| summit_session_attendee_username14 = &lt;br /&gt;
| summit_session_attendee_company14=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14= &lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name15 = &lt;br /&gt;
| summit_session_attendee_email15 = &lt;br /&gt;
| summit_session_attendee_username15 = &lt;br /&gt;
| summit_session_attendee_company15=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name16 = &lt;br /&gt;
| summit_session_attendee_email16 = &lt;br /&gt;
| summit_session_attendee_username16 = &lt;br /&gt;
| summit_session_attendee_company16=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name17 = &lt;br /&gt;
| summit_session_attendee_email17 = &lt;br /&gt;
| summit_session_attendee_username17 = &lt;br /&gt;
| summit_session_attendee_company17=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name18 = &lt;br /&gt;
| summit_session_attendee_email18 = &lt;br /&gt;
| summit_session_attendee_username18 = &lt;br /&gt;
| summit_session_attendee_company18=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name19 = &lt;br /&gt;
| summit_session_attendee_email19 = &lt;br /&gt;
| summit_session_attendee_username19 = &lt;br /&gt;
| summit_session_attendee_company19=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name20 = &lt;br /&gt;
| summit_session_attendee_email20 = &lt;br /&gt;
| summit_session_attendee_username20 = &lt;br /&gt;
| summit_session_attendee_company20=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| summit_track_logo = [[Image:T._individual_projects.jpg]]&lt;br /&gt;
| summit_ws_logo = [[Image:WS._individual_projects.jpg]]&lt;br /&gt;
| summit_session_name = O2 Platform&lt;br /&gt;
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session063&lt;br /&gt;
| mailing_list =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| short_working_session_description= This session will focus on exchanging experiences between O2 users and on how to make O2 easier to use and consume. There are a lot of areas that O2 can add value during security reviews, the problem most O2 users have is '' 'I know that it can be done, but how?' ''. Another key topic for discussion and debate is the '' 'No more security reports as PDFs concept' '' (where after a security engagement, clients should be given Unit Tests, not PDFs)&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| related_project_name1 = &lt;br /&gt;
| related_project_url_1 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name2 = &lt;br /&gt;
| related_project_url_2 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name3 = &lt;br /&gt;
| related_project_url_3 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name4 = &lt;br /&gt;
| related_project_url_4 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name5 = &lt;br /&gt;
| related_project_url_5 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name1= Define 'What is O2'&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name2 = Map out easy ways to start using O2&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name3 = Document success stories and 'real world' O2 usage&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name4 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name5 =  &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_date_and_time = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| discussion_model = participants and attendees&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_resources = Projector, whiteboards, markers, Internet connectivity, power&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_additional_details = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name1 = Simple user’s guide that shows how to install, configure, and use O2 to do a few simple common things.  &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name2 = Detailed workflows for the more complex features&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name3 = Roadmap for the next version of O2&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name4 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name5 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name6 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name7 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name8 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name1 = Dinis Cruz&lt;br /&gt;
| summit_session_leader_email1 = dinis.cruz@owasp.org&lt;br /&gt;
| summit_session_leader_username1 = Dinis.cruz&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name2 = &lt;br /&gt;
| summit_session_leader_email2 = &lt;br /&gt;
| summit_session_leader_username2 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name3 = &lt;br /&gt;
| summit_session_leader_email3 = &lt;br /&gt;
| summit_session_leader_username3 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_leader_name1 =&lt;br /&gt;
| operational_leader_email1 =&lt;br /&gt;
| operational_leader_username1 = &lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| meeting_notes = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| session_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Session063&lt;br /&gt;
| session_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Working_Sessions/Session063&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session034&amp;diff=102289</id>
		<title>Summit 2011 Working Sessions/Session034</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session034&amp;diff=102289"/>
				<updated>2011-01-27T10:44:08Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Summit 2011 Working Sessions test tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name1 = Paolo Perego&lt;br /&gt;
| summit_session_attendee_email1 = thesp0nge@owasp.org&lt;br /&gt;
| summit_session_attendee_company1= armoredcode.com&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=I'm leading the ESAPI port to Ruby so I want to make sure to understand exactly the library core.&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name2 = &lt;br /&gt;
| summit_session_attendee_email2 = &lt;br /&gt;
| summit_session_attendee_company2=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name3 = &lt;br /&gt;
| summit_session_attendee_email3 = &lt;br /&gt;
| summit_session_attendee_company3=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name4 = &lt;br /&gt;
| summit_session_attendee_email4 = &lt;br /&gt;
| summit_session_attendee_company4=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name5 = &lt;br /&gt;
| summit_session_attendee_email5 = &lt;br /&gt;
| summit_session_attendee_company5=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name6 = &lt;br /&gt;
| summit_session_attendee_email6 = &lt;br /&gt;
| summit_session_attendee_company6=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name7 = &lt;br /&gt;
| summit_session_attendee_email7 = &lt;br /&gt;
| summit_session_attendee_company7=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name8 = &lt;br /&gt;
| summit_session_attendee_email8 = &lt;br /&gt;
| summit_session_attendee_company8=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name9 = &lt;br /&gt;
| summit_session_attendee_email9 = &lt;br /&gt;
| summit_session_attendee_company9=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name10 = &lt;br /&gt;
| summit_session_attendee_email10 = &lt;br /&gt;
| summit_session_attendee_company10=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name11 = &lt;br /&gt;
| summit_session_attendee_email11 = &lt;br /&gt;
| summit_session_attendee_company11=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name12 = &lt;br /&gt;
| summit_session_attendee_email12 = &lt;br /&gt;
| summit_session_attendee_company12=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name13 = &lt;br /&gt;
| summit_session_attendee_email13 = &lt;br /&gt;
| summit_session_attendee_company13=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name14 = &lt;br /&gt;
| summit_session_attendee_email14 = &lt;br /&gt;
| summit_session_attendee_company14=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14= &lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name15 = &lt;br /&gt;
| summit_session_attendee_email15 = &lt;br /&gt;
| summit_session_attendee_company15=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name16 = &lt;br /&gt;
| summit_session_attendee_email16 = &lt;br /&gt;
| summit_session_attendee_company16=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name17 = &lt;br /&gt;
| summit_session_attendee_email17 = &lt;br /&gt;
| summit_session_attendee_company17=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name18 = &lt;br /&gt;
| summit_session_attendee_email18 = &lt;br /&gt;
| summit_session_attendee_company18=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name19 = &lt;br /&gt;
| summit_session_attendee_email19 = &lt;br /&gt;
| summit_session_attendee_company19=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name20 = &lt;br /&gt;
| summit_session_attendee_email20 = &lt;br /&gt;
| summit_session_attendee_company20=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| summit_track_logo = [[Image:T._secure_coding.jpg]] &lt;br /&gt;
| summit_ws_logo = [[Image:WS._secure_coding.jpg]]&lt;br /&gt;
| summit_session_name = ESAPI-CORE&lt;br /&gt;
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session034&lt;br /&gt;
| mailing_list =&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| short_working_session_description=&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| related_project_name1 = &lt;br /&gt;
| related_project_url_1 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name2 = &lt;br /&gt;
| related_project_url_2 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name3 = &lt;br /&gt;
| related_project_url_3 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name4 = &lt;br /&gt;
| related_project_url_4 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name5 = &lt;br /&gt;
| related_project_url_5 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name1= &lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name2 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name3 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name4 = &lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name5 =  &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_date_and_time = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| discussion_model = participants and attendees&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_resources = Projector, whiteboards, markers, Internet connectivity, power&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_additional_details = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name1 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name2 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name3 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name4 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name5 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name6 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name7 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name8 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name1 = Jim Manico&lt;br /&gt;
| summit_session_leader_email1 = jim.manico@owasp.org&lt;br /&gt;
| summit_session_leader_username1 = Jmanico&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name2 = &lt;br /&gt;
| summit_session_leader_email2 = &lt;br /&gt;
| summit_session_leader_username2 =&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name3 = &lt;br /&gt;
| summit_session_leader_email3 = &lt;br /&gt;
| summit_session_leader_username3 =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_leader_name1 =&lt;br /&gt;
| operational_leader_email1 =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| meeting_notes = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| session_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Session034&lt;br /&gt;
| session_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Working_Sessions/Session034&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session033&amp;diff=102286</id>
		<title>Summit 2011 Working Sessions/Session033</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session033&amp;diff=102286"/>
				<updated>2011-01-27T09:58:15Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Summit 2011 Working Sessions test tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name1 = &lt;br /&gt;
| summit_session_attendee_email1 = &lt;br /&gt;
| summit_session_attendee_company1=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name2 = &lt;br /&gt;
| summit_session_attendee_email2 = &lt;br /&gt;
| summit_session_attendee_company2=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name3 = &lt;br /&gt;
| summit_session_attendee_email3 = &lt;br /&gt;
| summit_session_attendee_company3=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name4 = &lt;br /&gt;
| summit_session_attendee_email4 = &lt;br /&gt;
| summit_session_attendee_company4=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name5 = &lt;br /&gt;
| summit_session_attendee_email5 = &lt;br /&gt;
| summit_session_attendee_company5=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name6 = &lt;br /&gt;
| summit_session_attendee_email6 = &lt;br /&gt;
| summit_session_attendee_company6=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name7 = &lt;br /&gt;
| summit_session_attendee_email7 = &lt;br /&gt;
| summit_session_attendee_company7=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name8 = &lt;br /&gt;
| summit_session_attendee_email8 = &lt;br /&gt;
| summit_session_attendee_company8=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name9 = &lt;br /&gt;
| summit_session_attendee_email9 = &lt;br /&gt;
| summit_session_attendee_company9=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name10 = &lt;br /&gt;
| summit_session_attendee_email10 = &lt;br /&gt;
| summit_session_attendee_company10=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name11 = &lt;br /&gt;
| summit_session_attendee_email11 = &lt;br /&gt;
| summit_session_attendee_company11=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name12 = &lt;br /&gt;
| summit_session_attendee_email12 = &lt;br /&gt;
| summit_session_attendee_company12=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name13 = &lt;br /&gt;
| summit_session_attendee_email13 = &lt;br /&gt;
| summit_session_attendee_company13=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name14 = &lt;br /&gt;
| summit_session_attendee_email14 = &lt;br /&gt;
| summit_session_attendee_company14=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14= &lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name15 = &lt;br /&gt;
| summit_session_attendee_email15 = &lt;br /&gt;
| summit_session_attendee_company15=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name16 = &lt;br /&gt;
| summit_session_attendee_email16 = &lt;br /&gt;
| summit_session_attendee_company16=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name17 = &lt;br /&gt;
| summit_session_attendee_email17 = &lt;br /&gt;
| summit_session_attendee_company17=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name18 = &lt;br /&gt;
| summit_session_attendee_email18 = &lt;br /&gt;
| summit_session_attendee_company18=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name19 = &lt;br /&gt;
| summit_session_attendee_email19 = &lt;br /&gt;
| summit_session_attendee_company19=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name20 = &lt;br /&gt;
| summit_session_attendee_email20 = &lt;br /&gt;
| summit_session_attendee_company20=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| summit_track_logo = [[Image:T._secure_coding.jpg]]&lt;br /&gt;
| summit_ws_logo = [[Image:WS._secure_coding.jpg]]&lt;br /&gt;
| summit_session_name = ESAPI for Ruby&lt;br /&gt;
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session033&lt;br /&gt;
| mailing_list = https://lists.owasp.org/mailman/listinfo/owasp-esapi-ruby&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| short_working_session_description= During this working session we would like to kickstart the project. We will define what and how to port from other ESAPIs and we will start writing rspec test case and cucumber scenarios using behavior driven development model&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| related_project_name1 = OWASP Enterprise Security API&lt;br /&gt;
| related_project_url_1 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&lt;br /&gt;
&lt;br /&gt;
| related_project_name2 = &lt;br /&gt;
| related_project_url_2 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name3 = &lt;br /&gt;
| related_project_url_3 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name4 = &lt;br /&gt;
| related_project_url_4 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name5 = &lt;br /&gt;
| related_project_url_5 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name1= Define which APIs needs to be implemented&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name2 = Define the module's namespace inside the gem&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name3 = Write cucumber scenarios to define overall integration tests&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name4 = Write rspec contexts for each API for fine grain test&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name5 =  (hopefully: implementing at least 5% of APIs starting from their rspecs)&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_date_and_time = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| discussion_model = participants and attendees&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_resources = Projector, whiteboards, markers, Internet connectivity, power&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_additional_details = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name1 = cucumber scenarios &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name2 = rspec context for each API choosen&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name3 = 5% of APIs being implemented&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name4 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name5 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name6 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name7 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name8 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name1 = Paolo Perego&lt;br /&gt;
| summit_session_leader_email1 = thesp0nge@owasp.org&lt;br /&gt;
| summit_session_leader_username1 = Thesp0nge&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name2 = &lt;br /&gt;
| summit_session_leader_email2 = &lt;br /&gt;
| summit_session_leader_username2 =&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name3 = &lt;br /&gt;
| summit_session_leader_email3 = &lt;br /&gt;
| summit_session_leader_username3 =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_leader_name1 =&lt;br /&gt;
| operational_leader_email1 =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| meeting_notes = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| session_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Session033&lt;br /&gt;
| session_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Working_Sessions/Session033&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session033&amp;diff=102285</id>
		<title>Summit 2011 Working Sessions/Session033</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Working_Sessions/Session033&amp;diff=102285"/>
				<updated>2011-01-27T09:55:52Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Summit 2011 Working Sessions test tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name1 = &lt;br /&gt;
| summit_session_attendee_email1 = &lt;br /&gt;
| summit_session_attendee_company1=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name2 = &lt;br /&gt;
| summit_session_attendee_email2 = &lt;br /&gt;
| summit_session_attendee_company2=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name3 = &lt;br /&gt;
| summit_session_attendee_email3 = &lt;br /&gt;
| summit_session_attendee_company3=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name4 = &lt;br /&gt;
| summit_session_attendee_email4 = &lt;br /&gt;
| summit_session_attendee_company4=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name5 = &lt;br /&gt;
| summit_session_attendee_email5 = &lt;br /&gt;
| summit_session_attendee_company5=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name6 = &lt;br /&gt;
| summit_session_attendee_email6 = &lt;br /&gt;
| summit_session_attendee_company6=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name7 = &lt;br /&gt;
| summit_session_attendee_email7 = &lt;br /&gt;
| summit_session_attendee_company7=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name8 = &lt;br /&gt;
| summit_session_attendee_email8 = &lt;br /&gt;
| summit_session_attendee_company8=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name9 = &lt;br /&gt;
| summit_session_attendee_email9 = &lt;br /&gt;
| summit_session_attendee_company9=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name10 = &lt;br /&gt;
| summit_session_attendee_email10 = &lt;br /&gt;
| summit_session_attendee_company10=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name11 = &lt;br /&gt;
| summit_session_attendee_email11 = &lt;br /&gt;
| summit_session_attendee_company11=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name12 = &lt;br /&gt;
| summit_session_attendee_email12 = &lt;br /&gt;
| summit_session_attendee_company12=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name13 = &lt;br /&gt;
| summit_session_attendee_email13 = &lt;br /&gt;
| summit_session_attendee_company13=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name14 = &lt;br /&gt;
| summit_session_attendee_email14 = &lt;br /&gt;
| summit_session_attendee_company14=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14= &lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name15 = &lt;br /&gt;
| summit_session_attendee_email15 = &lt;br /&gt;
| summit_session_attendee_company15=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name16 = &lt;br /&gt;
| summit_session_attendee_email16 = &lt;br /&gt;
| summit_session_attendee_company16=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name17 = &lt;br /&gt;
| summit_session_attendee_email17 = &lt;br /&gt;
| summit_session_attendee_company17=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name18 = &lt;br /&gt;
| summit_session_attendee_email18 = &lt;br /&gt;
| summit_session_attendee_company18=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name19 = &lt;br /&gt;
| summit_session_attendee_email19 = &lt;br /&gt;
| summit_session_attendee_company19=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=&lt;br /&gt;
&lt;br /&gt;
| summit_session_attendee_name20 = &lt;br /&gt;
| summit_session_attendee_email20 = &lt;br /&gt;
| summit_session_attendee_company20=&lt;br /&gt;
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| summit_track_logo = [[Image:T._secure_coding.jpg]]&lt;br /&gt;
| summit_ws_logo = [[Image:WS._secure_coding.jpg]]&lt;br /&gt;
| summit_session_name = ESAPI for Ruby&lt;br /&gt;
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session033&lt;br /&gt;
| mailing_list =&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| short_working_session_description= During this working session we would like to kickstart the project. We will define what and how to port from other ESAPIs and we will start writing rspec test case and cucumber scenarios using behavior driven development model&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| related_project_name1 = OWASP Enterprise Security API&lt;br /&gt;
| related_project_url_1 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API&lt;br /&gt;
&lt;br /&gt;
| related_project_name2 = &lt;br /&gt;
| related_project_url_2 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name3 = &lt;br /&gt;
| related_project_url_3 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name4 = &lt;br /&gt;
| related_project_url_4 = &lt;br /&gt;
&lt;br /&gt;
| related_project_name5 = &lt;br /&gt;
| related_project_url_5 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name1= Define which APIs needs to be implemented&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name2 = Define the module's namespace inside the gem&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name3 = Write cucumber scenarios to define overall integration tests&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name4 = Write rspec contexts for each API for fine grain test&lt;br /&gt;
&lt;br /&gt;
| summit_session_objective_name5 =  (hopefully: implementing at least 5% of APIs starting from their rspecs)&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_date_and_time = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| discussion_model = participants and attendees&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_resources = Projector, whiteboards, markers, Internet connectivity, power&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| working_session_additional_details = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name1 = cucumber scenarios &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name2 = rspec context for each API choosen&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name3 = 5% of APIs being implemented&lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name4 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name5 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name6 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name7 = &lt;br /&gt;
&lt;br /&gt;
|summit_session_deliverable_name8 = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name1 = Paolo Perego&lt;br /&gt;
| summit_session_leader_email1 = thesp0nge@owasp.org&lt;br /&gt;
| summit_session_leader_username1 = Thesp0nge&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name2 = &lt;br /&gt;
| summit_session_leader_email2 = &lt;br /&gt;
| summit_session_leader_username2 =&lt;br /&gt;
&lt;br /&gt;
| summit_session_leader_name3 = &lt;br /&gt;
| summit_session_leader_email3 = &lt;br /&gt;
| summit_session_leader_username3 =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| operational_leader_name1 =&lt;br /&gt;
| operational_leader_email1 =&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| meeting_notes = &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
| session_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Session033&lt;br /&gt;
| session_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Working_Sessions/Session033&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Attendee/Attendee045&amp;diff=97661</id>
		<title>Summit 2011 Attendee/Attendee045</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Attendee/Attendee045&amp;diff=97661"/>
				<updated>2010-12-23T09:45:48Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP 2011 Global Summit Attendee Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_name1 = Paolo Perego&lt;br /&gt;
| summit_attendee_email1 = thesp0nge@owasp.org&lt;br /&gt;
| summit_attendee_wiki_username1 = Thesp0nge&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_company = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name1 =  Orizon Project Project Leader&lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_1 = http://www.owasp.org/index.php/Category:OWASP_Orizon_Project&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name2 = ESAPI Ruby Project Leader&lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_2 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Ruby&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name3 = OWASP Code Guide Review Guide Member&lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_3 = http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name4 = Italy Local Chapter Board Member&lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_4 = http://www.owasp.org/index.php/Italy&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name5 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_5 = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name1 =  Kickstarting Owasp ESAPI for Ruby with live session coding&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_1 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_1 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name2 = Partecipating to Owasp Code Review Guide working sessions&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_2 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_2 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name3 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_3 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_3 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name4 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_4 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_4 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name5 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_5 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_5 = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_owasp_sponsor = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_summit_time_paid_by_name1 =&lt;br /&gt;
| summit_attendee_summit_time_paid_by_url_1 =&lt;br /&gt;
| summit_attendee_summit_time_paid_by_name2 =&lt;br /&gt;
| summit_attendee_summit_time_paid_by_url_2 =&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_name1 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_url_1 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_name2 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_url_2 = &lt;br /&gt;
|-&lt;br /&gt;
| reason_for_sponsorship = Owasp Project Leader and member&lt;br /&gt;
|-&lt;br /&gt;
| status = Confirmed, seeking funds&lt;br /&gt;
|-&lt;br /&gt;
| letter sent to sponsor = &lt;br /&gt;
|-&lt;br /&gt;
| notes for Kate =&lt;br /&gt;
|-&lt;br /&gt;
| attendee_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Attendee045&lt;br /&gt;
| attendee_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Attendee/Attendee045 &lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Attendee/Attendee045&amp;diff=95844</id>
		<title>Summit 2011 Attendee/Attendee045</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Attendee/Attendee045&amp;diff=95844"/>
				<updated>2010-12-09T09:34:20Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP 2011 Global Summit Attendee Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_name1 = Paolo Perego&lt;br /&gt;
| summit_attendee_email1 = thesp0nge@owasp.org&lt;br /&gt;
| summit_attendee_wiki_username1 = Thesp0nge&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_company = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name1 =  Orizon Project Project Leader&lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_1 = http://www.owasp.org/index.php/Category:OWASP_Orizon_Project&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name2 = ESAPI Ruby Project Leader&lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_2 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Ruby&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name3 = OWASP Code Guide Review Guide Member&lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_3 = http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name4 = Italy Local Chapter Board Member&lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_4 = http://www.owasp.org/index.php/Italy&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name5 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_5 = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name1 =  &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_1 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_1 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name2 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_2 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_2 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name3 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_3 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_3 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name4 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_4 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_4 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name5 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_5 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_5 = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_owasp_sponsor = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_summit_time_paid_by_name1 =&lt;br /&gt;
| summit_attendee_summit_time_paid_by_url_1 =&lt;br /&gt;
| summit_attendee_summit_time_paid_by_name2 =&lt;br /&gt;
| summit_attendee_summit_time_paid_by_url_2 =&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_name1 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_url_1 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_name2 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_url_2 = &lt;br /&gt;
|-&lt;br /&gt;
| reason_for_sponsorship = &lt;br /&gt;
|-&lt;br /&gt;
| status = Confirmed, seeking funds&lt;br /&gt;
|-&lt;br /&gt;
| letter sent to sponsor = &lt;br /&gt;
|-&lt;br /&gt;
| notes for Kate =&lt;br /&gt;
|-&lt;br /&gt;
| attendee_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Attendee045&lt;br /&gt;
| attendee_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Attendee/Attendee045 &lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Thesp0nge&amp;diff=84749</id>
		<title>User:Thesp0nge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Thesp0nge&amp;diff=84749"/>
				<updated>2010-06-09T14:11:30Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Paolo Perego (aka thesp0nge) writes software for an Italian digital media company called [http://www.bitmama.it Bitmama]. &lt;br /&gt;
He leads the Owasp [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Orizon] project, an opensource code review engine and the [http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Ruby Owasp Esapi for Ruby] project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You want more? &lt;br /&gt;
&lt;br /&gt;
My [http://en.gravatar.com/thesp0nge gravatar] page.&lt;br /&gt;
&lt;br /&gt;
My email: thesp0nge_at_owasp.org&lt;br /&gt;
&lt;br /&gt;
My Linkedin [http://www.linkedin.com/in/thesp0nge profile]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Thesp0nge&amp;diff=84748</id>
		<title>User:Thesp0nge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Thesp0nge&amp;diff=84748"/>
				<updated>2010-06-09T14:10:53Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Paolo Perego (aka thesp0nge) writes software for an Italian digital media company called [http://www.bitmama.it Bitmama]. &lt;br /&gt;
He leads the Owasp [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Orizon] project, an opensource code review engine and the [http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Ruby Owasp Esapi for Ruby] project.&lt;br /&gt;
&lt;br /&gt;
You want more? &lt;br /&gt;
&lt;br /&gt;
My [http://en.gravatar.com/thesp0nge gravatar] page.&lt;br /&gt;
My email: thesp0nge_at_owasp.org&lt;br /&gt;
My Linkedin [http://www.linkedin.com/in/thesp0nge profile]&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Enterprise_Security_API&amp;diff=84198</id>
		<title>GPC Project Details/OWASP Enterprise Security API</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Enterprise_Security_API&amp;diff=84198"/>
				<updated>2010-06-01T10:05:49Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Project Identification Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Enterprise Security API&lt;br /&gt;
| project_description = Don’t write your own security controls! Reinventing the wheel when it comes to developing security controls for every web application or web service leads to wasted time and massive security holes. '''OWASP Enterprise Security API (ESAPI) Toolkits''' help software developers guard against security‐related design and implementation flaws. ESAPI is designed to make it easy to retrofit security into existing applications, as well as providing a solid foundation for new development. Allowing for language-specific differences, all OWASP ESAPI versions have the same basic design:&lt;br /&gt;
&lt;br /&gt;
* '''There is a set of security control interfaces.''' They define for example types of parameters that are passed to types of security controls. &lt;br /&gt;
&lt;br /&gt;
* '''There is a reference implementation for each security control.''' The logic is not organization‐specific and the logic is not application‐specific. An example: string‐based input validation.&lt;br /&gt;
&lt;br /&gt;
* '''There are optionally your own implementations for each security control.''' There may be application logic contained in these classes which may be developed by or for your organization. An example: enterprise authentication.&lt;br /&gt;
| project_license = [http://en.wikipedia.org/wiki/BSD_license BSD license]&lt;br /&gt;
| leader_name = Jeff Williams&lt;br /&gt;
| leader_email = jeff.williams@owasp.org&lt;br /&gt;
| leader_username = Jeff_Williams&lt;br /&gt;
| past_leaders_special_contributions = &lt;br /&gt;
| maintainer_name = Mike Boberski&lt;br /&gt;
| maintainer_email = mike.boberski@owasp.org&lt;br /&gt;
| maintainer_username = mike.boberski&lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = http://www.owasp.org/images/8/81/Esapi-datasheet.pdf&lt;br /&gt;
| presentation_link = http://owasp-esapi-java.googlecode.com/files/OWASP%20ESAPI.ppt&lt;br /&gt;
| mailing_list_name = esapi-user&lt;br /&gt;
| links_url1 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Downloads&lt;br /&gt;
| links_name1 = General ESAPI information&lt;br /&gt;
| links_url2 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Java_EE&lt;br /&gt;
| links_name2 = ESAPI for Java EE&lt;br /&gt;
| links_url3 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=.NET&lt;br /&gt;
| links_name3 = ESAPI for .NET&lt;br /&gt;
| links_url4 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Classic_ASP&lt;br /&gt;
| links_name4 = ESAPI for Classic ASP&lt;br /&gt;
| links_url5 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=PHP&lt;br /&gt;
| links_name5 = ESAPI for PHP&lt;br /&gt;
| links_url6 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=ColdFusion.2FCFML&lt;br /&gt;
| links_name6 = ESAPI for ColdFusion/CFML&lt;br /&gt;
| links_url7 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Python&lt;br /&gt;
| links_name7 = ESAPI for Python&lt;br /&gt;
| links_url8 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=JavaScript&lt;br /&gt;
| links_name8 = ESAPI for JavaScript&lt;br /&gt;
| links_url9 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Haskell&lt;br /&gt;
| links_name9 = ESAPI for Haskell&lt;br /&gt;
| links_url10 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Ruby  &lt;br /&gt;
| links_name10 = ESAPI for Ruby&lt;br /&gt;
| project_road_map = &lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username =&lt;br /&gt;
| current_release_details =  &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
| last_GPC_update = 4/10/2009&lt;br /&gt;
| GPC_Notes = Empty template (ESAPI Global)&lt;br /&gt;
| project_home_page = :Category:OWASP_Enterprise_Security_API&lt;br /&gt;
| project_details_wiki_page = GPC_Project_Details/OWASP_Enterprise_Security_API&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Enterprise_Security_API&amp;diff=84197</id>
		<title>Category:OWASP Enterprise Security API</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Enterprise_Security_API&amp;diff=84197"/>
				<updated>2010-06-01T10:03:16Z</updated>
		
		<summary type="html">&lt;p&gt;Thesp0nge: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Home  ====&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;100%&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;66%&amp;quot; | &lt;br /&gt;
! width=&amp;quot;33%&amp;quot; | &lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| &lt;br /&gt;
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library that makes it easier for programmers to write lower-risk applications. The ESAPI libraries are designed to make it easier for programmers to retrofit security into existing applications. The ESAPI libraries also serve as a solid foundation for new development. &lt;br /&gt;
&lt;br /&gt;
Allowing for language-specific differences, all OWASP ESAPI versions have the same basic design: &lt;br /&gt;
&lt;br /&gt;
*'''There is a set of security control interfaces.''' They define for example types of parameters that are passed to types of security controls.&lt;br /&gt;
&lt;br /&gt;
*'''There is a reference implementation for each security control.''' The logic is not organization‐specific and the logic is not application‐specific. An example: string‐based input validation.&lt;br /&gt;
&lt;br /&gt;
*'''There are optionally your own implementations for each security control.''' There may be application logic contained in these classes which may be developed by or for your organization. An example: enterprise authentication.&lt;br /&gt;
&lt;br /&gt;
The following organizations are a few of the many organizations that are starting to adopt ESAPI to secure their web applications: [http://www.americanexpress.com/ American Express], [http://www.apache.org/ Apache Foundation], [http://www.boozallen.com Booz Allen Hamilton], [http://www.aspectsecurity.com/ Aspect Security], [http://www.galois.com Galois], [http://www.foundstone.com Foundstone(McAfee)], [http://www.thehartford.com/ The Hartford], [http://www.infinitecampus.com Infinite Campus], [http://www.lockheedmartin.com/ Lockheed Martin], [http://cwe.mitre.org/top25/index.html MITRE], [http://www.nationwide.com/ Nationwide Insurance], [http://enterprise.spawar.navy.mil/ U.S. Navy - SPAWAR], [http://www.worldbank.org/ The World Bank], [http://www.sans.org/top25errors/ SANS Institute]. Please let us know how your organization is using OWASP ESAPI. Include your name, organization's name, and brief description of how you are using it. The project lead can be reached [mailto:jeff.williams@owasp.org here]. &lt;br /&gt;
&lt;br /&gt;
| &lt;br /&gt;
[[Image:Esapi-sponsors.PNG]] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;100%&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;33%&amp;quot; | &lt;br /&gt;
! width=&amp;quot;33%&amp;quot; | &lt;br /&gt;
! width=&amp;quot;33%&amp;quot; | &lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| &lt;br /&gt;
== Let's talk here  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-bulb.jpg]]'''ESAPI Communities''' &lt;br /&gt;
&lt;br /&gt;
Further development of ESAPI occurs through mailing list discussions and occasional workshops, and suggestions for improvement are welcome. For more information, please [mailto:jeff.williams@owasp.org contact us]. &lt;br /&gt;
&lt;br /&gt;
*[https://lists.owasp.org/mailman/listinfo/esapi-user esapi-user mailing list (this is the main list)] &lt;br /&gt;
*[https://lists.owasp.org/mailman/listinfo/esapi-dev esapi-dev mailing list] &lt;br /&gt;
*[https://lists.owasp.org/mailman/listinfo/esapi-php esapi-php mailing list] &lt;br /&gt;
*[https://lists.owasp.org/mailman/listinfo/esapi-python esapi-python mailing list] &lt;br /&gt;
*[https://lists.owasp.org/mailman/listinfo/owasp-esapi-ruby esapi-ruby mailing list] &lt;br /&gt;
*[https://lists.owasp.org/mailman/listinfo/esapi-summit esapi-summit mailing list]&lt;br /&gt;
&lt;br /&gt;
| &lt;br /&gt;
== Got developer cycles?  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-waiting.JPG]]'''ESAPI Coding''' &lt;br /&gt;
&lt;br /&gt;
The ESAPI project is always on the lookout for volunteers who are interested in contributing developer cycles. &lt;br /&gt;
&lt;br /&gt;
*[http://owasp-esapi-php.googlecode.com/files/esapi4php-contributing.pdf ESAPI for PHP Developer Onboarding Instructions] &lt;br /&gt;
*ESAPI for other languages developer onboarding instructions -- coming soon!&lt;br /&gt;
&lt;br /&gt;
| &lt;br /&gt;
== Related resources  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-satellite.jpg]]'''OWASP Resources''' &lt;br /&gt;
&lt;br /&gt;
*[[Top Ten|OWASP Top Ten]] &lt;br /&gt;
*[[ASVS|OWASP Application Security Verification Standard]] &lt;br /&gt;
*[http://www.owasp.org/index.php/Category:OWASP_Guide_Project OWASP Development Guide] &lt;br /&gt;
*[http://www.owasp.org/index.php/Category:OWASP_Legal_Project OWASP Legal Project] &lt;br /&gt;
*[[SQL Injection Prevention Cheat Sheet]] &lt;br /&gt;
*[[XSS (Cross Site Scripting) Prevention Cheat Sheet]] &lt;br /&gt;
*[http://www.owasp.org/index.php/Category:OWASP_Newsletter#tab=Press_releases OWASP Press Releases]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Downloads  ====&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;100%&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;33%&amp;quot; | &lt;br /&gt;
! width=&amp;quot;33%&amp;quot; | &lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
| &lt;br /&gt;
[[Image:Asvs-step1.jpg]]'''1. About ESAPI''' &lt;br /&gt;
&lt;br /&gt;
*Data sheet([http://www.owasp.org/images/8/81/Esapi-datasheet.pdf PDF], [http://www.owasp.org/images/3/32/Esapi-datasheet.doc Word]) &lt;br /&gt;
*Project presentation ([http://owasp-esapi-java.googlecode.com/files/OWASP%20ESAPI.ppt PowerPoint]) &lt;br /&gt;
*Video presentation ([http://www.youtube.com/watch?v=QAPD1jPn04g YouTube])&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-step2.jpg]]'''2. Get ESAPI''' &lt;br /&gt;
&lt;br /&gt;
*[http://owasp-esapi-java.googlecode.com/files/ESAPI-1.4.4.zip ESAPI for Java 1.4.4 complete zip (JDK 1.4+)] &lt;br /&gt;
*[http://owasp-esapi-java.googlecode.com/files/ESAPI-2.0-rc6.zip ESAPI for Java 2.0 rc6 complete zip (JDK 1.5+)] &lt;br /&gt;
*{{#switchtablink:.NET|ESAPI for .NET}}&amp;lt;br&amp;gt; &lt;br /&gt;
*{{#switchtablink:Classic ASP|ESAPI for Classic ASP}}&amp;lt;br&amp;gt; &lt;br /&gt;
*{{#switchtablink:PHP|ESAPI for PHP}}&amp;lt;br&amp;gt; &lt;br /&gt;
*{{#switchtablink:ColdFusion.2FCFML|ESAPI for ColdFusion &amp;amp; CFML}}&amp;lt;br&amp;gt; &lt;br /&gt;
*{{#switchtablink:Python|ESAPI for Python}}&amp;lt;br&amp;gt; &lt;br /&gt;
*{{#switchtablink:Haskell|ESAPI for Haskell}}&amp;lt;br&amp;gt; &lt;br /&gt;
*{{#switchtablink:JavaScript|ESAPI for Javascript}}&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| &lt;br /&gt;
[[Image:Asvs-step3.jpg]]'''3. Learn ESAPI''' &lt;br /&gt;
&lt;br /&gt;
*ESAPI design patterns (not language-specific): [http://www.owasp.org/images/8/82/Esapi-design-patterns.pdf (PDF], [http://www.owasp.org/index.php/File:Esapi-design-patterns.doc Word], [http://www.owasp.org/images/8/87/Esapi-design-patterns.ppt PPT)] &lt;br /&gt;
*The [[ESAPI Swingset|ESAPI Swingset]] sample application demonstrates how to leverage ESAPI to protect a web application. &lt;br /&gt;
*LAMP should be spelled LAMPE ([http://www.owasp.org/images/a/ac/LAMP_Should_be_Spelled_LAMPE.pdf PDF]) &lt;br /&gt;
*ESAPI for Java interface documentation ([http://owasp-esapi-java.googlecode.com/svn/trunk_doc/index.html JavaDocs]) &lt;br /&gt;
*ESAPI for PHP interface documentation ([http://owasp-esapi-php.googlecode.com/svn/trunk_doc/latest/index.html phpdoc])&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Here's what I did with ESAPI  ====&lt;br /&gt;
&lt;br /&gt;
*I used ESAPI for Java with Google AppEngine. I used it for simple validation and encoding. --[mailto:jeff.williams@owasp.org Jeff]&lt;br /&gt;
&lt;br /&gt;
*I used ESAPI for PHP with a custom web 2.0 corporate knowledge management application, made up of many open source and commercial applications integrated to work together. I added an organization- and application-specific &amp;quot;Adapter&amp;quot; control to wrap calls to the other ESAPI controls. --[mailto:mike.boberski@owasp.org Mike]&lt;br /&gt;
&lt;br /&gt;
*I used ESAPI for Java’s &amp;quot;Logger&amp;quot; control to make it easier for a US Government customer to meet C&amp;amp;amp;A requirements. --[mailto:dave.wichers@owasp.org Dave]&lt;br /&gt;
&lt;br /&gt;
*I used ESAPI for Java to build a low risk web application that was over 250,000+ lines of code in size. --[mailto:jim.manico@owasp.org Jim]&lt;br /&gt;
&lt;br /&gt;
*I used ESAPI for Java's &amp;quot;Authenticator&amp;quot; to replace a spaghetti-like mechanism in a legacy financial services web application. In hindsight I should have used the application-specific &amp;quot;Adapter&amp;quot; pattern mentioned by Mike above. The organization also uses the ESAPI Encryptor as an interface to a hardware security module. --[mailto:roman.hustad@yahoo.com Roman]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Glossary  ====&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-letters.jpg]]'''ESAPI Terminology''' &lt;br /&gt;
&lt;br /&gt;
*'''adapter''' - There are optionally your own implementations for each security control. There may be application logic contained in these classes which may be developed by or for your organization. The logic may be organization-specific and/or application-specific. There may be proprietary information or logic contained in these classes which may be developed by or for your organization. &lt;br /&gt;
*'''built-in singleton design pattern''' - The &amp;quot;built-in&amp;quot; singleton design pattern refers to the replacement of security control reference implementations with your own implementations. ESAPI interfaces are otherwise left intact. &lt;br /&gt;
*'''codec''' - ESAPI encoder/decoder reference implementations. &lt;br /&gt;
*'''core''' - The ESAPI interfaces and reference implementations that are not intended to be replaced with enterprise-specific versions are called the ESAPI Core. &lt;br /&gt;
*'''exception''' - ESAPI exception reference implementations. &lt;br /&gt;
*'''extended factory design pattern''' - The &amp;quot;extended&amp;quot; factory design pattern refers to the addition of a new security control interface and corresponding implementation, which in turn calls ESAPI security control reference implementations and/or security control reference implementations that were replaced with your own implementations. The ESAPI locator class would be called in order to retrieve a singleton instance of your new security control, which in turn would call ESAPI security control reference implementations and/or security control reference implementations that were replaced with your own implementations. &lt;br /&gt;
*'''extended singleton design pattern''' - The &amp;quot;extended&amp;quot; singleton pattern refers to the replacement of security control reference implementations with your own implementations and the addition/modification/subtraction of corresponding security control interfaces. &lt;br /&gt;
*'''ES-enable (or ESAPI-enable)''' - Just as web applications and web services can be Public Key Infrastructure (PKI) enabled (PK-enabled) to perform for example certificate-based authentication, applications and services can be OWASP ESAPI-enabled (ES-enabled) to enable applications and services to protect themselves from attackers. &lt;br /&gt;
*'''filter''' - In ESAPI for Java, there is additionally an HTTP filter that can be called separately from the other controls. &lt;br /&gt;
*'''interfaces''' - There is a set of security control interfaces. There is no application logic contained in these interfaces. They define for example types of parameters that are passed to types of security controls. There is no proprietary information or logic contained in these interfaces. &lt;br /&gt;
*'''locator''' - The ESAPI security control interfaces include an &amp;quot;ESAPI&amp;quot; class that is commonly referred to as a &amp;quot;locator&amp;quot; class. The ESAPI locator class is called in order to retrieve singleton instances of individual security controls, which are then called in order to perform security checks (such as performing an access control check) or that result in security effects (such as generating an audit record). &lt;br /&gt;
*'''reference implementation''' - There is a reference implementation for each security control. There is application logic contained in these classes, i.e. contained in these interface implementations. However, the logic is not organization-specific and the logic is not application-specific. There is no proprietary information or logic contained in these reference implementation classes. &lt;br /&gt;
*'''Web Application Firewall (WAF)''' - In ESAPI for Java, there is additionally a Web Application Firewall (WAF) that can be called separately from the other controls.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Java EE  ====&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;200&amp;quot; cellspacing=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; border=&amp;quot;0&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
{{:GPC_Project_Details/OWASP_Enterprise_Security_API_Java_EE_Version | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
[[Image:New-esapi-docs.PNG|border]] &lt;br /&gt;
&lt;br /&gt;
'''Cool new documentation'''&lt;br /&gt;
&lt;br /&gt;
'''(which is currently under development)&amp;amp;nbsp;'''&lt;br /&gt;
&lt;br /&gt;
'''can be found '''[http://code.google.com/p/owasp-esapi-java/wiki/Welcome '''here''']'''!'''&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== .NET  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC_Project_Details/OWASP_Enterprise_Security_API_.NET_Version | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
==== Classic ASP  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC_Project_Details/OWASP_Enterprise_Security_API_-_Classic_ASP_Version | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
==== PHP  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC_Project_Details/OWASP_Enterprise_Security_API_-_PHP_Version | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
==== ColdFusion/CFML  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC_Project_Details/OWASP_Enterprise_Security_API_-_ColdFusion/CFML | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
==== Python  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC_Project_Details/OWASP_Enterprise_Security_API_-_Python_Version | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
==== JavaScript  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC_Project_Details/OWASP_Enterprise_Security_API_JavaScript_Version  | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
==== Haskell  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC_Project_Details/OWASP_Enterprise_Security_API_-_Haskell_Version | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
==== Force.com  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC_Project_Details/OWASP_Enterprise_Security_API_-_Force.com_Version | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
==== Ruby ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/Owasp Esapi Ruby | Project About}} &lt;br /&gt;
&lt;br /&gt;
==== Project Details  ====&lt;br /&gt;
&lt;br /&gt;
{{:GPC_Project_Details/OWASP_Enterprise_Security_API | OWASP Project Identification Tab}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; ''This project licensed under the [http://en.wikipedia.org/wiki/BSD_license BSD license], which is very permissive and about as close to public domain as is possible. You can use or modify ESAPI however you want, even include it in commercial products.'' &amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Thesp0nge</name></author>	</entry>

	</feed>