<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Tlr</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Tlr"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Tlr"/>
		<updated>2026-06-03T14:40:19Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29890</id>
		<title>AppSecEU08 HTML5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29890"/>
				<updated>2008-05-27T10:45:11Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[AppSecEU08 | AppSecEU08]] &amp;gt; [[AppSecEU08#Agenda_and_Presentations_-_May_21-22 | Agenda and Presentations]] &amp;gt; [[AppSecEU08_HTML5 | HTML5 Security]]&lt;br /&gt;
&lt;br /&gt;
= Slides and Contact =&lt;br /&gt;
&lt;br /&gt;
Slides: [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Would you like fries with that?]&lt;br /&gt;
&lt;br /&gt;
Contact: Thomas Roessler, W3C Security Activity Lead, [mailto:tlr@w3.org tlr@w3.org]&lt;br /&gt;
&lt;br /&gt;
= HTML5 resources =&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/ HTML 5 editor's draft]&lt;br /&gt;
* [http://dev.w3.org/html5/pubnotes/ HTML 5 publication notes]&lt;br /&gt;
* [http://html5.org/tools/web-apps-tracker Web interface to specification changes]&lt;br /&gt;
* [http://twitter.com/whatwg Major changes as a twitter feed]&lt;br /&gt;
* [http://www.w3.org/html/wg/ HTML Working Group Home Page]&lt;br /&gt;
&lt;br /&gt;
Specific parts of the specification that were mentioned during the talk:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#windows Browsing contexts]; [http://www.w3.org/html/wg/html5/#security6 navigation policy]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#origin Origin]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#custom-handlers Custom protocol and content handlers]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#offline Offline Web Applications]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#structured Structured client-side storge]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#crossDocumentMessages Cross Document Messaging] (aka postMessage)&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#server-sent-events server-sent DOM events]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#network Network connections]&lt;br /&gt;
&lt;br /&gt;
Also of interest, but added even more recently:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#sandbox iframe sandboxing]; [http://lists.w3.org/Archives/Public/public-webapi/2008May/0326.html summary of concepts]&lt;br /&gt;
&lt;br /&gt;
= Cross-domain XMLHttpRequest =&lt;br /&gt;
&lt;br /&gt;
* [http://dev.w3.org/2006/waf/access-control/ access-control editor's draft]&lt;br /&gt;
* [http://dev.w3.org/2006/webapi/XMLHttpRequest-2/ XMLHttpRequest Level 2 editor's draft]&lt;br /&gt;
&lt;br /&gt;
Note that the &amp;quot;access-control&amp;quot; specification provides a mechanism for authorizing exceptions to the same-origin policy. How that authorization (and the data retrieved) is used isn't actually specified. For XMLHttpRequest, the governing specification is XMLHttpRequest Level 2.  Don't read one without the other.&lt;br /&gt;
&lt;br /&gt;
Also relevant:&lt;br /&gt;
&lt;br /&gt;
* [http://lists.w3.org/Archives/Public/public-appformats/2008Mar/0017.html IE Team's proposal for Cross Site Requests] (XDomainRequest)&lt;br /&gt;
&lt;br /&gt;
Relevant work is currently occuring in the [http://www.w3.org/2006/webapi/ Web API] and [http://www.w3.org/2006/appformats/ Web Application Formats] Working Groups at W3C. A [http://www.w3.org/2007/12/WebApps-Charter-2007 proposed restructuring] of that work is currently being negotiated.&lt;br /&gt;
&lt;br /&gt;
= About W3C =&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/Consortium/ About W3C]&lt;br /&gt;
* [http://www.w3.org/Consortium/process W3C Process]&lt;br /&gt;
* [http://www.w3.org/Consortium/membership About W3C membership]&lt;br /&gt;
* [http://www.w3.org/Consortium/Member/List Current members]&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29889</id>
		<title>AppSecEU08 HTML5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29889"/>
				<updated>2008-05-27T10:44:22Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[AppSecEU08 | AppSecEU08]] &amp;gt; [[AppSecEU08#Agenda_and_Presentations_-_May_21-22 | Agenda and Presentations]]&lt;br /&gt;
&lt;br /&gt;
= Slides and Contact =&lt;br /&gt;
&lt;br /&gt;
Slides: [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Would you like fries with that?]&lt;br /&gt;
&lt;br /&gt;
Contact: Thomas Roessler, W3C Security Activity Lead, [mailto:tlr@w3.org tlr@w3.org]&lt;br /&gt;
&lt;br /&gt;
= HTML5 resources =&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/ HTML 5 editor's draft]&lt;br /&gt;
* [http://dev.w3.org/html5/pubnotes/ HTML 5 publication notes]&lt;br /&gt;
* [http://html5.org/tools/web-apps-tracker Web interface to specification changes]&lt;br /&gt;
* [http://twitter.com/whatwg Major changes as a twitter feed]&lt;br /&gt;
* [http://www.w3.org/html/wg/ HTML Working Group Home Page]&lt;br /&gt;
&lt;br /&gt;
Specific parts of the specification that were mentioned during the talk:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#windows Browsing contexts]; [http://www.w3.org/html/wg/html5/#security6 navigation policy]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#origin Origin]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#custom-handlers Custom protocol and content handlers]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#offline Offline Web Applications]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#structured Structured client-side storge]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#crossDocumentMessages Cross Document Messaging] (aka postMessage)&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#server-sent-events server-sent DOM events]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#network Network connections]&lt;br /&gt;
&lt;br /&gt;
Also of interest, but added even more recently:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#sandbox iframe sandboxing]; [http://lists.w3.org/Archives/Public/public-webapi/2008May/0326.html summary of concepts]&lt;br /&gt;
&lt;br /&gt;
= Cross-domain XMLHttpRequest =&lt;br /&gt;
&lt;br /&gt;
* [http://dev.w3.org/2006/waf/access-control/ access-control editor's draft]&lt;br /&gt;
* [http://dev.w3.org/2006/webapi/XMLHttpRequest-2/ XMLHttpRequest Level 2 editor's draft]&lt;br /&gt;
&lt;br /&gt;
Note that the &amp;quot;access-control&amp;quot; specification provides a mechanism for authorizing exceptions to the same-origin policy. How that authorization (and the data retrieved) is used isn't actually specified. For XMLHttpRequest, the governing specification is XMLHttpRequest Level 2.  Don't read one without the other.&lt;br /&gt;
&lt;br /&gt;
Also relevant:&lt;br /&gt;
&lt;br /&gt;
* [http://lists.w3.org/Archives/Public/public-appformats/2008Mar/0017.html IE Team's proposal for Cross Site Requests] (XDomainRequest)&lt;br /&gt;
&lt;br /&gt;
Relevant work is currently occuring in the [http://www.w3.org/2006/webapi/ Web API] and [http://www.w3.org/2006/appformats/ Web Application Formats] Working Groups at W3C. A [http://www.w3.org/2007/12/WebApps-Charter-2007 proposed restructuring] of that work is currently being negotiated.&lt;br /&gt;
&lt;br /&gt;
= About W3C =&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/Consortium/ About W3C]&lt;br /&gt;
* [http://www.w3.org/Consortium/process W3C Process]&lt;br /&gt;
* [http://www.w3.org/Consortium/membership About W3C membership]&lt;br /&gt;
* [http://www.w3.org/Consortium/Member/List Current members]&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29888</id>
		<title>AppSecEU08 HTML5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29888"/>
				<updated>2008-05-27T10:44:05Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[AppSecEU08 | AppSecEU08]] &amp;gt; [[AppSecEU08#Agenda_and_Presentations_-_May_21-22 Agenda and Presentations]]&lt;br /&gt;
&lt;br /&gt;
= Slides and Contact =&lt;br /&gt;
&lt;br /&gt;
Slides: [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Would you like fries with that?]&lt;br /&gt;
&lt;br /&gt;
Contact: Thomas Roessler, W3C Security Activity Lead, [mailto:tlr@w3.org tlr@w3.org]&lt;br /&gt;
&lt;br /&gt;
= HTML5 resources =&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/ HTML 5 editor's draft]&lt;br /&gt;
* [http://dev.w3.org/html5/pubnotes/ HTML 5 publication notes]&lt;br /&gt;
* [http://html5.org/tools/web-apps-tracker Web interface to specification changes]&lt;br /&gt;
* [http://twitter.com/whatwg Major changes as a twitter feed]&lt;br /&gt;
* [http://www.w3.org/html/wg/ HTML Working Group Home Page]&lt;br /&gt;
&lt;br /&gt;
Specific parts of the specification that were mentioned during the talk:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#windows Browsing contexts]; [http://www.w3.org/html/wg/html5/#security6 navigation policy]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#origin Origin]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#custom-handlers Custom protocol and content handlers]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#offline Offline Web Applications]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#structured Structured client-side storge]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#crossDocumentMessages Cross Document Messaging] (aka postMessage)&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#server-sent-events server-sent DOM events]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#network Network connections]&lt;br /&gt;
&lt;br /&gt;
Also of interest, but added even more recently:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#sandbox iframe sandboxing]; [http://lists.w3.org/Archives/Public/public-webapi/2008May/0326.html summary of concepts]&lt;br /&gt;
&lt;br /&gt;
= Cross-domain XMLHttpRequest =&lt;br /&gt;
&lt;br /&gt;
* [http://dev.w3.org/2006/waf/access-control/ access-control editor's draft]&lt;br /&gt;
* [http://dev.w3.org/2006/webapi/XMLHttpRequest-2/ XMLHttpRequest Level 2 editor's draft]&lt;br /&gt;
&lt;br /&gt;
Note that the &amp;quot;access-control&amp;quot; specification provides a mechanism for authorizing exceptions to the same-origin policy. How that authorization (and the data retrieved) is used isn't actually specified. For XMLHttpRequest, the governing specification is XMLHttpRequest Level 2.  Don't read one without the other.&lt;br /&gt;
&lt;br /&gt;
Also relevant:&lt;br /&gt;
&lt;br /&gt;
* [http://lists.w3.org/Archives/Public/public-appformats/2008Mar/0017.html IE Team's proposal for Cross Site Requests] (XDomainRequest)&lt;br /&gt;
&lt;br /&gt;
Relevant work is currently occuring in the [http://www.w3.org/2006/webapi/ Web API] and [http://www.w3.org/2006/appformats/ Web Application Formats] Working Groups at W3C. A [http://www.w3.org/2007/12/WebApps-Charter-2007 proposed restructuring] of that work is currently being negotiated.&lt;br /&gt;
&lt;br /&gt;
= About W3C =&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/Consortium/ About W3C]&lt;br /&gt;
* [http://www.w3.org/Consortium/process W3C Process]&lt;br /&gt;
* [http://www.w3.org/Consortium/membership About W3C membership]&lt;br /&gt;
* [http://www.w3.org/Consortium/Member/List Current members]&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29887</id>
		<title>AppSecEU08 HTML5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29887"/>
				<updated>2008-05-27T10:43:18Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;AppSecEU08 &amp;gt; [[AppSecEU08#Agenda_and_Presentations_-_May_21-22 Agenda and Presentations]]&lt;br /&gt;
&lt;br /&gt;
= Slides and Contact =&lt;br /&gt;
&lt;br /&gt;
Slides: [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Would you like fries with that?]&lt;br /&gt;
&lt;br /&gt;
Contact: Thomas Roessler, W3C Security Activity Lead, [mailto:tlr@w3.org tlr@w3.org]&lt;br /&gt;
&lt;br /&gt;
= HTML5 resources =&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/ HTML 5 editor's draft]&lt;br /&gt;
* [http://dev.w3.org/html5/pubnotes/ HTML 5 publication notes]&lt;br /&gt;
* [http://html5.org/tools/web-apps-tracker Web interface to specification changes]&lt;br /&gt;
* [http://twitter.com/whatwg Major changes as a twitter feed]&lt;br /&gt;
* [http://www.w3.org/html/wg/ HTML Working Group Home Page]&lt;br /&gt;
&lt;br /&gt;
Specific parts of the specification that were mentioned during the talk:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#windows Browsing contexts]; [http://www.w3.org/html/wg/html5/#security6 navigation policy]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#origin Origin]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#custom-handlers Custom protocol and content handlers]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#offline Offline Web Applications]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#structured Structured client-side storge]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#crossDocumentMessages Cross Document Messaging] (aka postMessage)&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#server-sent-events server-sent DOM events]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#network Network connections]&lt;br /&gt;
&lt;br /&gt;
Also of interest, but added even more recently:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#sandbox iframe sandboxing]; [http://lists.w3.org/Archives/Public/public-webapi/2008May/0326.html summary of concepts]&lt;br /&gt;
&lt;br /&gt;
= Cross-domain XMLHttpRequest =&lt;br /&gt;
&lt;br /&gt;
* [http://dev.w3.org/2006/waf/access-control/ access-control editor's draft]&lt;br /&gt;
* [http://dev.w3.org/2006/webapi/XMLHttpRequest-2/ XMLHttpRequest Level 2 editor's draft]&lt;br /&gt;
&lt;br /&gt;
Note that the &amp;quot;access-control&amp;quot; specification provides a mechanism for authorizing exceptions to the same-origin policy. How that authorization (and the data retrieved) is used isn't actually specified. For XMLHttpRequest, the governing specification is XMLHttpRequest Level 2.  Don't read one without the other.&lt;br /&gt;
&lt;br /&gt;
Also relevant:&lt;br /&gt;
&lt;br /&gt;
* [http://lists.w3.org/Archives/Public/public-appformats/2008Mar/0017.html IE Team's proposal for Cross Site Requests] (XDomainRequest)&lt;br /&gt;
&lt;br /&gt;
Relevant work is currently occuring in the [http://www.w3.org/2006/webapi/ Web API] and [http://www.w3.org/2006/appformats/ Web Application Formats] Working Groups at W3C. A [http://www.w3.org/2007/12/WebApps-Charter-2007 proposed restructuring] of that work is currently being negotiated.&lt;br /&gt;
&lt;br /&gt;
= About W3C =&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/Consortium/ About W3C]&lt;br /&gt;
* [http://www.w3.org/Consortium/process W3C Process]&lt;br /&gt;
* [http://www.w3.org/Consortium/membership About W3C membership]&lt;br /&gt;
* [http://www.w3.org/Consortium/Member/List Current members]&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29886</id>
		<title>AppSecEU08 HTML5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29886"/>
				<updated>2008-05-27T10:41:00Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Slides and Contact =&lt;br /&gt;
&lt;br /&gt;
Slides: [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Would you like fries with that?]&lt;br /&gt;
&lt;br /&gt;
Contact: Thomas Roessler, W3C Security Activity Lead, [mailto:tlr@w3.org tlr@w3.org]&lt;br /&gt;
&lt;br /&gt;
= HTML5 resources =&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/ HTML 5 editor's draft]&lt;br /&gt;
* [http://dev.w3.org/html5/pubnotes/ HTML 5 publication notes]&lt;br /&gt;
* [http://html5.org/tools/web-apps-tracker Web interface to specification changes]&lt;br /&gt;
* [http://twitter.com/whatwg Major changes as a twitter feed]&lt;br /&gt;
* [http://www.w3.org/html/wg/ HTML Working Group Home Page]&lt;br /&gt;
&lt;br /&gt;
Specific parts of the specification that were mentioned during the talk:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#windows Browsing contexts]; [http://www.w3.org/html/wg/html5/#security6 navigation policy]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#origin Origin]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#custom-handlers Custom protocol and content handlers]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#offline Offline Web Applications]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#structured Structured client-side storge]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#crossDocumentMessages Cross Document Messaging] (aka postMessage)&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#server-sent-events server-sent DOM events]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#network Network connections]&lt;br /&gt;
&lt;br /&gt;
Also of interest, but added even more recently:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#sandbox iframe sandboxing]; [http://lists.w3.org/Archives/Public/public-webapi/2008May/0326.html summary of concepts]&lt;br /&gt;
&lt;br /&gt;
= Cross-domain XMLHttpRequest =&lt;br /&gt;
&lt;br /&gt;
* [http://dev.w3.org/2006/waf/access-control/ access-control editor's draft]&lt;br /&gt;
* [http://dev.w3.org/2006/webapi/XMLHttpRequest-2/ XMLHttpRequest Level 2 editor's draft]&lt;br /&gt;
&lt;br /&gt;
Note that the &amp;quot;access-control&amp;quot; specification provides a mechanism for authorizing exceptions to the same-origin policy. How that authorization (and the data retrieved) is used isn't actually specified. For XMLHttpRequest, the governing specification is XMLHttpRequest Level 2.  Don't read one without the other.&lt;br /&gt;
&lt;br /&gt;
Also relevant:&lt;br /&gt;
&lt;br /&gt;
* [http://lists.w3.org/Archives/Public/public-appformats/2008Mar/0017.html IE Team's proposal for Cross Site Requests] (XDomainRequest)&lt;br /&gt;
&lt;br /&gt;
Relevant work is currently occuring in the [http://www.w3.org/2006/webapi/ Web API] and [http://www.w3.org/2006/appformats/ Web Application Formats] Working Groups at W3C. A [http://www.w3.org/2007/12/WebApps-Charter-2007 proposed restructuring] of that work is currently being negotiated.&lt;br /&gt;
&lt;br /&gt;
= About W3C =&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/Consortium/ About W3C]&lt;br /&gt;
* [http://www.w3.org/Consortium/process W3C Process]&lt;br /&gt;
* [http://www.w3.org/Consortium/membership About W3C membership]&lt;br /&gt;
* [http://www.w3.org/Consortium/Member/List Current members]&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29885</id>
		<title>AppSecEU08 HTML5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29885"/>
				<updated>2008-05-27T10:37:33Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: /* Contact */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Would you like fries with that? =&lt;br /&gt;
&lt;br /&gt;
''-- a security-minded reader's guide to HTML5''&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Slides (pdf)]&lt;br /&gt;
&lt;br /&gt;
== HTML5 resources ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/ HTML 5 editor's draft]&lt;br /&gt;
* [http://dev.w3.org/html5/pubnotes/ HTML 5 publication notes]&lt;br /&gt;
* [http://html5.org/tools/web-apps-tracker Web interface to specification changes]&lt;br /&gt;
* [http://twitter.com/whatwg Major changes as a twitter feed]&lt;br /&gt;
* [http://www.w3.org/html/wg/ HTML Working Group Home Page]&lt;br /&gt;
&lt;br /&gt;
Specific parts of the specification that were mentioned during the talk:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#windows Browsing contexts]; [http://www.w3.org/html/wg/html5/#security6 navigation policy]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#origin Origin]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#custom-handlers Custom protocol and content handlers]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#offline Offline Web Applications]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#structured Structured client-side storge]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#crossDocumentMessages Cross Document Messaging] (aka postMessage)&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#server-sent-events server-sent DOM events]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#network Network connections]&lt;br /&gt;
&lt;br /&gt;
Also of interest, but added even more recently:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#sandbox iframe sandboxing]; [http://lists.w3.org/Archives/Public/public-webapi/2008May/0326.html summary of concepts]&lt;br /&gt;
&lt;br /&gt;
== Cross-domain XMLHttpRequest ==&lt;br /&gt;
&lt;br /&gt;
* [http://dev.w3.org/2006/waf/access-control/ access-control editor's draft]&lt;br /&gt;
* [http://dev.w3.org/2006/webapi/XMLHttpRequest-2/ XMLHttpRequest Level 2 editor's draft]&lt;br /&gt;
&lt;br /&gt;
Note that the &amp;quot;access-control&amp;quot; specification provides a mechanism for authorizing exceptions to the same-origin policy. How that authorization (and the data retrieved) is used isn't actually specified. For XMLHttpRequest, the governing specification is XMLHttpRequest Level 2.  Don't read one without the other.&lt;br /&gt;
&lt;br /&gt;
Also relevant:&lt;br /&gt;
&lt;br /&gt;
* [http://lists.w3.org/Archives/Public/public-appformats/2008Mar/0017.html IE Team's proposal for Cross Site Requests] (XDomainRequest)&lt;br /&gt;
&lt;br /&gt;
Relevant work is currently occuring in the [http://www.w3.org/2006/webapi/ Web API] and [http://www.w3.org/2006/appformats/ Web Application Formats] Working Groups at W3C. A [http://www.w3.org/2007/12/WebApps-Charter-2007 proposed restructuring] of that work is currently being negotiated.&lt;br /&gt;
&lt;br /&gt;
== Contact ==&lt;br /&gt;
&lt;br /&gt;
Thomas Roessler, W3C Security Activity Lead, [mailto:tlr@w3.org tlr@w3.org]&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29884</id>
		<title>AppSecEU08 HTML5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29884"/>
				<updated>2008-05-27T10:37:13Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: /* Would you like fries with that? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Would you like fries with that? =&lt;br /&gt;
&lt;br /&gt;
''-- a security-minded reader's guide to HTML5''&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Slides (pdf)]&lt;br /&gt;
&lt;br /&gt;
== HTML5 resources ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/ HTML 5 editor's draft]&lt;br /&gt;
* [http://dev.w3.org/html5/pubnotes/ HTML 5 publication notes]&lt;br /&gt;
* [http://html5.org/tools/web-apps-tracker Web interface to specification changes]&lt;br /&gt;
* [http://twitter.com/whatwg Major changes as a twitter feed]&lt;br /&gt;
* [http://www.w3.org/html/wg/ HTML Working Group Home Page]&lt;br /&gt;
&lt;br /&gt;
Specific parts of the specification that were mentioned during the talk:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#windows Browsing contexts]; [http://www.w3.org/html/wg/html5/#security6 navigation policy]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#origin Origin]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#custom-handlers Custom protocol and content handlers]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#offline Offline Web Applications]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#structured Structured client-side storge]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#crossDocumentMessages Cross Document Messaging] (aka postMessage)&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#server-sent-events server-sent DOM events]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#network Network connections]&lt;br /&gt;
&lt;br /&gt;
Also of interest, but added even more recently:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#sandbox iframe sandboxing]; [http://lists.w3.org/Archives/Public/public-webapi/2008May/0326.html summary of concepts]&lt;br /&gt;
&lt;br /&gt;
== Cross-domain XMLHttpRequest ==&lt;br /&gt;
&lt;br /&gt;
* [http://dev.w3.org/2006/waf/access-control/ access-control editor's draft]&lt;br /&gt;
* [http://dev.w3.org/2006/webapi/XMLHttpRequest-2/ XMLHttpRequest Level 2 editor's draft]&lt;br /&gt;
&lt;br /&gt;
Note that the &amp;quot;access-control&amp;quot; specification provides a mechanism for authorizing exceptions to the same-origin policy. How that authorization (and the data retrieved) is used isn't actually specified. For XMLHttpRequest, the governing specification is XMLHttpRequest Level 2.  Don't read one without the other.&lt;br /&gt;
&lt;br /&gt;
Also relevant:&lt;br /&gt;
&lt;br /&gt;
* [http://lists.w3.org/Archives/Public/public-appformats/2008Mar/0017.html IE Team's proposal for Cross Site Requests] (XDomainRequest)&lt;br /&gt;
&lt;br /&gt;
Relevant work is currently occuring in the [http://www.w3.org/2006/webapi/ Web API] and [http://www.w3.org/2006/appformats/ Web Application Formats] Working Groups at W3C. A [http://www.w3.org/2007/12/WebApps-Charter-2007 proposed restructuring] of that work is currently being negotiated.&lt;br /&gt;
&lt;br /&gt;
== Contact ==&lt;br /&gt;
&lt;br /&gt;
Thomas Roessler, W3C Security Activity Lead, [mailto:tlr@w3.org]&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29883</id>
		<title>AppSecEU08 HTML5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29883"/>
				<updated>2008-05-27T10:36:14Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: /* Cross-domain XMLHttpRequest */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Would you like fries with that? =&lt;br /&gt;
&lt;br /&gt;
''-- a security-minded reader's guide to HTML5''&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Slides (pdf)]&lt;br /&gt;
&lt;br /&gt;
== HTML5 resources ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/ HTML 5 editor's draft]&lt;br /&gt;
* [http://dev.w3.org/html5/pubnotes/ HTML 5 publication notes]&lt;br /&gt;
* [http://html5.org/tools/web-apps-tracker Web interface to specification changes]&lt;br /&gt;
* [http://twitter.com/whatwg Major changes as a twitter feed]&lt;br /&gt;
* [http://www.w3.org/html/wg/ HTML Working Group Home Page]&lt;br /&gt;
&lt;br /&gt;
Specific parts of the specification that were mentioned during the talk:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#windows Browsing contexts]; [http://www.w3.org/html/wg/html5/#security6 navigation policy]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#origin Origin]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#custom-handlers Custom protocol and content handlers]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#offline Offline Web Applications]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#structured Structured client-side storge]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#crossDocumentMessages Cross Document Messaging] (aka postMessage)&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#server-sent-events server-sent DOM events]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#network Network connections]&lt;br /&gt;
&lt;br /&gt;
Also of interest, but added even more recently:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#sandbox iframe sandboxing]; [http://lists.w3.org/Archives/Public/public-webapi/2008May/0326.html summary of concepts]&lt;br /&gt;
&lt;br /&gt;
== Cross-domain XMLHttpRequest ==&lt;br /&gt;
&lt;br /&gt;
* [http://dev.w3.org/2006/waf/access-control/ access-control editor's draft]&lt;br /&gt;
* [http://dev.w3.org/2006/webapi/XMLHttpRequest-2/ XMLHttpRequest Level 2 editor's draft]&lt;br /&gt;
&lt;br /&gt;
Note that the &amp;quot;access-control&amp;quot; specification provides a mechanism for authorizing exceptions to the same-origin policy. How that authorization (and the data retrieved) is used isn't actually specified. For XMLHttpRequest, the governing specification is XMLHttpRequest Level 2.  Don't read one without the other.&lt;br /&gt;
&lt;br /&gt;
Also relevant:&lt;br /&gt;
&lt;br /&gt;
* [http://lists.w3.org/Archives/Public/public-appformats/2008Mar/0017.html IE Team's proposal for Cross Site Requests] (XDomainRequest)&lt;br /&gt;
&lt;br /&gt;
Relevant work is currently occuring in the [http://www.w3.org/2006/webapi/ Web API] and [http://www.w3.org/2006/appformats/ Web Application Formats] Working Groups at W3C. A [http://www.w3.org/2007/12/WebApps-Charter-2007 proposed restructuring] of that work is currently being negotiated.&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29882</id>
		<title>AppSecEU08 HTML5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29882"/>
				<updated>2008-05-27T10:32:15Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: /* Cross-domain XMLHttpRequest */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Would you like fries with that? =&lt;br /&gt;
&lt;br /&gt;
''-- a security-minded reader's guide to HTML5''&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Slides (pdf)]&lt;br /&gt;
&lt;br /&gt;
== HTML5 resources ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/ HTML 5 editor's draft]&lt;br /&gt;
* [http://dev.w3.org/html5/pubnotes/ HTML 5 publication notes]&lt;br /&gt;
* [http://html5.org/tools/web-apps-tracker Web interface to specification changes]&lt;br /&gt;
* [http://twitter.com/whatwg Major changes as a twitter feed]&lt;br /&gt;
* [http://www.w3.org/html/wg/ HTML Working Group Home Page]&lt;br /&gt;
&lt;br /&gt;
Specific parts of the specification that were mentioned during the talk:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#windows Browsing contexts]; [http://www.w3.org/html/wg/html5/#security6 navigation policy]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#origin Origin]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#custom-handlers Custom protocol and content handlers]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#offline Offline Web Applications]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#structured Structured client-side storge]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#crossDocumentMessages Cross Document Messaging] (aka postMessage)&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#server-sent-events server-sent DOM events]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#network Network connections]&lt;br /&gt;
&lt;br /&gt;
Also of interest, but added even more recently:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#sandbox iframe sandboxing]; [http://lists.w3.org/Archives/Public/public-webapi/2008May/0326.html summary of concepts]&lt;br /&gt;
&lt;br /&gt;
== Cross-domain XMLHttpRequest ==&lt;br /&gt;
&lt;br /&gt;
* [http://dev.w3.org/2006/waf/access-control/ access-control editor's draft]&lt;br /&gt;
* [http://dev.w3.org/2006/webapi/XMLHttpRequest-2/ XMLHttpRequest Level 2 editor's draft]&lt;br /&gt;
&lt;br /&gt;
Note that the &amp;quot;access-control&amp;quot; specification provides a mechanism for authorizing exceptions to the same-origin policy. How that authorization (and the data retrieved) is used isn't actually specified. For XMLHttpRequest, the governing specification is XMLHttpRequest Level 2.  Don't read one without the other.&lt;br /&gt;
&lt;br /&gt;
Also relevant:&lt;br /&gt;
&lt;br /&gt;
* [http://lists.w3.org/Archives/Public/public-appformats/2008Mar/0017.html IE Team's proposal for Cross Site Requests] (XDomainRequest)&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29881</id>
		<title>AppSecEU08 HTML5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU08_HTML5&amp;diff=29881"/>
				<updated>2008-05-27T10:28:22Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: New page: = Would you like fries with that? =  ''-- a security-minded reader's guide to HTML5''  * [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Slides (pdf)]  == HTML5...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Would you like fries with that? =&lt;br /&gt;
&lt;br /&gt;
''-- a security-minded reader's guide to HTML5''&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/2008/Talks/0521-owasp-html5-tlr/0521-owasp-html5-tlr.pdf Slides (pdf)]&lt;br /&gt;
&lt;br /&gt;
== HTML5 resources ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/ HTML 5 editor's draft]&lt;br /&gt;
* [http://dev.w3.org/html5/pubnotes/ HTML 5 publication notes]&lt;br /&gt;
* [http://html5.org/tools/web-apps-tracker Web interface to specification changes]&lt;br /&gt;
* [http://twitter.com/whatwg Major changes as a twitter feed]&lt;br /&gt;
* [http://www.w3.org/html/wg/ HTML Working Group Home Page]&lt;br /&gt;
&lt;br /&gt;
Specific parts of the specification that were mentioned during the talk:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#windows Browsing contexts]; [http://www.w3.org/html/wg/html5/#security6 navigation policy]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#origin Origin]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#custom-handlers Custom protocol and content handlers]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#offline Offline Web Applications]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#structured Structured client-side storge]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#crossDocumentMessages Cross Document Messaging] (aka postMessage)&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#server-sent-events server-sent DOM events]&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#network Network connections]&lt;br /&gt;
&lt;br /&gt;
Also of interest, but added even more recently:&lt;br /&gt;
&lt;br /&gt;
* [http://www.w3.org/html/wg/html5/#sandbox iframe sandboxing]; [http://lists.w3.org/Archives/Public/public-webapi/2008May/0326.html summary of concepts]&lt;br /&gt;
&lt;br /&gt;
== Cross-domain XMLHttpRequest ==&lt;br /&gt;
&lt;br /&gt;
*&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_AppSec_Europe_2008_-_Belgium&amp;diff=29880</id>
		<title>OWASP AppSec Europe 2008 - Belgium</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_AppSec_Europe_2008_-_Belgium&amp;diff=29880"/>
				<updated>2008-05-27T10:15:17Z</updated>
		
		<summary type="html">&lt;p&gt;Tlr: /* Agenda and Presentations - May 21-22 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:Owasp_banner_EU08.jpg]]&lt;br /&gt;
&lt;br /&gt;
Welcome to the European OWASP Application Security Conference! After successful OWASP Conferences in the United States and Europe, we are back in Belgium: 5 tutorials and 2 conference tracks in the historic center of Ghent on May 19-22 2008! &lt;br /&gt;
&lt;br /&gt;
The conference is stuffed with top notch presentations from industry recognised speakers and technical experts on the latest application security risks and trends. New for AppSec Europe: technical vendor demos and a Capture the Flag! &lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
[[Image:GhentEU2008.JPG]]&lt;br /&gt;
&lt;br /&gt;
The historic center of  [http://en.wikipedia.org/wiki/Ghent Ghent], Belgium May 19th-22nd.&lt;br /&gt;
&lt;br /&gt;
[[OWASP_AppSec_Europe_2008_-_Belgium/Training | Tutorial Days: May 19th-20th]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP_AppSec_Europe_2008_-_Belgium/Agenda | Main Conference: May 21st-22nd]]&lt;br /&gt;
&lt;br /&gt;
'''Registration is available via the OWASP Conference Cvent site at: [http://guest.cvent.com/i.aspx?4W,M3,7b36ecdc-1234-4d63-bc08-898a7bf60b2a Cvent link]'''&lt;br /&gt;
&lt;br /&gt;
'''If you are registering as a Speaker or Sponsor, please use the following link: [http://guest.cvent.com/i.aspx?4W,M3,49b0aaab-82ef-4a36-a982-6e56a485c531 Cvent link for speakers/sponsors]'''&lt;br /&gt;
&lt;br /&gt;
You may want to print out [http://local.google.com/maps/ms?ie=UTF8&amp;amp;hl=en&amp;amp;msa=0&amp;amp;msid=106138833491653132955.00044c6dc6d591427c620&amp;amp;ll=51.059388,3.729258&amp;amp;spn=0.019879,0.040169&amp;amp;z=15|usefull this map] of OWASP AppSec EU 2008 locations in Ghent.&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations - May 21-22==&lt;br /&gt;
&lt;br /&gt;
The agenda follows the successful OWASP conference two tracks format, with opening keynotes and presentations in the main auditorium, split tracks in the middle of the day, and closing pannel discussions back in the main auditorium both days. As in the previous editions, the OWASP AppSec Europe 2008 conference will feature a refereed papers track.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Day 1 - May 21, 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | || style=&amp;quot;width:40%; background:#BC857A&amp;quot; | Track 1: Auditorium &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; | Track 2: Council Room&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:00-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Coffee&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:05 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Welcome to OWASP AppSec 2008 Conference &lt;br /&gt;
''Sebastien Deleersnyder''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:05-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Keynote: The Great Information Security Scrap Yard Challenge&lt;br /&gt;
''Mark Curphey, Microsoft''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:45-10:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | OWASP State of the Union&lt;br /&gt;
''Dinis Cruz''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:20-10:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_The_OWASP_ESAPI_project | Fundamental Application Security Building Blocks - The Benefits of Establishing an Enterprise Security API (ESAPI) for Your Organization]] ([http://www.owasp.org/images/c/cd/AppSecEU08-ESAPI.ppt ppt])&lt;br /&gt;
''[[User:Wichers | Dave Wichers]], Aspect Security''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_Trends_in_Web_Hacking_Incidents:_What's_hot_for_2008 | Trends in Web Hacking: What's hot in 2008&amp;lt;br/&amp;gt;Analysis of the Web Hacking Incidents Database (WHID)]] ([[Media:AppSecEU2008-WHID.ppt‎|ppt]])&lt;br /&gt;
''[http://blog.shezaf.com Ofer Shezaf], Breach''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:20-12:00 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_Evaluation_Criteria_for_Web_Application_Firewalls | Evaluation Criteria for Web Application Firewalls]] ([http://www.owasp.org/images/f/f4/AppSecEU08_Evaluation_Criteria_for_Web_Application_Firewalls.pdf pdf])&lt;br /&gt;
''[http://blog.ivanristic.com Ivan Ristic], Breach''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_HTML5 | HTML5 security]]&lt;br /&gt;
''Thomas Roessler''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:00-12:30 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_The_OWASP_ORIZON_project | The OWASP Orizon Project internals]] ([http://www.owasp.org/images/0/0b/The_Owasp_Orizon_Project_Internals_v2_2_Paolo.ppt ppt])&lt;br /&gt;
''Paolo Perego''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_Remo_presentation |Remo presentation - Positive ModSecurity rulesets / Input validation]] ([http://www.owasp.org/images/f/f3/AppSecEU08_Remo_Presentation.pdf pdf])&lt;br /&gt;
''Christian Folini''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:30-14:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:00-14:40 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_Best_Practices_Guide_Web_Application_Firewalls | Best Practices Guide: Web Application Firewalls]] ([http://www.owasp.org/images/a/a4/AppSecEU08-BPWAF.pdf pdf])&lt;br /&gt;
''Alexander Meisel, art of defence''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_Input_validation:_the_Good,_the_Bad_and_the_Ugly| &lt;br /&gt;
Input validation: the Good, the Bad and the Ugly]] ([http://www.owasp.org/images/4/4c/AppSecEU08-JohanPeeters.pdf pdf])&lt;br /&gt;
[[Johan_Peeters|''Johan Peeters'']]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:40-15:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_NTLM_Relay_Attacks | NTLM Relay Attacks]] ([http://www.owasp.org/images/2/20/AppSecEU08_NTLM_Relay_Attacks-pptx.ppt ppt])&lt;br /&gt;
''Eric Rachner''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_PHPIDS_Monitoring_attack_surface_activity|PHPIDS Monitoring attack surface activity]] ([http://www.owasp.org/images/d/dd/AppSec08_PHPIDS_Monitoring_attack_surface_activity.ppt ppt])&lt;br /&gt;
''[http://mario.heideri.ch/ Mario Heiderich]''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:20-15:50 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_Agile_Security_Breaking_the_Waterfall_Mindset | Agile Security - Breaking the Waterfall Mindset of the Security Industry]] ([http://www.owasp.org/images/b/b8/AppSecEU08-Agile_and_Secure.ppt ppt])&lt;br /&gt;
''[[User:Wichers | Dave Wichers]], Aspect Security''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Security framework is not in the code ([http://www.owasp.org/images/a/ae/AppSecEU08-Sec_Frm_not_in_code.pdf pdf])&lt;br /&gt;
''Sam Reghenzi''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:50-16:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:10-17:00 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_Exploiting_Online_Games | Exploiting Online Games]]&lt;br /&gt;
''[[User:gem | Gary McGraw]], Cigital''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08 SHIELDS: metrics, tools and Internet services to improve security in application developments | SHIELDS: metrics, tools and Internet services to improve security in application developments]]&lt;br /&gt;
''[[AppSecEU08 Domenico Rotondi | Domenico Rotondi]], TXT e-solutions Spa''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:00-18:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Panel: The PCI 6.6 dogfight - to Scan or to WAF, this is the question&lt;br /&gt;
Moderator: [[User:Oshezaf|Ofer Shezaf]]&amp;lt;br/&amp;gt;&lt;br /&gt;
Panelists (updated): Scanning side: Ory Segal (''IBM''), Matias Madou (''Fortify''), Gary McGraw (''Cigital''); WAF side: Christian Folini (''netnea.com''), Mario Heiderich (''PHPIDS''), Alexander Meisel (''Art of Defence'')&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 18:00-19:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08 Leader Meeting | OWASP Leader Meeting ]] Organized by ''[[User:Mmeucci | Matteo Meucci]], Minded Security''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 19:00-21:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP Social Gathering: Dinner and Drinks at the Monasterium&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Day 2 - May 22, 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | || style=&amp;quot;width:40%; background:#BC857A&amp;quot; | Track 1: Auditorium &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; | Track 2: Council Room&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:00-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Coffee&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-9:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Keynote: [[AppSecEU08 Software Security State of the Practice 2008 | Software Security: State of the Practice 2008]]&lt;br /&gt;
''[[user:gem | Gary McGraw]], Cigital''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 9:40-10:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Tour of OWASP projects&lt;br /&gt;
''Dinis Cruz (Chief OWASP Evangelist),  [[User:Wichers | Dave Wichers]] (OWASP Board), Michael Eddington (OWASP Encoding Project, .NET Web Service Validation Project) ([http://www.owasp.org/images/f/f8/AppSecEU08-ReformAndCanoodle-Eddington.ppt ppt]) and Mark Roxberry (OWASP .NET Project)''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:20-10:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | Graph Analysis for WebApps: From Nodes to Edges&lt;br /&gt;
''Simon Roses Femerling, Microsoft''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | The OWASP Education Project&lt;br /&gt;
''[[User:Konbloma | Martin Knobloch]], Sogeti Nederland B.V.''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:20-12:00 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[ AppSecEU08_The_Dynamic_Taint_Propagation_Finding_Vulnerabilities_Without_Attacking | Dynamic Taint Propagation: Finding Vulnerabilities Without Attacking]] ([http://www.owasp.org/images/d/d3/AppSecEU08_Dynamic_Taint_Propagation_OWASP.ppt ppt])&lt;br /&gt;
''[[User:mmadou | Matias Madou]], Fortify''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_Threat_Modeling_for_Application_Designers_and_Architects | Threat Modeling for Application Designers &amp;amp; Architects]] ([http://www.owasp.org/images/3/38/AppSecEU08_Threat_Modeling_AppSecEU08_v_9_2.ppt ppt])&lt;br /&gt;
''[[AppSecEU08 Shay Zalalichin Shay Zalalichin | Shay Zalalichin]]''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:00-12:30 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; |  &lt;br /&gt;
[[AppSecEU08_Scanstud_-_Evaluating_static_analysis_tools | Scanstud: Evaluating static analysis tools]] ([https://www.owasp.org/images/7/76/Johns_jodeit_-_ScanStud_OWASP_Europe_2008.pdf pdf])&lt;br /&gt;
&lt;br /&gt;
''[http://www.informatik.uni-hamburg.de/SVS/personnel/martin/index.php Martin Johns]'', ''Moritz Jodeit'', ''Wolfgang Koeppl'', ''Martin Wimmer''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08_Office_2.0:_Software_as_a_Service%2C_Security_on_the_Sidelines | Office 2.0:  Software as a Service, Security on the Sidelines?]]  &lt;br /&gt;
''[[User:JohnH | John Heasman]], NGSSoftware''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:30-14:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:00-14:40 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[AppSecEU08 How Data Privacy affects Applications and Databases | How Data Privacy affects Applications and Databases]] ([http://www.owasp.org/images/6/61/AppSecEU08-DeMaeyerDirk.pdf pdf])&lt;br /&gt;
''[[AppSecEU08 Dirk De Maeyer | Dirk De Maeyer]]''&lt;br /&gt;
 | rowspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [http://www.cs.kuleuven.be/~lieven/AppSec2008/program.html Refereed papers track] &lt;br /&gt;
'''Invited talk:''' &lt;br /&gt;
&lt;br /&gt;
''Prof. Dieter Gollmann:'' Know Thyself! &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:40-14:50 || rowspan=&amp;quot;3&amp;quot; style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; |  [[AppSecEU08_The_OWASP_Anti-Samy_project | The OWASP Anti-Samy project]] ([http://www.owasp.org/images/4/47/AppSecEU08-AntiSamy.ppt ppt])&lt;br /&gt;
''Jason Li, Aspect Security''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:50-15:10 &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [http://www.cs.kuleuven.be/~lieven/AppSec2008/program.html Refereed papers track]&lt;br /&gt;
''fukami and Ben Fuhrmannek:'' [http://www.owasp.org/images/1/10/OWASP-AppSecEU08-Fukami.pdf SWF and the Malware Tragedy]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:10-15:20  &lt;br /&gt;
 | rowspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [http://www.cs.kuleuven.be/~lieven/AppSec2008/program.html Refereed papers track]&lt;br /&gt;
''Andrew Petukhov and Dmitry Kozlov:'' [http://www.owasp.org/images/3/3e/OWASP-AppSecEU08-Petukhov.pdf Detecting Security Vulnerabilities in Web Applications Using Dynamic Analysis with Penetration Testing]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:20-15:30 || rowspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | Google-Hacking and Google-Shielding ([http://www.owasp.org/images/6/6a/AppSecEU08-BeyondGoogleHacking-AmichaiShulman.ppt ppt])&lt;br /&gt;
''Amichai Shulman''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:30-15:50&lt;br /&gt;
 |  style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [http://www.cs.kuleuven.be/~lieven/AppSec2008/program.html Refereed papers track]&lt;br /&gt;
''Matias Madou, Edward Lee, Jacob West and Brian Chess:'' [http://www.owasp.org/images/9/9d/OWASP-AppSecEU08-Madou.pdf Watch What You Write: Preventing Cross-Site Scripting by Observing Program Output]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:50-16:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo - CTF&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:10-16:30 || rowspan=&amp;quot;3&amp;quot; style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | Client-side security&lt;br /&gt;
''pdp''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [http://www.cs.kuleuven.be/~lieven/AppSec2008/program.html Refereed papers track]&lt;br /&gt;
''Arshan Dabirsiaghi:'' [http://www.owasp.org/images/1/1b/OWASP-AppSecEU08-Dabirsiaghi.pdf Building and Stopping Next Generation XSS Worms]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:30-16:50&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | [http://www.cs.kuleuven.be/~lieven/AppSec2008/program.html Refereed papers track]&lt;br /&gt;
''Etienne Janot and Pavol Zavarsky:'' [http://www.owasp.org/images/5/57/OWASP-AppSecEU08-Janot.pdf Preventing SQL Injections in Online Applications: Study, Recommendations and Java Solution Prototype Based on the SQL DOM]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:50-17:00&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:00-18:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Panel: How to “sell” web application security to your organisation?&lt;br /&gt;
Moderator: tbd&lt;br /&gt;
Panelists: tbd&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 18:00-18:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Conference Wrap Up - Dave Wichers, OWASP Conferences Chair &lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Venue: Aula, Ghent University, Voldersstraat 9, 9000 Ghent [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Voldersstraat+9,+9000+Gent&amp;amp;jsv=107&amp;amp;sll=50.994753,3.745665&amp;amp;sspn=0.154284,0.466919&amp;amp;ie=UTF8&amp;amp;ll=51.054749,3.723121&amp;amp;spn=0.00963,0.029182&amp;amp;z=15&amp;amp;iwloc=addr Google Maps Link] &lt;br /&gt;
&lt;br /&gt;
Registration is available via the OWASP Conference Cvent site at: [http://guest.cvent.com/i.aspx?4W,M3,7b36ecdc-1234-4d63-bc08-898a7bf60b2a Cvent link]&lt;br /&gt;
&lt;br /&gt;
==Tutorial Days -  May 19-20== &lt;br /&gt;
&lt;br /&gt;
OWASP arranged for several Application Security tutorials on May 19th-20th, the days prior to the conference. &lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | T1. Building and Testing Secure Web Applications&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#F2F2F2&amp;quot; | Most developers, IT professionals, and auditors learn what they know about application security on the job, usually by making mistakes. Application security is just not a part of many computer science curricula today and most organizations have not focused on instituting a culture that includes application security as a core part of their IT security efforts. This powerful two day course focuses on the most common web application security problems, including the OWASP Top Ten. The course will introduce and demonstrate hacking techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities into their code.&lt;br /&gt;
&lt;br /&gt;
Trainer: Jason Li, [http://www.aspectsecurity.com Aspect Security] - [[OWASP_AppSec_Europe_2008_-_Belgium/Training#T1._Building_and_Testing_Secure_Web_Applications_-_2-Day Course_-_May_19-20,_2008 | Read more here!]]&lt;br /&gt;
 |-&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | T2. Leading the Development of Secure Applications&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#F2F2F2&amp;quot; | In this one-day management session you’ll get the answers to the ten key questions that most CIOs and development managers face when trying to improve security in the development process. The course provides proven techniques and valuable lessons learned that can be applied to projects at any phase of their application’s lifecycle. &lt;br /&gt;
&lt;br /&gt;
Trainer: Arshan Dabirsiaghi, [http://www.aspectsecurity.com Aspect Security] - [[OWASP_AppSec_Europe_2008_-_Belgium/Training#T2._Leading_the_Development_of_Secure_Applications_-_1-Day_Course_-_May_19,_2008 | Read more here!]]&lt;br /&gt;
 |-&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | T3. Building Secure Rich Internet Applications&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#F2F2F2&amp;quot; | Rich Internet applications using technologies like Ajax, Flash, ActiveX, and Java Applets require special attention to secure. This one day training addresses the special issues that arise in this type of application development. &lt;br /&gt;
&lt;br /&gt;
Trainer: Arshan Dabirsiaghi, [http://www.aspectsecurity.com Aspect Security] - [[OWASP_AppSec_Europe_2008_-_Belgium/Training#T3._Building_Secure_Rich_Internet_Applications_-_1-Day_Course_-_May_20,_2008 | Read more here!]]&lt;br /&gt;
 |-&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | T4. Building Secure Web Services &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#F2F2F2&amp;quot; | The movement towards Web Services and Service Oriented architecture (SOA) paradigms requires new security paradigms to deal with new risks posed by these architectures. This session takes a pragmatic approach towards identifying Web Services security risks and selecting and applying countermeasures to the application, code, web servers, databases, application, and identity servers and related software. Many enterprises are currently developing new Web Services and/or adding and acquiring Web Services functionality into existing applications -- now is the time to build security into the system! &lt;br /&gt;
&lt;br /&gt;
Trainer: [[User:wichers | Dave Wichers]], [http://www.aspectsecurity.com Aspect Security] - [[OWASP_AppSec_Europe_2008_-_Belgium/Training#T4._Building_Secure_Web_Services_-_2-Day_Course_-_May_19-20,_2008 | Read more here!]]&lt;br /&gt;
 |-&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | T5. Open Source ModSecurity Training &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#F2F2F2&amp;quot; | ModSecurity is currently the most widely deployed web application firewall (WAF) product. This two-day class is for those people who want to learn how to build, deploy, and use ModSecurity in the most effective manner. The course will cover the open source ModSecurity Console, which helps manage alerts on suspicious web activity targeting your web servers. The course also provides an in-depth look at the extremely powerful ModSecurity Rules Language. &lt;br /&gt;
&lt;br /&gt;
Trainer: Ryan Barnett, Breach - [[OWASP_AppSec_Europe_2008_-_Belgium/Training#T5._ModSecurity_Boot-Camp_Training_-_2-Day_Course_-_May_19-20,_2008 | Read more here!]]&lt;br /&gt;
|}&lt;br /&gt;
More information about the tutorials are [[OWASP_AppSec_Europe_2008_-_Belgium/Training | online]].&lt;br /&gt;
&lt;br /&gt;
Venue: Monasterium PoortAckere, Oude Houtlei 56, 9000 Gent [http://www.monasterium.be/ http://www.monasterium.be/]&lt;br /&gt;
&lt;br /&gt;
==Cocktail Party - May 20, sponsored by Breach Security==&lt;br /&gt;
&lt;br /&gt;
In what is also becoming a tradition, there will be a cocktail party the night before the conference begins, sponsored by Breach Security. The free and open for all conference attendees event will be held at the Vintage Wine Bar at 6:30pm. We would appreciate it if you let us know if you are coming so we can be ready, please mail ofers@breach.com to confirm.&lt;br /&gt;
&lt;br /&gt;
[[Media:AppSec_EU_2008_Breach_Party.pdf|Details and direction map]] (updated May 7th with map and instructions from Monasterium Poortackere, the location of the training classes)&lt;br /&gt;
&lt;br /&gt;
==Evening Social Event - May 21==&lt;br /&gt;
&lt;br /&gt;
At every conference we have an evening social event the first night. This allows participants to have some unstructured time to mingle with the other attendees. They are always fun and typically attract about half the conference attendees. This year's event will be a Flemish buffet with special Belgian beers at the Monasterium (near the conference location).&lt;br /&gt;
&lt;br /&gt;
Registration is available via the OWASP Conference Cvent site at: [http://guest.cvent.com/i.aspx?4W,M3,7b36ecdc-1234-4d63-bc08-898a7bf60b2a Cvent link]&lt;br /&gt;
&lt;br /&gt;
==OWASP Band - May 21, sponsored by Breach Security ==&lt;br /&gt;
&lt;br /&gt;
If that is not enough: tune in for the OWASP Band! Check out the vibes of last year [[OWASP Band | online]]. After the OWASP Dinner you can play, dance or listen to the greatest open-source band: THE OWASP Band. You play an instrument; the neighbours don't complain on your singing talents: contact dinis.cruz &amp;lt;at&amp;gt; owasp.org!&lt;br /&gt;
&lt;br /&gt;
Venue: [http://www.whitecatbelgium.com/ The White Cat]&lt;br /&gt;
Time: 23h&lt;br /&gt;
&lt;br /&gt;
Be there, or be ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
* OWASP arranged for a room block of 20 Executive Deluxe rooms at the [http://www.nh-hotels.com/nh/en/hotels/belgium/ghent/nh-gent-belfort.html NH Gent Belfort] at a rate of €199 per night. This room block is being held through April 11!! After that date, there is no guarantee that rooms at this rate will be available at the NH Gent Belfort.&lt;br /&gt;
* OWASP attendees have an option for 20 rooms at € 122 and 10 rooms at € 132 per night at the [http://www.monasterium.be Hotel Monasterium PoortAckere] up until April 30. Use OWASP as reference when booking your room. Please note that there are no more rooms for the night of May 22.&lt;br /&gt;
* OWASP arranged for a room block of 25 rooms at the IBIS hotels. You can already contact them on [http://www.ibishotel.com/ibis/fichehotel/gb/ibi/1455/fiche_hotel.shtml Hotel Ibis Gent Centrum Opera] (€ 89 per night - 10 rooms) and [http://www.ibishotel.com/ibis/fichehotel/gb/ibi/0961/fiche_hotel.shtml Hotel Ibis Gent Centrum Kathedraal] (€ 99 per night - 15 rooms of which 3 still available for the 22nd) - reservations through e-mail: H0961-RE at accor.com or fax: 0032/9 233 10 00 (before April 19 - reference OWASP).&lt;br /&gt;
&lt;br /&gt;
It is difficult getting rooms at reduced prices, as there is a medical congress around the same time in Ghent. You will find it difficult to get a room for the night of May 22. We recommend you then book a room for one night near the airport of [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=hotels+zaventem,+belgium&amp;amp;ie=UTF8&amp;amp;z=11 Brussels].&lt;br /&gt;
&lt;br /&gt;
The following is a list of nearby accommodations that may have availability:&lt;br /&gt;
&lt;br /&gt;
* [http://www.gent.be/eCache/THE/44/235.html List of hotels in Ghent]&lt;br /&gt;
* [http://www.hotelnazareth.be/ Hotel Vandervalken Nazareth - on Highway 5 minutes from Ghent]&lt;br /&gt;
* [http://www.bedandbreakfast-gent.be/en/home.php A list of bed and breakfasts in Ghent]&lt;br /&gt;
* [http://www.jeugdherbergen.be/jeugdherbergen/gent/ Youth hostels in Ghent]&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
If you are flying in you'll come through [http://www.brusselsairport.be Brussels Airport]. From there  it is 65 km to Ghent. The airport train station is located below the terminal (basement level-1). Up to 4 trains an hour connect the airport to Brussels North, Brussels Central and Brussels Midi stations. The easiest way is then to take the train to Ghent Sint-Pieters (directly or through Brussels).&lt;br /&gt;
&lt;br /&gt;
To travel by train to the conferene come through Gent Sint-Pieters, see the [http://www.b-rail.be/main/E/ Belgian Railways Website]. &lt;br /&gt;
&lt;br /&gt;
'''Next Tuesday May 20th, the Belgian railway is on strike!''' If you are flying in towards Brussels Airport, There will be long queues for the taxis. I advise to contact airport transport beforehand to reserve a place upfront. Possible services to and from Ghent are:&lt;br /&gt;
* [http://www.taxi2airport.be/ http://www.taxi2airport.be/]&lt;br /&gt;
* [http://www.palitax.be/ http://www.palitax.be/]&lt;br /&gt;
* [http://www.taxi-eurojet.be/ http://www.taxi-eurojet.be/]&lt;br /&gt;
If you are travelling with HST like Eurostar or Thalys: check with them it they will ride.&lt;br /&gt;
&lt;br /&gt;
From Ghent Sint-Pieters station tram nr 1 (direction Evergem Brielken) is the quickest and most comfortable way to travel to the city centre (stop KORTE MEER: from there it is a 150m walk to the Ghent Aula). The transport system is Ghent is excellent and always on time. A single ticket costs € 1.50 if bought in the bus/tram or € 1.20 if bought from ticket machine of small kiosk called lijnwinkel, such ticket is valid for an hour's travel on all trams and buses. &lt;br /&gt;
&lt;br /&gt;
If you are coming by car, Ghent can be reached through the E40 and the E17. There are 2 parkings nearby: Parking Korte Meer and Parking Kouter.&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
Registration is available via the OWASP Conference Cvent site at: [http://guest.cvent.com/i.aspx?4W,M3,7b36ecdc-1234-4d63-bc08-898a7bf60b2a Cvent link]&lt;br /&gt;
&lt;br /&gt;
The conference fee for this conference is :&lt;br /&gt;
&lt;br /&gt;
* Standard: 350 Euros, OWASP Members: 300 Euros, Students: 225 Euros. &lt;br /&gt;
* Conference Dinner (Evening of May 21st): 50 Euros&lt;br /&gt;
* Conference Tutorials: 825 Euros, Student Fee: 430 Euros&lt;br /&gt;
* [http://2008.confidence.org.pl/ CONFidence Poland 2008] members get a € 35 reduction on OWASP (see OWASP On a Plane below).&lt;br /&gt;
* [http://www.issa-be.org ISSA], [http://www.isaca.be ISACA] and [http://www.lsec.be L-SEC] Members get a € 35 reduction.&lt;br /&gt;
&lt;br /&gt;
Note: To save on processing expenses, all fees paid for the OWASP conference are non-refundable. OWASP can accomodate transfers of registrations from one person to another, if such an adjustment becomes necessary.&lt;br /&gt;
&lt;br /&gt;
==OWASP on a Plane - CONFidence 2008==&lt;br /&gt;
This year's [http://2008.confidence.org.pl/lang-pref/en/ CONFidence 2008] will take place on 16-17.05.2008 in Cracow (Poland). They have decided to spend Saturday morning talking about OWASP-related projects. No more excuses: you can attend 2 OWASP events in a row in Europe!&lt;br /&gt;
&lt;br /&gt;
==Conference Committee==&lt;br /&gt;
&lt;br /&gt;
OWASP Conferences Chair: Dave Wichers - Aspect Security - dave.wichers 'at' owasp.org&lt;br /&gt;
&lt;br /&gt;
2008 EU Planning Committee Chair: Sebastien Deleersnyder - Telindus - seba 'at' owasp.org&lt;br /&gt;
&lt;br /&gt;
Vendor Exhibition Chair: Pravir Chandra - Cigital - chandra 'at' cigital.com&lt;br /&gt;
&lt;br /&gt;
Capture the Flag Chair: Pieter Danhieux - Ernst &amp;amp; Young - pieter.danhieux 'at' be.ey.com&lt;br /&gt;
&lt;br /&gt;
Refereed Papers Chair: Lieven Desmet - KU Leuven - Lieven.Desmet 'at' cs.kuleuven.ac.be&lt;br /&gt;
&lt;br /&gt;
== Affiliated Partners ==&lt;br /&gt;
We are glad to have the local support of:&lt;br /&gt;
* ISACA&lt;br /&gt;
* ISSA&lt;br /&gt;
* L-SEC&lt;br /&gt;
* Katholieke Universiteit Leuven&lt;br /&gt;
&lt;br /&gt;
==[[OWASP AppSec Conference Sponsors | Conference Sponsors]]==&lt;br /&gt;
&lt;br /&gt;
The following organizations are sponsors for this conference. If you are interested in sponsoring an OWASP conference, please contact OWASP at: conferences 'at' owasp.org.&lt;br /&gt;
&lt;br /&gt;
[http://www.aspectsecurity.com https://www.owasp.org/images/d/d1/Aspect_logo.gif]&lt;br /&gt;
[http://www.telindus.com https://www.owasp.org/images/b/b3/Telindus.jpg]&lt;br /&gt;
[http://www.imperva.com/ https://www.owasp.org/images/d/de/Imperva_2color_RGB.jpg]&lt;br /&gt;
[http://www.fortifysoftware.com https://www.owasp.org/images/a/ac/Fortify.jpg] &lt;br /&gt;
[http://www.ibm.com https://www.owasp.org/images/2/2a/IBM_logo_black.jpg] &lt;br /&gt;
&lt;br /&gt;
More information about conference sponsorship is available [[OWASP AppSec Conference Sponsors | here]].&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Tlr</name></author>	</entry>

	</feed>