<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Walden</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Walden"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Walden"/>
		<updated>2026-05-26T15:04:41Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Global_Industry_Committee_-_Application_2&amp;diff=73513</id>
		<title>Global Industry Committee - Application 2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Global_Industry_Committee_-_Application_2&amp;diff=73513"/>
				<updated>2009-11-16T20:27:19Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[How to Join a Committee|Click here to return to 'How to Join a Committee' page]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE APPLICATION FORM''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Applicant's Name'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;Alexander Fry&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Current and past OWASP Roles''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|SoC 2008 Reviewer for Teachable Static Analysis Workbench and Source Code Review OWASP Projects&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Committee Applying for''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|OWASP Global Industry Committee.&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Please be aware that for an application to be considered by the board, '''you MUST have 5 recommendations'''.  &lt;br /&gt;
An incomplete application will not be considered for vote.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;8&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE RECOMMENDATIONS''' &lt;br /&gt;
 |- &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Who Recommends/Name''' &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Role in OWASP'''&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Recommendation Content''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''1'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Nishi Kumar'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Contributor of Live CD Project'''&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Alexander is bright and dedicated towards security. His involvement in Industry committe will be very valuable. '''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''2'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''James Walden'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Project leader for Source Code Review OWASP Projects'''&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Alexander has contacts that would let him reach out to industry areas OWASP hasn't impacted yet.'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''3'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''4'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''5'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=49606</id>
		<title>Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=49606"/>
				<updated>2008-12-19T19:09:38Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The major project objectives have been accomplished:&lt;br /&gt;
# We have finalized the workflow for introducing static analysis into OWASP projects.&lt;br /&gt;
# We have submitted 10 OWASP projects to be analyzed on the owasp.fortify.com site to establish an OWASP baseline.&lt;br /&gt;
# We have submitted the 25 most popular open source PHP projects to the be analyzed on the owasp.fortify.com site to establish an open source baseline.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We spent the time since the project midpoint submitting projects to the owasp.fortify.com site.  The current status of tasks is:&lt;br /&gt;
# Workflow for introducing static analysis into OWASP projects (100%).&lt;br /&gt;
# Analyzed 10 OWASP projects (100%).&lt;br /&gt;
# Analyzed 25 most popular open source PHP projects on owasp.fortify.com (100%).&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
All Alpha criteria are fulfilled.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
All Beta criteria are fulfilled.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The OWASP EU Summit presentation has been uploaded to fulfill that requirement.&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
To ensure that this project leads to continuing improvement in the security of OWASP projects, we need more OWASP project leaders to incorporate static analysis into their project's software development lifecycle.  We have received only one volunteer who was willing to take the time to incorporate static analysis into his project: Yiannis, project leader of the JBroFuzz project.  We can analyze OWASP projects on our own, but it's important to include static analysis as part of the lifecycle.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=49391</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=49391"/>
				<updated>2008-12-16T14:53:17Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: /* Process */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
This project involving creating a process for integrating the Fortify Open Review Process into the OWASP project development lifecycle and working with Fortify to develop and test their new Open Review site at [http://owasp.fortify.com/ http://owasp.fortify.com/].  The [https://www.owasp.org/images/c/c9/OWASPEU_SourceReview.ppt OWASP EU Summit presentation] contains a more detailed summary of the project.&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
&lt;br /&gt;
The goals of this project were to:&lt;br /&gt;
&lt;br /&gt;
# Create a process for integrating the Fortify Open Review into open source development, so that source code review can be a required step in OWASP development.&lt;br /&gt;
# Test functionality of the new Fortify Open Review site introduced in Summer 2008.&lt;br /&gt;
# Scan 10 OWASP projects with the Fortify Open Review to verify the site's functionality and establish a baseline.&lt;br /&gt;
# Scan 25 popular open source PHP projects to verify the site's ability to handle large scale projects and establish a baseline.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this workflow is to integrate and automate SCA into the development cycle of open source applications for the sole purpose of decreasing software vulnerabilities.  This effort can, and should, be supplemented by a manual code review as described in the OWASP Open Review Project.  The workflow diagrams can be found in [https://www.owasp.org/index.php/Image:Workflow_July_11a.zip Workflow.zip].  Within the ZIP file, overview.pdf describes the relationships between the different parts of the workflow. The file start.pdf describes the first step of the workflow which verifies that the project is an OWASP project.  If it is not then the project is added as a new OWASP project [[Image:Workflow_Draft1.pdf#file]].  Once the project is established as an OWASP project, it can be added by an OWASP administrator (contact the project mailing list below to contact an OWASP administrator) to the Fortify Open Review (reference createProject.pdf).  &lt;br /&gt;
&lt;br /&gt;
As described in the [http://www.owasp.org/index.php/Category:OWASP_Open_Review_Project_owasp.fortify.com_FAQ Fortify Open Review process], the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where the project is checked out from its repository and the Open Review scan is updated on a weekly basis, or a one time analysis as part of their usual development process (see waterfall.pdf and iterative.pdf) after unit testing and prior to final system testing.   The single analysis requires the evaluator to produce and upload a Fortify FPR scan file, which requires either that the evaluator uses their own copy of Fortify SCA or contacts an OWASP administrator via the project mailing list to request a scan.   In order to track project progress over time, single analyses of major project versions will be maintained on the project web site so that software vulnerability metrics can be tracked.  The continuous evaluation is automated, does not require the developer have a Fortify SCA license.  There are additional open source static analysis tools that can be used as part of a project's development lifecycle on a regular basis, such as FindBugs (see findBugs.pdf) and OWASP Orizon.&lt;br /&gt;
&lt;br /&gt;
Of course, once vulnerabilities are detected, they need to be either fixed or marked as false positives through the Fortify Open Review site interface.  See the [http://www.lulu.com/content/1415989 OWASP Code Review Guide] for information on how to fix common vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=48495</id>
		<title>Project Information:template Source Code Review OWASP Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=48495"/>
				<updated>2008-12-12T16:16:08Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Source Code Review OWASP-Projects Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The objectives of this project are: 1. Develop and document a workflow for FLOSS projects to incorporate static analysis into the Software Development Life Cycle (SDLC); 2. Apply the above workflow as a required step for OWASP projects; 3. Aid in auditing select FLOSS projects to create a baseline for comparing security amongst FLOSS projects. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:dan@denimgroup.com '''Dan Cornell''']&amp;lt;br&amp;gt;SoC's Project Leader&amp;lt;br&amp;gt;[mailto:waldenj1@nku.edu '''James Walden''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;[mailto:jderry@owasp.org '''Justin Derry''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:doylem3@nku.edu '''Maureen Doyle''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:whelanm87@gmail.com '''Michael Whelan''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-SCode-Review-OWASP-Projects(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:afry(at)strongcrypto.biz '''Alex Fry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:marco.m.morana(at)gmail.com '''Marco M. Morana''']&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Marco M Morana Curriculum|Curriculum]]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* Updated workflow [[Image:Workflow_July_11a.zip]]&lt;br /&gt;
* [[Image:Workflow_Draft1.pdf]]&lt;br /&gt;
* [[Image:CreateProjectExample.pdf]]&lt;br /&gt;
* [https://owasp.fortify.com/teamserver/welcome.fhtml Fortify OWASP Open Review Project]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* [[:Category:OWASP Open Review Project|'''OWASP Open Review Project (ORPRO)''']]&lt;br /&gt;
&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' -&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes''' &amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' &amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' -&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' -&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48494</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48494"/>
				<updated>2008-12-12T16:15:10Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
This project involving creating a process for integrating the Fortify Open Review Process into the OWASP project development lifecycle and working with Fortify to develop and test their new Open Review site at [http://owasp.fortify.com/ http://owasp.fortify.com/].  The [https://www.owasp.org/images/c/c9/OWASPEU_SourceReview.ppt OWASP EU Summit presentation] contains a more detailed summary of the project.&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
&lt;br /&gt;
The goals of this project were to:&lt;br /&gt;
&lt;br /&gt;
# Create a process for integrating the Fortify Open Review into open source development, so that source code review can be a required step in OWASP development.&lt;br /&gt;
# Test functionality of the new Fortify Open Review site introduced in Summer 2008.&lt;br /&gt;
# Scan 10 OWASP projects with the Fortify Open Review to verify the site's functionality and establish a baseline.&lt;br /&gt;
# Scan 25 popular open source PHP projects to verify the site's ability to handle large scale projects and establish a baseline.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this workflow is to integrate and automate SCA into the development cycle of open source applications for the sole purpose of decreasing software vulnerabilities.  This effort can, and should, be supplemented by a manual code review as described in the OWASP Open Review Project.  The workflow diagrams can be found in [https://www.owasp.org/index.php/Image:Workflow_July_11a.zip Workflow.zip].  Within the ZIP file, overview.pdf describes the relationships between the different parts of the workflow. The file start.pdf describes the first step of the workflow which verifies that the project is an OWASP project.  If it is not then the project is added as a new OWASP project [[Image:Workflow_Draft1.pdf#file]].  Once the project is established as an OWASP project, it can be added by an OWASP administrator (contact the project mailing list below to contact an OWASP administrator) to the Fortify Open Review (reference createProject.pdf).  &lt;br /&gt;
&lt;br /&gt;
As described in the Fortify Open Review process, the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where the project is checked out from its repository and the Open Review scan is updated on a weekly basis, or a one time analysis as part of their usual development process (see waterfall.pdf and iterative.pdf) after unit testing and prior to final system testing.   The single analysis requires the evaluator to produce and upload a Fortify FPR scan file, which requires either that the evaluator uses their own copy of Fortify SCA or contacts an OWASP administrator via the project mailing list to request a scan.   In order to track project progress over time, single analyses of major project versions will be maintained on the project web site so that software vulnerability metrics can be tracked.  The continuous evaluation is automated, does not require the developer have a Fortify SCA license.  There are additional open source static analysis tools that can be used as part of a project's development lifecycle on a regular basis, such as FindBugs (see findBugs.pdf) and OWASP Orizon.&lt;br /&gt;
&lt;br /&gt;
Of course, once vulnerabilities are detected, they need to be either fixed or marked as false positives through the Fortify Open Review site interface.  See the [http://www.lulu.com/content/1415989 OWASP Code Review Guide] for information on how to fix common vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48492</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48492"/>
				<updated>2008-12-12T16:01:21Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: /* Goals */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
This project involving creating a process for integrating the Fortify Open Review Process into the OWASP project development lifecycle and working with Fortify to develop and test their new Open Review site at [http://owasp.fortify.com/ http://owasp.fortify.com/].&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
&lt;br /&gt;
The goals of this project were to:&lt;br /&gt;
&lt;br /&gt;
# Create a process for integrating the Fortify Open Review into open source development, so that source code review can be a required step in OWASP development.&lt;br /&gt;
# Test functionality of the new Fortify Open Review site introduced in Summer 2008.&lt;br /&gt;
# Scan 10 OWASP projects with the Fortify Open Review to verify the site's functionality and establish a baseline.&lt;br /&gt;
# Scan 25 popular open source PHP projects to verify the site's ability to handle large scale projects and establish a baseline.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
The workflow diagrams can be found in [https://www.owasp.org/index.php/Image:Workflow_July_11a.zip Workflow.zip].  Within the ZIP file, overview.pdf describes the relationships between the different parts of the workflow. The file start.pdf describes the first step of the workflow which verifies that the project is an OWASP project.  If it is not then the project is added as a new OWASP project [[Image:Workflow_Draft1.pdf#file]].  Once the project is established as an OWASP project, it can be added by an OWASP administrator (contact the project mailing list below to contact an OWASP administrator) to the Fortify Open Review (reference createProject.pdf).  &lt;br /&gt;
&lt;br /&gt;
As described in the Fortify Open Review process, the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where the project is checked out from its repository and the Open Review scan is updated on a weekly basis, or a one time analysis as part of their usual development process (see waterfall.pdf and iterative.pdf) after unit testing and prior to final system testing.   The single analysis requires the evaluator to produce and upload a Fortify FPR scan file, which requires either that the evaluator uses their own copy of Fortify SCA or contacts an OWASP administrator via the project mailing list to request a scan.   In order to track project progress over time, single analyses of major project versions will be maintained on the project web site so that software vulnerability metrics can be tracked.  The continuous evaluation is automated, does not require the developer have a Fortify SCA license.  There are additional open source static analysis tools that can be used as part of a project's development lifecycle on a regular basis, such as FindBugs (see findBugs.pdf) and OWASP Orizon.&lt;br /&gt;
&lt;br /&gt;
Of course, once vulnerabilities are detected, they need to be either fixed or marked as false positives through the Fortify Open Review site interface.  See the [http://www.lulu.com/content/1415989 OWASP Code Review Guide] for information on how to fix common vulnerabilities. remove common problems.&lt;br /&gt;
&lt;br /&gt;
The purpose of this workflow is to integrate and automate SCA into the development cycle of open source applications for the sole purpose of decreasing software vulnerabilities.  This effort can, and should, be supplemented by a manual code review as described in the OWASP Open Review Project.&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48491</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48491"/>
				<updated>2008-12-12T15:59:55Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
This project involving creating a process for integrating the Fortify Open Review Process into the OWASP project development lifecycle and working with Fortify to develop and test their new Open Review site at [http://owasp.fortify.com/ http://owasp.fortify.com/].&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
&lt;br /&gt;
The goals of this project were to:&lt;br /&gt;
&lt;br /&gt;
# Create a process for integrating the Fortify Open Review into open source development.&lt;br /&gt;
# Test functionality of the new Fortify Open Review site introduced in Summer 2008.&lt;br /&gt;
# Scan 10 OWASP projects with the Fortify Open Review to verify the site's functionality and establish a baseline.&lt;br /&gt;
# Scan 25 popular open source PHP projects to verify the site's ability to handle large scale projects and establish a baseline.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
The workflow diagrams can be found in [https://www.owasp.org/index.php/Image:Workflow_July_11a.zip Workflow.zip].  Within the ZIP file, overview.pdf describes the relationships between the different parts of the workflow. The file start.pdf describes the first step of the workflow which verifies that the project is an OWASP project.  If it is not then the project is added as a new OWASP project [[Image:Workflow_Draft1.pdf#file]].  Once the project is established as an OWASP project, it can be added by an OWASP administrator (contact the project mailing list below to contact an OWASP administrator) to the Fortify Open Review (reference createProject.pdf).  &lt;br /&gt;
&lt;br /&gt;
As described in the Fortify Open Review process, the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where the project is checked out from its repository and the Open Review scan is updated on a weekly basis, or a one time analysis as part of their usual development process (see waterfall.pdf and iterative.pdf) after unit testing and prior to final system testing.   The single analysis requires the evaluator to produce and upload a Fortify FPR scan file, which requires either that the evaluator uses their own copy of Fortify SCA or contacts an OWASP administrator via the project mailing list to request a scan.   In order to track project progress over time, single analyses of major project versions will be maintained on the project web site so that software vulnerability metrics can be tracked.  The continuous evaluation is automated, does not require the developer have a Fortify SCA license.  There are additional open source static analysis tools that can be used as part of a project's development lifecycle on a regular basis, such as FindBugs (see findBugs.pdf) and OWASP Orizon.&lt;br /&gt;
&lt;br /&gt;
Of course, once vulnerabilities are detected, they need to be either fixed or marked as false positives through the Fortify Open Review site interface.  See the [http://www.lulu.com/content/1415989 OWASP Code Review Guide] for information on how to fix common vulnerabilities. remove common problems.&lt;br /&gt;
&lt;br /&gt;
The purpose of this workflow is to integrate and automate SCA into the development cycle of open source applications for the sole purpose of decreasing software vulnerabilities.  This effort can, and should, be supplemented by a manual code review as described in the OWASP Open Review Project.&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48490</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48490"/>
				<updated>2008-12-12T15:49:58Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
This project involving creating a process for integrating the Fortify Open Review Process into the OWASP project development lifecycle and working with Fortify to develop and test their new Open Review site at [http://owasp.fortify.com/ http://owasp.fortify.com/].&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
&lt;br /&gt;
The goals of this project were to:&lt;br /&gt;
&lt;br /&gt;
# Create a process for integrating the Fortify Open Review into open source development.&lt;br /&gt;
# Test functionality of the new Fortify Open Review site introduced in Summer 2008.&lt;br /&gt;
# Scan 10 OWASP projects with the Fortify Open Review to verify the site's functionality and establish a baseline.&lt;br /&gt;
# Scan 25 popular open source PHP projects to verify the site's ability to handle large scale projects and establish a baseline.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
The workflow diagrams can be found in [https://www.owasp.org/index.php/Image:Workflow_July_11a.zip Workflow.zip].  Within the ZIP file, overview.pdf describes the relationships between the different parts of the workflow. The file start.pdf describes the first step of the workflow which verifies that the project is an OWASP project.  If it is not then the project is added as a new OWASP project [[Image:Workflow_Draft1.pdf#file]].  Prior to any source code analysis (SCA), the project must also be added as a Fortify Open Review Project(reference createProject.pdf).  &lt;br /&gt;
&lt;br /&gt;
As described in the Fortify Open Review Process, the Project Lead or Source Code Review Lead can choose between a continuous evaluation, where SCA is done weekly, or a one time analysis as part of their usual development process (see waterfall.pdf and iterative.pdf) after unit testing and prior to final system testing.   The single analysis requires the evaluator to submit a Fortify output file which requires the evaluator to own a copy of Fortify 360.   The continuous evaluation is automated, does not require the developer have a Fortify 360 license,  and in accordance with the [http://www.lulu.com/content/1415989 OWASP Code Review Guide] these results can be used to remove common problems.  The common problems, along with other software errors exposed by findBugs (reference findBugs.pdf) will then be documented as known problems in the project's bug list.  &lt;br /&gt;
&lt;br /&gt;
The purpose of this workflow is to integrate and automate SCA into the development cycle of open source applications for the sole purpose of decreasing software vulnerabilities.  This effort can, and should, be supplemented by a Manual Code Review as described in the OWASP Open Review Project.&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48252</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48252"/>
				<updated>2008-12-09T23:20:03Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Walden&amp;diff=48251</id>
		<title>User:Walden</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Walden&amp;diff=48251"/>
				<updated>2008-12-09T22:01:06Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: New page: [http://faculty.cs.nku.edu/~waldenj/ James Walden] is a professor of computer science at the [http://informatics.nku.edu/ NKU College of Informatics].  He leads the [https://www.owasp.org/...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://faculty.cs.nku.edu/~waldenj/ James Walden] is a professor of computer science at the [http://informatics.nku.edu/ NKU College of Informatics].  He leads the [https://www.owasp.org/index.php/Category:OWASP_Source_Code_Review_OWASP_Projects_Project OWASP Source Code Review] project and is a member of the [http://www.owasp.org/index.php/Cincinnati Cincinnati chapter] of OWASP.&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48250</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48250"/>
				<updated>2008-12-09T21:53:50Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
&lt;br /&gt;
CSRFGuard&lt;br /&gt;
&lt;br /&gt;
CSRFTester&lt;br /&gt;
&lt;br /&gt;
DirBuster&lt;br /&gt;
&lt;br /&gt;
JBroFuzz&lt;br /&gt;
&lt;br /&gt;
Lapse&lt;br /&gt;
&lt;br /&gt;
Stinger&lt;br /&gt;
&lt;br /&gt;
Webekci&lt;br /&gt;
&lt;br /&gt;
WebGoat&lt;br /&gt;
&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48249</id>
		<title>Category:OWASP Source Code Review OWASP Projects Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Source_Code_Review_OWASP_Projects_Project&amp;diff=48249"/>
				<updated>2008-12-09T21:51:47Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[:Project Information:template Source Code Review OWASP Projects|Click here to see (&amp;amp; edit, if wanted) the template.]] &lt;br /&gt;
{{:Project Information:template Source Code Review OWASP Projects}}&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Scanned ==&lt;br /&gt;
&lt;br /&gt;
AntiSamy&lt;br /&gt;
CSRFGuard&lt;br /&gt;
CSRFTester&lt;br /&gt;
DirBuster&lt;br /&gt;
JBroFuzz&lt;br /&gt;
Lapse&lt;br /&gt;
Stinger&lt;br /&gt;
Webekci&lt;br /&gt;
WebGoat&lt;br /&gt;
WebScarab&lt;br /&gt;
&lt;br /&gt;
Non-OWASP projects scanned in MediaWiki, WordPress, and many others. See [https://owasp.fortify.com/ owasp.fortify.com] for details.&lt;br /&gt;
&lt;br /&gt;
== Get involved ==&lt;br /&gt;
&lt;br /&gt;
We need OWASP project leaders to submit their projects for review.  We will work with you to upload your project and review the findings, so that we can get each OWASP project to show zero defects.&lt;br /&gt;
&lt;br /&gt;
Please go to https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects to subscribe to the list to contact us. You can post to the mailing list by emailing [mailto:owasp-scode-review-owasp-projects@lists.owasp.org].&lt;br /&gt;
&lt;br /&gt;
== People ==&lt;br /&gt;
&lt;br /&gt;
Project lead: [[User:Walden|James Walden]]&lt;br /&gt;
Contributors: Maureen Doyle, Grant Welch, Michael Whelan&lt;br /&gt;
Reviewers: Marco Morano, Alex Fry&lt;br /&gt;
&lt;br /&gt;
[http://www.fortify.com Fortify Software] has generously made their Source Code Analyzer (SCA) technology available for use by open source projects at [http://owasp.fortify.com/ owasp.fortify.com].&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008&amp;diff=48245</id>
		<title>OWASP EU Summit 2008</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008&amp;diff=48245"/>
				<updated>2008-12-09T18:39:11Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| &lt;br /&gt;
! width=&amp;quot;315&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
! width=&amp;quot;190&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
! width=&amp;quot;300&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot;|__TOC__&lt;br /&gt;
| align=&amp;quot;center&amp;quot;|[[Image:OWASP EU Summit Portugal 2008.jpg]]&amp;lt;br&amp;gt;''''SETTING THE WEB APPLICATION SECURITY AGENDA FOR 2009''''&amp;lt;br&amp;gt;3th - 7th November 2008&lt;br /&gt;
| align=&amp;quot;left&amp;quot;|&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_EU_Summit_2008_Media_Coverage Summit media coverage]&lt;br /&gt;
* [http://spreadsheets.google.com/pub?key=pAX6n7m2zaTVLrPtR07riBA Sponsored Participants]&lt;br /&gt;
|}&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 | align=&amp;quot;center&amp;quot; |&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; align=&amp;quot;center&amp;quot;|[[Image:Summit Group 4.jpg]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== KEY RESULTS FROM THE OWASP SUMMIT ==&lt;br /&gt;
&lt;br /&gt;
=== SUMMIT CONCLUSIONS DOCUMENT ===&lt;br /&gt;
&lt;br /&gt;
&amp;quot;ALGARVE, PORTUGAL, November 7, 2008 – The Open Web Application Security Project (OWASP) today announced results from the annual OWASP Summit. Over 80 application security experts from over 20 countries joined forces to identify, coordinate, and prioritize our 2009 efforts to create a more secure Internet.&lt;br /&gt;
&lt;br /&gt;
OWASP is a free and open community that focuses on improving application security. There is overwhelming evidence that the vast majority of web applications contain security holes that are increasingly putting people and organizations at serious risk. Securing web applications is an extraordinarily difficult technical challenge that demands a concerted effort.&lt;br /&gt;
&lt;br /&gt;
“OWASP came together for a week and produced a stunning amount of new ideas,” said OWASP Chair Jeff Williams. “Our community is growing and organizing into a powerful movement that will affect software development worldwide.  This summit marks a major milestone our efforts to improve application security. (...)”&amp;lt;b&amp;gt; [https://www.owasp.org/images/4/46/Board_signed_Document.pdf See here the fully OWASP Board's signed document with OWASP Summit 2008's conclusions&amp;quot;] and watch OWASP Board's videos - [http://www.youtube.com/watch?v=skTNrQOGLOc '''Jeff Williams'''] and [http://uk.youtube.com/watch?v=kHAC7skATQg&amp;amp;feature=related '''Dinis Cruz'''].&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Key results from the OWASP Summit include:&lt;br /&gt;
&lt;br /&gt;
=== UPDATED OWASP PRINCIPLES ===&lt;br /&gt;
&lt;br /&gt;
•	Free &amp;amp; Open,&lt;br /&gt;
&lt;br /&gt;
•	Governed by rough consensus &amp;amp; running code,&lt;br /&gt;
&lt;br /&gt;
•	Abide by a code of ethics (see ethics),&lt;br /&gt;
&lt;br /&gt;
•	Not-for-profit,&lt;br /&gt;
&lt;br /&gt;
•	Not driven by commercial interests,&lt;br /&gt;
&lt;br /&gt;
•	Risk based approach.&lt;br /&gt;
&lt;br /&gt;
=== UPDATED CODE OF ETHICS ===&lt;br /&gt;
•	Support the implementation of and promote compliance with standards, procedures, controls for application security,&lt;br /&gt;
&lt;br /&gt;
•	Have objectivity, due diligence and professional care in accordance with established standards,&lt;br /&gt;
&lt;br /&gt;
•	Responsible disclosure.&lt;br /&gt;
&lt;br /&gt;
=== NEW OUTREACH PROGRAMS === &lt;br /&gt;
•	OWASP has expanded its outreach efforts by building relationships with technology vendors, framework providers, and standards bodies. In addition, we piloted a new program to provide free one-day seminars at universities and developer conferences worldwide.&lt;br /&gt;
&lt;br /&gt;
=== NEW GLOBAL COMMITTEE STRUCTURE ===&lt;br /&gt;
•	OWASP recognized the extraordinary contribution of our most active leaders by engaging them to lead a set of six new committees.  Each democratically established committee will focus on a key function or geographic region, such as OWASP projects, conferences, local chapters, membership and industry outreach.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | OWASP GLOBAL COMMITTEES ( OWASP GC)&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:17%; background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | [[Global Education Committee|Education]]&lt;br /&gt;
 | style=&amp;quot;width:17%; background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | [[Global Chapter Committee|Chapters]]&lt;br /&gt;
 | style=&amp;quot;width:17%; background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | [[Global Conferences Committee|Conferences]] &lt;br /&gt;
 | style=&amp;quot;width:17%; background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | [[Global Industry Committee|Industry]]&lt;br /&gt;
 | style=&amp;quot;width:16%; background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | [[Global Projects and Tools Committee|Projects &amp;amp; Tools]]&lt;br /&gt;
 | style=&amp;quot;width:16%; background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | [[Global Membership Committee|Membership]]&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/How_to_Join_a_Committee '''How to Join a Global Committee'''] - '''Applications being accepted until January 9th 2009 for a 24 month term.''' &lt;br /&gt;
&lt;br /&gt;
=== NEW FREE TOOLS AND GUIDANCE ===&lt;br /&gt;
&lt;br /&gt;
•	OWASP announced the release of Live CD 2008, many new testing tools, static analysis tools, the Enterprise Security API (ESAPI v1.4), AntiSamy, the Application Security Verification Standard (ASVS), guidance for Ruby on Rails and Classic ASP, international versions of our materials, and much more.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | '''OWASP is proud to launch the following new or updated tools:'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|'''PROJECT'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|'''AUTHOR''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Application Security Verification Standard Project|'''OWASP Application Security Verification Standard - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Mike Boberski&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP AppSensor Project|'''OWASP AppSensor - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Michael Coates&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Access Control Rules Tester Project|'''OWASP Access Control Rules Tester - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Andrew Petukhov &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP AntiSamy Project .NET|'''OWASP AntiSamy Project - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Arshan Dabirsiaghi &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project|'''OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Dmitry Kozlov &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Code Crawler|'''OWASP Code Crawler - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Alessio Marziali &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP JSP Testing Tool Project|'''OWASP JSP Testing Tool - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Jason Li &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Live CD 2008 Project|'''OWASP Live CD - SoC 08''']]&lt;br /&gt;
 &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Matt Tesauro &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|'''OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Arturo ‘Buanzo’&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Orizon Project|'''OWASP Orizon Project - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Paolo Perego &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Python Static Analysis Project|'''OWASP Python Static Analysis Project - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Georgy Kilmov&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Skavenger Project|'''OWASP Skavenger Project - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Matthias Rohr &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Teachable Static Analysis Workbench Project|'''OWASP Teachable Static Analysis Workbench - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Dmitry Kozlov &amp;amp; Igor Konnov &lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | '''OWASP is proud to launch the following new or updated documents and resources:'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|'''PROJECT'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|'''AUTHOR''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP ASDR Project|'''OWASP Application Security Desk Reference - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Leonardo Cavallari  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Backend Security Project|'''OWASP Backend Security Project - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Carlo Pelliccioni &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:Classic ASP Security Project|'''OWASP Classic ASP Security Project - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Juan Carlos Calderon &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Code Review Project|'''OWASP Code Review Project - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Eoin Keary &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Education Project|'''OWASP Education Project - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Sebastien Deleersnyder, Martin Knobloch &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:OWASP Internationalization|'''OWASP Internationalization Project - Soc 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Juan Carlos Calderon &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:OWASP Spanish|'''OWASP Spanish Project - SoC 08''']]&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Juan Carlos Calderon &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Positive Security Project|'''OWASP Positive Security Project - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Eduardo V.C. Neves &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Ruby on Rails Security Guide V2|'''OWASP Ruby on Rails Security Project - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Heiko Webers&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Securing WebGoat using ModSecurity Project|'''OWASP Securing WebGoat using ModSecurity Project - SoC 08''']]  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Stephen Craig Evans &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Source Code Review OWASP Projects Project|'''OWASP Source Code Review - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|James Walden &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:80%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot;|[[:Category:OWASP Testing Project|'''OWASP Testing Guide V3 - SoC 08''']] &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Matteo Meucci &lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
Find more OWASP Projects at the [https://www.owasp.org/index.php/Category:OWASP_Project OWASP Projects Page].&lt;br /&gt;
&lt;br /&gt;
== EVENT AGENDA == &lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Agenda for Monday, November 3rd, 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| 13:00 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Lunch&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|  &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:white&amp;quot; align=&amp;quot;center&amp;quot; | Training Sessions&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| 15:00 - 17:00 &lt;br /&gt;
 | style=&amp;quot;width:30%; background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; |  Securing WebGoat with ModSecurity&amp;lt;br&amp;gt;Stephen Craig Evans&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; |  WebSec Apps for Managers and Executives&amp;lt;br&amp;gt;[http://uk.youtube.com/watch?v=r04EOuukvMQ Video]&amp;lt;br&amp;gt;Mano Paul&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; |  OWASP Testing Guide&amp;lt;br&amp;gt;Matteo Meucci&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 19:00 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Summit Briefing&amp;lt;br&amp;gt;Dinis Cruz and Summit Organization Team&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 20:00 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Dinner&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Agenda for Tuesday, November 4th, 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 08:00 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Registration&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| 09:00 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Summit Keynote&amp;lt;br&amp;gt;Dinis Cruz and Summit Organization Team&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:45%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; |  '''Documents''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:45%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; |  '''Tools'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:30 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Testing Project|'''OWASP Testing Guide - SoC 08''']]&amp;lt;br&amp;gt;Matteo Meucci&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP JSP Testing Tool Project|'''OWASP JSP Testing Tool - SoC 08''']]&amp;lt;br&amp;gt;Jason Li&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 09:45 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Code Review Project|'''OWASP Code Review Project - SoC 08''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/5/59/Code_Review_Eoin.pptx PowerPoint Presentation]&amp;lt;br&amp;gt;Eoin Keary&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Orizon Project|'''OWASP Orizon Project - SoC 08''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/9/9b/OWASP_EU_Summit_2008_The_Owasp_Orizon_Project.ppt PowerPoint Presentation]&amp;lt;br&amp;gt;Paolo Perego &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP ASDR Project|'''OWASP Application Security Desk Reference - SoC 08''']]&amp;lt;br&amp;gt;Leonardo Cavallari Militelli&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Live CD 2008 Project|'''OWASP Live CD - SoC 08''']]&amp;lt;br&amp;gt;Matt Tesauro&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:15 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Spanish|'''OWASP Spanish Project - SoC 08''']]&amp;lt;br&amp;gt;Juan Carlos Calderon&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP WebScarab Project|'''OWASP WebScarab Project''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/8/88/OWASP_EU_Summit_2008_WebScarab_treasures.ppt PowerPoint Presentation]&amp;lt;br&amp;gt;Rogan Dawes&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| 10:30 &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Coffee Break&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| 10:45 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | .NET ESAPI&amp;lt;br&amp;gt;Alex Smolen&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 11:00 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Working Sessions Briefing&amp;lt;br&amp;gt;Dinis Cruz&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|  &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:white&amp;quot; align=&amp;quot;center&amp;quot; | Working Sessions&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white&amp;quot; | &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 11:15 - 13:00&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; |  [[:OWASP Working Session - OWASP Documentation Projects|'''Documentation Projects/Guides Integration and Unified 4.0 Version''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/9/92/Final_OWASP_Guidelines_Ideas_List_.docx WS Conclusions]&amp;lt;br&amp;gt;Eduardo Neves&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; |  [[:OWASP Working Session - Browser Security|'''OWASP Intrinsic Security Working Group - Browser Security ''']]&amp;lt;br&amp;gt;Arshan Dabirsiaghi&lt;br /&gt;
 | style=&amp;quot;width:30%; background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; |  [[:OWASP Working Session - OWASP Tools Projects|'''Tools Projects]]'''&amp;lt;br&amp;gt;[https://www.owasp.org/images/5/51/EUSummit08_OWASP_Tools_Working_Session_Suggestions.doc WS Conclusions]&amp;lt;br&amp;gt;Matt Tesauro&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00&lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Lunch&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|  &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:white&amp;quot; align=&amp;quot;center&amp;quot; | Training Sessions&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00&lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | '''The Art and Science of Threat Modeling Web Applications'''&amp;lt;br&amp;gt;[http://uk.youtube.com/watch?v=r04EOuukvMQ Video]&amp;lt;br&amp;gt;Mano Paul&lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | '''Web Server Hardening SELinux'''&amp;lt;br&amp;gt;[https://www.owasp.org/images/d/db/SELinux-course-OWASP.pdf PDF Presentation]&amp;lt;br&amp;gt;Pavol Luptak&lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | '''Offensive WebApp Hacking'''&amp;lt;br&amp;gt;[http://www.youtube.com/watch?v=cl6BHhi2Dys Video - LDAP, XML and SQL injection]&amp;lt;br&amp;gt;[http://www.carlosserrao.net/files/owasp/owaspdemo02.swf Video - LDAP injection demo]&amp;lt;br&amp;gt;[http://www.carlosserrao.net/files/owasp/owaspdemo04.swf XML injection demo]&amp;lt;br&amp;gt;[http://www.carlosserrao.net/files/owasp/owaspdemo03.swf Video - SQL injection demo ]&amp;lt;br&amp;gt;Marco Slaviero&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00&lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | '''Phishing attack'''&amp;lt;br&amp;gt;[http://www.youtube.com/watch?v=uf9hw-qvx-I Video]&amp;lt;br&amp;gt;Matt Teasuro &amp;amp; Brad Causey &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | '''Clickjacking'''&amp;lt;br&amp;gt;[http://www.youtube.com/watch?v=H9srYh0HMP4 Video]&amp;lt;br&amp;gt;[http://www.carlosserrao.net/files/owasp/owaspdemo01.swf Demonstration]&amp;lt;br&amp;gt;Arshan Dabirsiaghi &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:00 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Coffee Break&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|  &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:white&amp;quot; align=&amp;quot;center&amp;quot; | Working Sessions&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:30 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; |[[:OWASP Working Session Enterprise Security API Project|'''OWASP Enterprise Security API Project (ESAPI)''']]&amp;lt;br&amp;gt;[http://uk.youtube.com/watch?v=-D_bymZ-8vI Video]&amp;lt;br&amp;gt;[https://www.owasp.org/images/7/70/ESAPI_Ideas_List.docx WS Conclusions]&amp;lt;br&amp;gt;Jeff Williams &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - OWASP ASDR|'''OWASP Application Security Desk Reference - ASDR]]'''&amp;lt;br&amp;gt;Leonardo Cavallari&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - .NET Project|'''.NET Project''']]&amp;lt;br&amp;gt;Dinis Cruz&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Agenda for Wednesday, November 5th, 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| 09:15 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Daily Briefing&amp;lt;br&amp;gt;Dinis Cruz&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; |  '''Standards and Education'''  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; |  '''Tools''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Positive Security Project|'''OWASP Positive Security Project - SoC 08''']]&amp;lt;br&amp;gt;Eduardo Neves&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Access Control Rules Tester Project|'''OWASP Access Control Rules Tester - SoC 08''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/3/32/OWASP_EU_Summit_2008_AcCoRuTe.pptx PowerPoint Presentation]&amp;lt;br&amp;gt;Andrew Petukhov&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:15 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Education Project|'''OWASP Education Project - SoC 08''']]&amp;lt;br&amp;gt;Sebastien Deleersnyder, Martin Knobloch&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Teachable Static Analysis Workbench Project|'''OWASP Teachable Static Analysis Workbench - SoC 08''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/6/69/Teachable_static_analysis_workbench.pptx PowerPoint Presentation]&amp;lt;br&amp;gt;Dmitry Kozlov&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:30 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Internationalization|'''OWASP Internationalization Project - Soc 08''']]&amp;lt;br&amp;gt;Juan Carlos Calderon&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP AppSensor Project|'''OWASP AppSensor - SoC 08''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/7/77/Presentation_AppSensor.ppt PowerPoint Presentation]&amp;lt;br&amp;gt; Michael Coates&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:45 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | '''PASSWD Project: Metrics and Vulnerabilities'''&amp;lt;br&amp;gt;[https://www.owasp.org/images/f/f6/PASSWD.ppt PowerPoint Presentation]&amp;lt;br&amp;gt;Lucilla Mancini &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Backend Security Project|'''OWASP Backend Security Project - SoC 08''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/2/20/OWASP_EU_Summit_2008_Presentation_Model.ppt PowerPoint Prsentation]&amp;lt;br&amp;gt;Carlo Pelliccioni&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 11:00 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Open Review Project|'''OWASP Open Review Project''']]&amp;lt;br&amp;gt;Dan Cornell&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project|'''OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project - SoC 08''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/c/c4/Site_generator.pptx PowerPoint Presentation]&amp;lt;br&amp;gt;Dmitry Kozlov&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 11:15 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | [[OWASP EU Summit 2008#NEW GLOBAL COMMITTEE STRUCTURE|'''OWASP Global Committee Elections''']]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 11:30 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Coffee Break&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|  &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:white&amp;quot; align=&amp;quot;center&amp;quot; | Working Sessions&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 12:45 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[OWASP Working Session Education Project|'''Education Project''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/3/33/OWASP_Education_Working_Session_Notes_-_Ideas.ppt WS Conclusions]&amp;lt;br&amp;gt;Sebastien Deleersnyder&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - OWASP Testing Guide|'''Testing Guide''']]&amp;lt;br&amp;gt;Matteo Meucci&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - Web Application Framework Security|'''Web Application Framework Security''']]&amp;lt;br&amp;gt;Arshan Dabirsiaghi&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:45 &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Lunch (During Working Sessions)&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|  &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:white&amp;quot; align=&amp;quot;center&amp;quot; | Training Sessions&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 15:00&lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | '''Flash Player Security'''&amp;lt;br&amp;gt;Peleus Uhley&lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | '''OWASP Top 10'''&amp;lt;br&amp;gt;[http://uk.youtube.com/watch?v=GsRbpshqqII Video]&amp;lt;br&amp;gt;Sebastien Deleersnyder and Martin Knobloch&lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | '''Uncovering WebScarab's Secret Treasures'''&amp;lt;br&amp;gt;[https://www.owasp.org/images/8/88/OWASP_EU_Summit_2008_WebScarab_treasures.ppt PowerPoint Presentation]&amp;lt;br&amp;gt;Rogan Dawes&lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | '''Hacking the Orizon'''&amp;lt;br&amp;gt;[http://www.owasp.org/index.php/Image:Hacking_the_Owasp_Orizon.ppt PowerPoint Presentation]&amp;lt;br&amp;gt;Paolo Perego&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| 17:00 &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Coffee Break&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|  &lt;br /&gt;
 | colspan=&amp;quot;4&amp;quot; style=&amp;quot;width:90%; background:white&amp;quot; align=&amp;quot;center&amp;quot; | Working Sessions&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:30 &lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - Code Review Guide|'''Code Review Guide''']]&amp;lt;br&amp;gt;Eoin Keary&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | EU Funding for OWASP Projects&amp;lt;br&amp;gt;Carlos Serrao&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - OWASP Certification|'''OWASP Certification''']]&amp;lt;br&amp;gt;Tom Brennan&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | Software Assurance Maturity Model&amp;lt;br&amp;gt;Pravir Chandra&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 19:00 &lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - OWASP Website|'''OWASP Website''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/8/8b/EUSummit08_OWASP_Web_Site_Working_Session_Suggestions.doc WS Conclusions]&amp;lt;br&amp;gt;[https://www.owasp.org/images/2/2e/Website.ppt PPT Presentation]&amp;lt;br&amp;gt;Fabio Cerullo&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | '''Metrics &amp;amp; Vulnerabilities'''&amp;lt;br&amp;gt;Lucilla Mancini&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | OWASP Orizon&amp;lt;br&amp;gt;Paolo Perego&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Agenda for Thursday, November 6th, 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| 09:15 &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Daily Briefing&amp;lt;br&amp;gt;Dinis Cruz&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:30%; background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; |  '''Technology''' &lt;br /&gt;
 | colspan=&amp;quot;3&amp;quot; style=&amp;quot;width:30%; background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; |  '''Tools''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:Classic ASP Security Project|'''OWASP Classic ASP Security Project - SoC 08''']]&amp;lt;br&amp;gt;Juan Carlos Calderon&lt;br /&gt;
 | colspan=&amp;quot;3&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Source Code Review OWASP Projects Project|'''OWASP Source Code Review - SoC 08''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/c/c9/OWASPEU_SourceReview.ppt PowerPoint Presentation]&amp;lt;br&amp;gt;James Walden&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:15 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Ruby on Rails Security Guide V2|'''OWASP Ruby on Rails Security Project - SoC 08''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/3/32/Rails_security_2_presentation.pdf PDF Presentation]&amp;lt;br&amp;gt;Heiko Webers&lt;br /&gt;
 | colspan=&amp;quot;3&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|'''OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp - SoC 08''']]&amp;lt;br&amp;gt;Arturo Alberto Busleiman &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:30 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Webslayer Project|'''OWASP Webslayer Project''']]&amp;lt;br&amp;gt;Christian Martorella&lt;br /&gt;
 | colspan=&amp;quot;3&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Securing WebGoat using ModSecurity Project|'''OWASP Securing WebGoat using ModSecurity Project - SoC 08''']]&amp;lt;br&amp;gt;Stephen Evans and Christian Folini&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 11:00 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#FFDF80&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP Skavenger Project|'''OWASP Skavenger Project - SoC 08''']]&amp;lt;br&amp;gt;Matthias Rohr&lt;br /&gt;
 | colspan=&amp;quot;3&amp;quot; style=&amp;quot;background:#a0c0e0&amp;quot; align=&amp;quot;center&amp;quot; | [[:Category:OWASP AntiSamy Project .NET|'''OWASP AntiSamy Project - SoC 08''']]&amp;lt;br&amp;gt;Marcin Wielgoszewski&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| 11:15 &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Coffee Break&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|  &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;width:90%; background:white&amp;quot; align=&amp;quot;center&amp;quot; | Working Sessions&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 11:30 &lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session Top 10 2009|'''OWASP Top 10 - 2009''']]&amp;lt;br&amp;gt;Dave Wichers&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - OWASP Intra Governmental Affairs|'''OWASP Intra Governmental Affairs''']]&amp;lt;br&amp;gt;David Campbell&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | SAMM v2&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - OWASP Website|'''OWASP Website''']]&amp;lt;br&amp;gt;Fabio Cerullo&lt;br /&gt;
 | style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | Handling Web MalWare&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00 &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Lunch (During Working Sessions)&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|  &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;width:90%; background:white&amp;quot; align=&amp;quot;center&amp;quot; | Training Sessions&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 14:00 &lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | Ajax Security&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | Auditing Flash Applications&amp;lt;br&amp;gt;Peleus Uhley&lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | WebApp Assessment&amp;lt;br&amp;gt;Vicente Aguilera Diaz&lt;br /&gt;
 | style=&amp;quot;background:#c0a0a0&amp;quot; align=&amp;quot;center&amp;quot; | Mod Security&amp;lt;br&amp;gt;Lucas C. Ferreira&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|  &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;width:90%; background:white&amp;quot; align=&amp;quot;center&amp;quot; | Working Sessions&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 16:30 &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; |  [[:Working Session OWASP Strategic Planning|'''OWASP Strategic Planning and Business Models compatible with OWASP values''']]&amp;lt;br&amp;gt;Jeff Williams, Dinis Cruz, Dave Wichers, Sebastien Deleersnyder, Tom Brennan &amp;amp; Kate Hartmann and Paulo Combra&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 18:30 &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - Two-way Internationalization of OWASP Content|'''Two-way Internationalization of OWASP Content''']]&amp;lt;br&amp;gt;Juan Carlos Calderon &amp;amp; Sebastien Deleersnyder&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:Best Practices for OWASP Chapter Leaders|'''OWASP Best Practices for Chapter Leaders''']]&amp;lt;br&amp;gt;[https://www.owasp.org/images/0/01/BestPractices_2008.pptx WS Conclusions]&amp;lt;br&amp;gt;Georg Hess&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;background:#B3FF99&amp;quot; align=&amp;quot;center&amp;quot; | [[:OWASP Working Session - OWASP Live CD&amp;amp;DVD|'''OWASP Live CD &amp;amp; DVD''']]&amp;lt;br&amp;gt;Matt Tesauro&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 20:00 &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Gala Dinner &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;background:#7B8ABD &amp;quot; align=&amp;quot;center&amp;quot; | 22:00 &lt;br /&gt;
 | colspan=&amp;quot;5&amp;quot; style=&amp;quot;background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | OWASP Band &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Agenda for Friday, November 7th, 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:00 &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Daily Briefing&amp;lt;br&amp;gt;Dinis Cruz&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 10:15 &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | OWASP AppSec Agenda 2009:  Working Session Outcomes&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Documentation Projects/Guides Integration and Unified 4.0 Version&amp;lt;br&amp;gt;Eduardo Neves&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Browser Security&amp;lt;br&amp;gt;Arshan Dabirsiaghi&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | ESAPI&amp;lt;br&amp;gt;Jeff Williams&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Tools Projects&amp;lt;br&amp;gt;Matt Tesauro&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Code Review Guide&amp;lt;br&amp;gt;Eoin Keary&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | OWASP Certification&amp;lt;br&amp;gt;Tom Brennan&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Software Assurance Maturity Model&amp;lt;br&amp;gt;Pravir Chandra&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Top 10 2009&amp;lt;br&amp;gt;Dave Wichers&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Intra Governmental Affairs&amp;lt;br&amp;gt;David Campbell&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Best Practices for Chapter Leaders&amp;lt;br&amp;gt;Georg Hess&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 11:15 &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | Coffee Break and Vote (put your dots on the wall)&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 11:30 &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Live CD &amp;amp; DVD&amp;lt;br&amp;gt;Matt Tesauro&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | ADSR&amp;lt;br&amp;gt;Leonardo Cavallari&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Education Project&amp;lt;br&amp;gt;Sebastien Deleersnyder&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Web Application Framework Security&amp;lt;br&amp;gt;Arshan Dabirsiaghi&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Testing Guide&amp;lt;br&amp;gt;Matteo Meucci&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | OWASP Censorship&amp;lt;br&amp;gt;Tom Brennan&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | EU Funding for OWASP Projects&amp;lt;br&amp;gt;Carlos Serrao&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | OWASP Website&amp;lt;br&amp;gt;Fabio Cerullo&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | OWASP Orizon&amp;lt;br&amp;gt;Paolo Perego&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Handling Web MalWare&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | 2-Way Internationalization&amp;lt;br&amp;gt;Juan Carlos Calderon&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Portuguese Public &amp;amp; Private Organizations&amp;lt;br&amp;gt;Carlos Serrao&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; |  &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot; | Winter of Code 2009&amp;lt;br&amp;gt;Dinis Cruz and Sebastien Deleersnyder&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 13:00 &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Lunch &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| 14:00 &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.owasp.org/index.php/Owasp_Board_Meetings_11-07-08 Board Meeting]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot; | 17:00 &lt;br /&gt;
 | style=&amp;quot;width:80%; background:#f2984c&amp;quot; align=&amp;quot;center&amp;quot; | Announcement of Summit Procedings&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
== OWASP BOARD MEETING ==&lt;br /&gt;
Board meeting was held at the OWASP Summit - [http://www.owasp.org/index.php/Owasp_Board_Meetings_11-07-08 RESULTS].&lt;br /&gt;
&lt;br /&gt;
== EVENT'S PHOTOS ==&lt;br /&gt;
&lt;br /&gt;
More event's photos can be seen [http://picasaweb.google.com/paulocoimbra7/OWASPSummitEUPortugal2008# here].&amp;lt;br&amp;gt;[http://picasaweb.google.com/paulocoimbra7/OWASPSummitEUPortugal2008#slideshow Summit's slide show].&lt;br /&gt;
&lt;br /&gt;
==ARCHIVED DATA==&lt;br /&gt;
&lt;br /&gt;
'''FORMER AGENDA''': [[:OWASP EU Summit 2008 Former Agenda|Click here to see.]]&lt;br /&gt;
&lt;br /&gt;
'''SUMMIT BROCHURE''': [https://www.owasp.org/images/8/89/OWASP_EU_Summit_2008-Overview.pdf 6 page brochure] or this [https://www.owasp.org/images/3/3d/OWASP_EU_Summit_2008_-Full_Brochure.pdf 33 page brochure].&lt;br /&gt;
&lt;br /&gt;
'''VENUE &amp;amp; TRAVEL ARRANGEMENTS''': The OWASP European Summit 2008 was hosted at the 5 start Resort in Algarve Portugal ([http://www.granderealsantaeulaliahotel.com/index.html '''Grande Real Santa Eulália Resort &amp;amp; Hotel''']). Hotel booking and the travel arrangements were be handled via [http://www.diplomatatours.pt/owasp.php '''Diplomata Tours'''], the assigned travel agency. The venue location - [http://maps.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Grande+Real+Santa+Eul%C3%A1lia+Resort+%26+Hotel+algarve&amp;amp;sll=37.015438,-7.919769&amp;amp;sspn=0.084982,0.176468&amp;amp;ie=UTF8&amp;amp;ll=37.124054,-8.182583&amp;amp;spn=0.08486,0.176468&amp;amp;z=13&amp;amp;iwloc=B Google Maps Link]. Nearest Airport - [http://maps.google.co.uk/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Aeroporto+de+Faro,+Montenegro,+Faro,+8005,+Portugal&amp;amp;ie=UTF8&amp;amp;ll=37.096812,-7.967834&amp;amp;spn=0.502766,1.235962&amp;amp;z=10&amp;amp;output=html Faro].&lt;br /&gt;
&lt;br /&gt;
'''OTHER LINKS''': [[OWASP EU Summit 2008--PRESS|Press Information]], [[:OWASP Working Session - Browser Security Letters|Open Letter to Browsers&amp;amp;Frameworks]], [[:OWASP Summit UALG 1 Day Conference|OWASP Summit UALG 1 Day Conference]], [http://twitter.com/OwaspEU08Summit OwaspEU08Summit on Twitter!], [[OWASP EU Summit 2008 Internals|OWASP EU Summit 2008 Internals]]. &lt;br /&gt;
&lt;br /&gt;
'''SPONSORS''':&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot; | &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#FFDF80&amp;quot;; align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/5/5a/AOD_Logo_2c.gif https://www.owasp.org/images/9/9e/Mnemonic_logo.png    https://www.owasp.org/images/1/1a/Softtek_logo.gif  &lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=48242</id>
		<title>Project Information:template Source Code Review OWASP Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=48242"/>
				<updated>2008-12-09T18:26:39Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Source Code Review OWASP-Projects Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The objectives of this project are: 1. Develop and document a workflow for FLOSS projects to incorporate static analysis into the Software Development Life Cycle (SDLC); 2. Apply the above workflow as a required step for OWASP projects; 3. Aid in auditing select FLOSS projects to create a baseline for comparing security amongst FLOSS projects. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:dan@denimgroup.com '''Dan Cornell''']&amp;lt;br&amp;gt;SoC's Project Leader&amp;lt;br&amp;gt;[mailto:waldenj1@nku.edu '''James Walden''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;[mailto:jderry@owasp.org '''Justin Derry''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:doylem3@nku.edu '''Maureen Doyle''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:whelanm87@gmail.com '''Michael Whelan''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-SCode-Review-OWASP-Projects(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:afry(at)strongcrypto.biz '''Alex Fry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:marco.m.morana(at)gmail.com '''Marco M. Morana''']&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Marco M Morana Curriculum|Curriculum]]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* Updated workflow [[Image:Workflow_July_11a.zip]]&lt;br /&gt;
* [[Image:Workflow_Draft1.pdf]]&lt;br /&gt;
* [[Image:CreateProjectExample.pdf]]&lt;br /&gt;
* [https://owasp.fortify.com/teamserver/welcome.fhtml Fortify OWASP Open Review Project]&lt;br /&gt;
* [[Image:OWASPEU_SourceReview.ppt]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* [[:Category:OWASP Open Review Project|'''OWASP Open Review Project (ORPRO)''']]&lt;br /&gt;
&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' -&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes''' &amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' &amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' -&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' -&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASPEU_SourceReview.ppt&amp;diff=48241</id>
		<title>File:OWASPEU SourceReview.ppt</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASPEU_SourceReview.ppt&amp;diff=48241"/>
				<updated>2008-12-09T18:26:22Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: OWASP EU Summit 2008 presentation for the Source Code Review OWASP Projects Summer of Code project.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP EU Summit 2008 presentation for the Source Code Review OWASP Projects Summer of Code project.&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45236</id>
		<title>Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45236"/>
				<updated>2008-10-31T03:07:28Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The major project objectives have been accomplished:&lt;br /&gt;
# We have finalized the workflow for introducing static analysis into OWASP projects.&lt;br /&gt;
# We have submitted 10 OWASP projects to be analyzed on the owasp.fortify.com site to establish an OWASP baseline.&lt;br /&gt;
# We have submitted the 25 most popular open source PHP projects to the be analyzed on the owasp.fortify.com site to establish an open source baseline.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We spent the time since the project midpoint submitting projects to the owasp.fortify.com site.  The current status of tasks is:&lt;br /&gt;
# Workflow for introducing static analysis into OWASP projects (100%).&lt;br /&gt;
# Analyzed 10 OWASP projects (100%).&lt;br /&gt;
# Analyzed 25 most popular open source PHP projects on owasp.fortify.com (100%).&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
All Alpha criteria are fulfilled.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The documentation needs to be expanded and links added to the code review guide.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We will add the OWASP EU Summit presentation to fulfill that requirement once it's ready.&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
To ensure that this project leads to continuing improvement in the security of OWASP projects, we need more OWASP project leaders to incorporate static analysis into their project's software development lifecycle.  We have received only one volunteer who was willing to take the time to incorporate static analysis into his project: Yiannis, project leader of the JBroFuzz project.  We can analyze OWASP projects on our own, but it's important to include static analysis as part of the lifecycle.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45235</id>
		<title>Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45235"/>
				<updated>2008-10-31T03:06:22Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The major project objectives have been accomplished:&lt;br /&gt;
# We have finalized the workflow for introducing static analysis into OWASP projects.&lt;br /&gt;
# We have submitted the 25 most popular open source PHP projects to the be analyzed on the owasp.fortify.com site to establish a baseline.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We spent the time since the project midpoint submitting projects to the owasp.fortify.com site.  The current status of tasks is:&lt;br /&gt;
# Workflow for introducing static analysis into OWASP projects (100%).&lt;br /&gt;
# Analyzed 25 most popular open source PHP projects on owasp.fortify.com (100%).&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
All Alpha criteria are fulfilled.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The documentation needs to be expanded and links added to the code review guide.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We will add the OWASP EU Summit presentation to fulfill that requirement once it's ready.&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
To ensure that this project leads to continuing improvement in the security of OWASP projects, we need more OWASP project leaders to incorporate static analysis into their project's software development lifecycle.  We have received only one volunteer who was willing to take the time to incorporate static analysis into his project: Yiannis, project leader of the JBroFuzz project.  We can analyze OWASP projects on our own, but it's important to include static analysis as part of the lifecycle.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45234</id>
		<title>Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45234"/>
				<updated>2008-10-31T03:02:39Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The major project objectives have been accomplished:&lt;br /&gt;
# We have finalized the workflow for introducing static analysis into OWASP projects.&lt;br /&gt;
# We have submitted the 25 most popular open source PHP projects to the be analyzed on the owasp.fortify.com site to establish a baseline.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We spent the time since the project midpoint submitting projects to the owasp.fortify.com site.  The current status of tasks is:&lt;br /&gt;
# Workflow for introducing static analysis into OWASP projects (100%).&lt;br /&gt;
# Analyzed 25 most popular open source PHP projects on owasp.fortify.com (100%).&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
All Alpha criteria are fulfilled.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We will add the OWASP EU Summit presentation to fulfill that requirement once it's ready.&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
To ensure that this project leads to continuing improvement in the security of OWASP projects, we need more OWASP project leaders to incorporate static analysis into their project's software development lifecycle.  We have received only one volunteer who was willing to take the time to incorporate static analysis into his project: Yiannis, project leader of the JBroFuzz project.  We can analyze OWASP projects on our own, but it's important to include static analysis as part of the lifecycle.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45198</id>
		<title>Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45198"/>
				<updated>2008-10-30T20:07:10Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The major project objectives have been accomplished:&lt;br /&gt;
# We have finalized the workflow for introducing static analysis into OWASP projects.&lt;br /&gt;
# We have submitted the 25 most popular open source PHP projects to the be analyzed on the owasp.fortify.com site to establish a baseline.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We spent the time since the project midpoint submitting projects to the owasp.fortify.com site.  The current status of tasks is:&lt;br /&gt;
# Workflow for introducing static analysis into OWASP projects (100%).&lt;br /&gt;
# Analyzed 25 most popular open source PHP projects on owasp.fortify.com (100%).&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
To ensure that this project leads to continuing improvement in the security of OWASP projects, we need more OWASP project leaders to incorporate static analysis into their project's software development.  We have received only one volunteer who was willing to take the time to incorporate static analysis into his project: Yiannis, project leader of the JBroFuzz project.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45197</id>
		<title>Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45197"/>
				<updated>2008-10-30T20:05:39Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The major project objectives have been accomplished:&lt;br /&gt;
# We have finalized the workflow for introducing static analysis into OWASP projects.&lt;br /&gt;
# We have submitted the 25 most popular open source PHP projects to the be analyzed on the owasp.fortify.com site to establish a baseline.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We spent the time since the project midpoint submitting projects to the owasp.fortify.com site.  The current status of tasks is:&lt;br /&gt;
# Workflow for introducing static analysis into OWASP projects (100%).&lt;br /&gt;
# Analyzed 25 most popular open source PHP projects on owasp.fortify.com (100%).&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We need to find more OWASP project leaders to incorporate static analysis into their project's software development.  We have worked with Yiannis, project leader of the JBroFuzz project.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45196</id>
		<title>Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45196"/>
				<updated>2008-10-30T20:04:23Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The major project objectives have been accomplished:&lt;br /&gt;
# We have finalized the workflow for introducing static analysis into OWASP projects.&lt;br /&gt;
# We have submitted the 25 most popular open source PHP projects to the be analyzed on the owasp.fortify.com site to establish a baseline.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
We spent the time since the project midpoint submitting projects to the owasp.fortify.com site.  The current status of tasks is:&lt;br /&gt;
# Workflow for introducing static analysis into OWASP projects (100%).&lt;br /&gt;
# Analyzed 25 most popular open source PHP projects on owasp.fortify.com (100%).&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 | We need to find more OWASP project leaders to incorporate static analysis into their project's software development.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=45195</id>
		<title>Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=45195"/>
				<updated>2008-10-30T20:02:17Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. To what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
#Team finalized (Maureen Doyle, James Walden, Michael Whelan.)&lt;br /&gt;
#Projects selected for initial analysis (AntiSamy, WebScarab, OWASP Enterprise Security API (ESAPI) Project)&lt;br /&gt;
#Preliminary workflow.&lt;br /&gt;
#No projects submitted to Fortify Open Source Review, as Fortify is updating the application.  We have talked extensively with Fortify and OWASP about the changes and how they match our workflow.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. To what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The current status of tasks planned for the end of June is:&lt;br /&gt;
#Team finalized (100%)&lt;br /&gt;
#Projects selected (100%)&lt;br /&gt;
#Preliminary workflow (100%)&lt;br /&gt;
#Projects submitted (0%)&lt;br /&gt;
Since the Fortify open source review is not currently accepting projects, we have not been able to submit any projects.  However, we are currently analyzing the following tools using Fortify's commercial source code analyzer (SCA) tool.  &lt;br /&gt;
#MediaWiki&lt;br /&gt;
#SquirrelMail&lt;br /&gt;
#WordPress&lt;br /&gt;
The updated version of Fortify's web site will allow us to upload the FPR files generated by this tool to create projects immediately, instead of waiting a week.  The following tasks remain to be done:&lt;br /&gt;
#Revise workflow based on reviews.&lt;br /&gt;
#Submit initial project to Fortify site once its online for testing.&lt;br /&gt;
#Submit 3 projects as continuously analyzed projects on Fortify site.&lt;br /&gt;
#Select additional OWASP and non-OWASP projects to analyze.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|We need feedback and direction on the preliminary workflow.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45194</id>
		<title>Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45194"/>
				<updated>2008-10-30T19:50:31Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The major project objectives have been accomplished:&lt;br /&gt;
# We have finalized the workflow for introducing static analysis into OWASP projects.&lt;br /&gt;
# We have submitted the 25 most popular open source PHP projects to the be analyzed on the owasp.fortify.com site to establish a baseline.&lt;br /&gt;
# We are working with one OWASP project leader to submit his project to the workflow.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45193</id>
		<title>Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=45193"/>
				<updated>2008-10-30T19:48:56Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
# We have finalized the workflow for introducing static analysis into OWASP projects.&lt;br /&gt;
# We have submitted the 25 most popular open source PHP projects to the be analyzed on the owasp.fortify.com site to establish a baseline.&lt;br /&gt;
# We are working with one OWASP project leader to submit his project to the workflow.&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Working_Session_Education_Project&amp;diff=44872</id>
		<title>OWASP Working Session Education Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Working_Session_Education_Project&amp;diff=44872"/>
				<updated>2008-10-27T20:40:08Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#b3b3b3; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Working Sessions Operational Rules''' - [[:Working Sessions Methodology|'''Please see here the general frame of rules''']].&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Work Session Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Education Project '''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Work Session Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Set 2009 goals for the OWASP Education project&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Related Projects (if any)''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Education Project|OWASP Education Project]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts &amp;amp; Roles'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Chair'''&amp;lt;br&amp;gt;[mailto:seba(at)owasp.org '''Sebastien Deleersnyder'''] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Secretary'''&amp;lt;br&amp;gt;[mailto:martin.knobloch(at)sogeti.nl '''Martin Knobloch''']&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Mailing list'''&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-education '''Subscription Page''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION SPECIFICS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Objectives'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
* How to improve knowledge transfer from OWASP projects towards the community,&lt;br /&gt;
* How to create training material (lessons, classes, courses) from OWASP project material?&lt;br /&gt;
* How to set up an OWASP education baseline,&lt;br /&gt;
* How to setup an OWASP Boot Camp,&lt;br /&gt;
* How to connect to organisation to promote OWASP education content: e.g. universities, other non-profit (or profit?) education organisations,&lt;br /&gt;
* How to organize the OWASP / Conference trainings to make them the best in the world?&lt;br /&gt;
* Can we integrate this into OWASP certification projects?&lt;br /&gt;
* How to setup an OWASP Boot Camp?&lt;br /&gt;
* How to create lessons, classes, courses from OWASP project material? &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue/Date&amp;amp;Time/Model'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue'''&amp;lt;br&amp;gt;[[:OWASP EU Summit 2008|OWASP EU Summit Portugal 2008]] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Date&amp;amp;Time'''&amp;lt;br&amp;gt;November 5, 2008 &amp;lt;br&amp;gt;Time TBD&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Discussion Model'''&amp;lt;br&amp;gt;&amp;quot;Everybody is a Participant&amp;quot;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION OPERATIONAL RESOURCES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Please add here, ASAP, any needed relevant resources, e.g. data-show, boards, laptops, etc.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION ADDITIONAL DETAILS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|There is plenty of knowledge available inside the OWASP community. This is spread via the OWASP AppSec Conferences and the local chapter meetings, not to forget the books available now. Another, very important way to distribute the available knowledge is to teach! In plenty presentations knowledge is put into slides to share it. The next step is to reuse the information of those presentations and create training material. In a Boot Camp for example, it's not only about telling how to break stuff, but let the attendees break it themselves. Also let them fix the problems, with guidance of the experienced! &lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|'''WORKING SESSION OUTCOMES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|Statements, Initiatives or Decisions &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Proposed by Working Group''' &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Approved by OWASP Board'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Educational Support on Winter of Code 2008. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Guildeline about creating training material. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here.&lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
  |}&lt;br /&gt;
== Working Session Participants ==&lt;br /&gt;
(Add you name by editing this table. On your the right, just above the this frame, you have the option to edit)&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION PARTICIPANTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Name'''&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Company'''&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Notes &amp;amp; reason for participating, issues to be discussed/addressed'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|1&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Sébastien GIORIA&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| OWASP France&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| I actually doing some training in government, company, school, training center oriented to Web security with some OWASP material (WebGoat, WebScarab) and want to see how we can &amp;quot;internationalize&amp;quot; the content for training and see what we can do a very good packages for OWASP. I could not be in Portugal, so I could participate (depending of Time) with Skype &amp;amp;&amp;amp; Twitter or other tools&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|2&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Eduardo Neves&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| OWASP Brazil&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| To discuss how the educational initiatives can be liaised with Universities and other educational sources to use OWASP tools and documents on educational actions and market development.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|3&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Colin Watson&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| OWASP London&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Interested in how we spread the word to non-technology professions - business owners, procurement specialists, project managers, marketers, graphic designers.&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|4&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Andrzej Targosz&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| OWASP Poland&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| How to spread training in universities.&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|4&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Joaquim Marques&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| OWASP Portugal&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| How to spread training and educational initiatives in universities.&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|5&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| James Walden&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Northern Kentucky University (NKU)&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Expand university awareness of web application security&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|6&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|7&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|8&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|9&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|10&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
If needed add here more lines.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Working_Session]]&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=44320</id>
		<title>Project Information:template Source Code Review OWASP Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=44320"/>
				<updated>2008-10-21T20:00:35Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Source Code Review OWASP-Projects Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The objectives of this project are: 1. Develop and document a workflow for FLOSS projects to incorporate static analysis into the Software Development Life Cycle (SDLC); 2. Apply the above workflow as a required step for OWASP projects; 3. Aid in auditing select FLOSS projects to create a baseline for comparing security amongst FLOSS projects. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:dan@denimgroup.com '''Dan Cornell''']&amp;lt;br&amp;gt;SoC's Project Leader&amp;lt;br&amp;gt;[mailto:waldenj1@nku.edu '''James Walden''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;[mailto:jderry@owasp.org '''Justin Derry''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:doylem3@nku.edu '''Maureen Doyle''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:whelanm87@gmail.com '''Michael Whelan''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-SCode-Review-OWASP-Projects(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:afry(at)strongcrypto.biz '''Alex Fry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:marco.m.morana(at)gmail.com '''Marco M. Morana''']&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Marco M Morana Curriculum|Curriculum]]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* Updated workflow [[Image:Workflow_July_11a.zip]]&lt;br /&gt;
* [[Image:Workflow_Draft1.pdf]]&lt;br /&gt;
* [[Image:CreateProjectExample.pdf]]&lt;br /&gt;
* [https://owasp.fortify.com/teamserver/welcome.fhtml Fortify OWASP Open Review Project]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=44319</id>
		<title>Project Information:template Source Code Review OWASP Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=44319"/>
				<updated>2008-10-21T19:59:11Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Source Code Review OWASP-Projects Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The objectives of this project are: 1. Develop and document a workflow for FLOSS projects to incorporate static analysis into the Software Development Life Cycle (SDLC); 2. Apply the above workflow as a required step for OWASP projects; 3. Aid in auditing select FLOSS projects to create a baseline for comparing security amongst FLOSS projects. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:dan@denimgroup.com '''Dan Cornell''']&amp;lt;br&amp;gt;SoC's Project Leader&amp;lt;br&amp;gt;[mailto:waldenj1@nku.edu '''James Walden''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;[mailto:jderry@owasp.org '''Justin Derry''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:doylem3@nku.edu '''Maureen Doyle''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:whelanm87@gmail.com '''Michael Whelan''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-SCode-Review-OWASP-Projects(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:afry(at)strongcrypto.biz '''Alex Fry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:marco.m.morana(at)gmail.com '''Marco M. Morana''']&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Marco M Morana Curriculum|Curriculum]]&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* 7/11/08 - Updated workflow [[Image:Workflow_July_11a.zip]]&lt;br /&gt;
* replaced 7/11/08 - [[Image:Workflow_Draft1.pdf]]&lt;br /&gt;
* replaced 7/11/08 - [[Image:CreateProjectExample.pdf]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[https://owasp.fortify.com/teamserver/welcome.fhtml Fortify OWASP Open Review Project]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Working_Session_-_Code_Review_Guide&amp;diff=44318</id>
		<title>OWASP Working Session - Code Review Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Working_Session_-_Code_Review_Guide&amp;diff=44318"/>
				<updated>2008-10-21T19:39:39Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#b3b3b3; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Working Sessions Operational Rules''' - [[:Working Sessions Methodology|'''Please see here the general frame of rules''']].&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Work Session Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Code Review Guide'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Work Session Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|TBD&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Related Projects (if any)''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Code Review Project|OWASP Code Review Project]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts &amp;amp; Roles'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Chair'''&amp;lt;br&amp;gt;[mailto:eoin.keary(at)owasp.org '''Eoin Keary'''] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Secretary'''&amp;lt;br&amp;gt;[mailto:name(at)name '''TBD''']&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Mailing list'''&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-codereview '''Subscription Page''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION SPECIFICS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Objectives'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
*  Discuss next version of code review guide.&lt;br /&gt;
* Discuss industry requirements for code review.&lt;br /&gt;
* Discuss academic versus practical ramifications of guide.&lt;br /&gt;
* Brainstorm: Ideas for integration with other projects and tools.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue/Date&amp;amp;Time/Model'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue'''&amp;lt;br&amp;gt;[[:OWASP EU Summit 2008|OWASP EU Summit Portugal 2008]] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Date&amp;amp;Time'''&amp;lt;br&amp;gt;November 5 &amp;amp; 6, 2008 &amp;lt;br&amp;gt;Time TBD&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Discussion Model'''&amp;lt;br&amp;gt;&amp;quot;Everybody is a Participant&amp;quot;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION OPERATIONAL RESOURCES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Whteboard and Pens, Projector, Coffee :)&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION ADDITIONAL DETAILS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
Please add here, any additional notes, links, ideas, guidelines, etc... The objective is to help the working sessions participants and attendees to prepare their participation/contribution.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|'''WORKING SESSION OUTCOMES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|Statements, Initiatives or Decisions &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Proposed by Working Group''' &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Approved by OWASP Board'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Develop a roadmap for the code review guide: Technologies, approaches. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here.   &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
  |}&lt;br /&gt;
== Working Session Participants ==&lt;br /&gt;
(Add you name by editing this table. On your the right, just above the this frame, you have the option to edit)&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION PARTICIPANTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Name'''&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Company'''&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Notes &amp;amp; reason for participating, issues to be discussed/addressed'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|1&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Paolo Perego (aka thesp0nge)&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Spike Reply&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Owasp Orizon - Project Leader&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|2&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|David Rook&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Realex Payments&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Contributor to Code Review Guide&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|3&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Giorgio Fedon&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Minded Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Very interested in the topic&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|4&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Matteo Meucci&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Minded Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Interested in integrating OWASP big 4: Dev, Code Review, Testing, ADSR&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|5&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kuai Hinojosa&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP (MSP) Chapter Leader&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|6&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|James Walden&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|NKU&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Source Code Analysis Project&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|7&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|8&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|9&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|10&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
If needed add here more lines.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Working_Session]]&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Code_Review_Guide_Frontispiece&amp;diff=44317</id>
		<title>Code Review Guide Frontispiece</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Code_Review_Guide_Frontispiece&amp;diff=44317"/>
				<updated>2008-10-21T18:36:02Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Welcome to the OWASP Code Review Guide 1.1==&lt;br /&gt;
“Thank Jaysus for the interweb”&amp;lt;br&amp;gt;&lt;br /&gt;
-- [[User:EoinKeary|Eoin Keary]]&lt;br /&gt;
&lt;br /&gt;
OWASP thanks the authors, reviewers, and editors for their hard work in bringing this guide to where it is today. If you have any comments or suggestions on the Code review Guide, please e-mail the Code review Guide mail list:&lt;br /&gt;
&lt;br /&gt;
 https://lists.owasp.org/mailman/listinfo/owasp-codereview&lt;br /&gt;
&lt;br /&gt;
==Copyright and License==&lt;br /&gt;
&lt;br /&gt;
Copyright (c) 2008 The OWASP Foundation.&lt;br /&gt;
&lt;br /&gt;
This document is released under the [http://creativecommons.org/licenses/by-sa/2.5/ Creative Commons 2.5 License]. Please read and understand the license and copyright conditions.&lt;br /&gt;
&lt;br /&gt;
==Revision History ==&lt;br /&gt;
&lt;br /&gt;
The Code review guide originated in 2006 and an splinter project from the testing guide. It was concieved by Eoin Keary in 2005 and transformed into a wiki.&lt;br /&gt;
&lt;br /&gt;
; September 30, 2007&lt;br /&gt;
: &amp;quot;OWASP Code Review Guide&amp;quot;, Version 1.0 (RC1)&lt;br /&gt;
&lt;br /&gt;
; December 22, 2007&lt;br /&gt;
: &amp;quot;&amp;quot;OWASP Code Review Guide&amp;quot;, Version 1.0 (RC2)&lt;br /&gt;
&lt;br /&gt;
; November 01, 2008&lt;br /&gt;
: &amp;quot;OWASP Code Review Guide&amp;quot;, Version 1.1 (Release)&lt;br /&gt;
&lt;br /&gt;
== Editors ==&lt;br /&gt;
'''Eoin Keary''': OWASP Code Review Guide 2005- Lead&lt;br /&gt;
&lt;br /&gt;
== Authors ==&lt;br /&gt;
&lt;br /&gt;
 Jenelle Chapman&lt;br /&gt;
 Andrew van der Stock&lt;br /&gt;
 Eoin Keary&lt;br /&gt;
 Paolo Perego&lt;br /&gt;
 David Lowry&lt;br /&gt;
 David Rook&lt;br /&gt;
 James Walden&lt;br /&gt;
&lt;br /&gt;
== Reviewers ==&lt;br /&gt;
Jeff Williams&lt;br /&gt;
Rahim Jina&lt;br /&gt;
&lt;br /&gt;
==Trademarks==&lt;br /&gt;
&lt;br /&gt;
* Java, Java Web Server, and JSP are registered trademarks of Sun Microsystems, Inc.&lt;br /&gt;
* Microsoft is a registered trademark of Microsoft Corporation.&lt;br /&gt;
* OWASP is a registered trademark of the OWASP Foundation&lt;br /&gt;
&lt;br /&gt;
All other products and company names may be trademarks of their respective owners. Use of a term in this document should not be regarded as affecting the validity of any trademark or service mark.&lt;br /&gt;
&lt;br /&gt;
{{Category:OWASP Code Review Project}}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_Paid_Participants&amp;diff=39009</id>
		<title>OWASP EU Summit 2008 Paid Participants</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_Paid_Participants&amp;diff=39009"/>
				<updated>2008-09-09T19:55:54Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: /* Provisory list of 'expenses paid' participants */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Provisory list of 'expenses paid' participants    ==&lt;br /&gt;
&lt;br /&gt;
 {| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECTED CONFERENCE PAID ATTENDEES AND/OR SPEAKERS - NEEDS OWASP BOARD CONFIRMATION''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''NAME'''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''POSITION/REASON OF ATTENDANCE'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''COUNTRY'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''DEPARTURE (AIRPORT/CITY)'''&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP BOARD MEMBERS &amp;amp; EMPLOYEES''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Jeff Williams&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, Chair, Wiki, Management&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Washington, D.C. &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dave Wichers &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, Conferences, Financials&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Washington, D.C.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dinis Cruz &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, Firehose of Ideas and Money spender&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Tom Brennan &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, OWASP Governance&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|New York, NY&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sebastien Deleersnyder &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, OWASP Chapters and Projects&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Belgium&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Paulo Coimbra&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Employee, Project Manager&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kate Hartmann&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Employee, Operations Director&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Washington, D.C.&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SUMMER OF CODE 2008 PROJECT LEADERS &amp;amp; REVIEWERS''' &lt;br /&gt;
|- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Achim Hoffmann&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Skavenger Project, OWASP w3af Project  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Germany&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Frankfurt or Munich&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Alexander Fry&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Source Code Review OWASP Projects&amp;lt;br&amp;gt;OWASP Teachable Static Analysis Workbench&amp;lt;br&amp;gt;OWASP WeBekci Project  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arshan Dabirsiaghi&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP AntiSamy Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Baltimore, MD&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Andrew Petukhov &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Access Control Rules Tester Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Russia&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Moscow&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dmitry Kozlov &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Teachable Static Analysis, OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Russia&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Moscow&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arturo Alberto Busleiman &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Enigform and mod_Openpgp &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Argentina&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Carlo Pelliccioni &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Backend Security Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Italy &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rome (FCO)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Deb, LX Studios&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Book Cover &amp;amp; Sleeve Design, OWASP Individual &amp;amp; Corporate Member Packs, Conference Attendee Packs&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Eduardo Vianna de Camargo Neves  &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Positive Security  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brazil &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Curitiba (CWB)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Wagner Elias  &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviwer, OWASP Positive Security  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brazil &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|São Paulo(GRU)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Eoin Keary&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Code Review Guide, Chapter Leader &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ireland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dublin (DUB)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Esteban Ribicic&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Backend Security Project&amp;lt;br&amp;gt;OWASP Classic ASP Security Project&amp;lt;br&amp;gt;OWASP AntiSamy .NET&amp;lt;br&amp;gt;OWASP Interceptor Project - 2008 Update&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Croatia&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Wien&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Fabio Cerullo&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Internationalization Guidelines Project&amp;lt;br&amp;gt;OWASP Spanish Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ireland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dublin (DUB)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Frederick Donovan&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Application Security Desk Reference (ASDR) &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|United States&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Heiko Webers&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Ruby on Rails Security Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Germany&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Frankfurt&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Anthony Shireman&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project reviewer, OWASP Ruby on Rails Security Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Portland, OR (PDX)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Justin Derry&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader &amp;amp; Project Leader, OWASP Interceptor Project &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sydney Australia&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sydney Australia &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kevin Fuller&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Testing Guide v3&amp;lt;br&amp;gt;OWASP SQL Injector Benchmarking Project (SQLiBENCH)&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sacramento Ca &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Leonardo Cavallari Militelli&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Application Security Desk Reference (ASDR)&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brazil &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sao Paulo (GRU)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Mark Roxberry&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Leader, OWASP .NET Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Matt Tesauro&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP Live CD 2008&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Austin, TX or Dallas, TX&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Matteo Meucci&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP Testing Guide&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Italy&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rome&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Matthias Rohr&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Skavenger Project &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Germany &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Michael Coates&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP AppSensor &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chicago&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Nam Nguyen&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Testing Guide v3, Python Static Analysis, OWASP Education&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Vietnam&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ho Chi Minh City&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|P.Satish Kumar&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Code Review Guide &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|India&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Hyderabad/Mumbai/Chennai&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Paolo Perego&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP Orizon Project  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Italy&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Parvathy Iyer &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Corporate Application Security Guide &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Newark (New Jersey)or Newyork (Newyork city)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Pierre Parrend&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP OpenSign Server Project&amp;lt;br&amp;gt;OWASP Application Security Verification Standard &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|France&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Stephen Craig Evans&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Securing WebGoat using ModSecurity &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Singapore&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Singapore&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Jason Li&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP JSP Testing Tool&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Baltimore&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Gandhi Aryavalli Sriranga Narasimha&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Application Security Desk Reference (ASDR)&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|India &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Bangalore&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rodrigo Marcos&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Internationalization Guidelines Project&amp;lt;br&amp;gt;OWASP Spanish Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Marcin Wielgoszewski&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP AntiSamy.NET&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|New York, NY&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|James Walden&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP Source Code Review OWASP Projects&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Cincinnati, OH&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SUMMER OF CODE 2008 SPECIAL PROJECT CONTRIBUTORS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SUMMER OF CODE 2008/LOGISTICS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sarah Cruz&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, Graphic Design &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SPRING OF CODE 2007 PROJECT LEADERS &amp;amp; REVIEWERS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Joshua Perrymon&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP LiveCD, OWASP Phishing Framework, Alabama Chapter Lead&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Birmingham,AL&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP AUTUMN OF CODE 2006 PROJECT LEADERS &amp;amp; REVIEWERS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rogan Dawes &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, WebScarab-NG &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|South Africa&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Johannesburg, South Africa&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Simon Roses Femerling&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Pantera&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Spain&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''ACTIVE PROJECT LEADERS (NOT CURRENTLY PARTICIPATING ON SOC 08)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Alex Smolen&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Project leader, .NET ESAPI &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
  |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''ACTIVE CHAPTER LEADERS (NOT CURRENTLY PARTICIPATING ON SOC 08)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Steve Antoniewicz&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter Board Member, NY/NJ Metro  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kuai Hinojosa&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader, Twin-Cities &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Jim Manico&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader/founder, Hawaii&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Hawaii, USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Anahola, Island of Kauai&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rex Booth&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader, Washington DC  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Washington DC&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Andrzej Targosz&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader, Poland  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Poland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Cracow&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''SIGNIFICANT PAST OWASP CONTRIBUTOR (NOT ALREADY COVERED BY ONE OF THE ABOVE CATEGORIES)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|David Rook&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Code Review Guide Contributor, Irish Chapter Contributor&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ireland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dublin (DUB)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;''''KEY INDUSTRY PLAYERS' INVITED TO THE WORKING SESSIONS (NOT ALREADY COVERED BY ONE OF THE ABOVE CATEGORIES)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Colin Watson&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Awards Contributor &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP NON-INDIVIDUAL MEMBERS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_Paid_Participants&amp;diff=39007</id>
		<title>OWASP EU Summit 2008 Paid Participants</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_Paid_Participants&amp;diff=39007"/>
				<updated>2008-09-09T19:53:59Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: /* Provisory list of 'expenses paid' participants */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Provisory list of 'expenses paid' participants    ==&lt;br /&gt;
&lt;br /&gt;
 {| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECTED CONFERENCE PAID ATTENDEES AND/OR SPEAKERS - NEEDS OWASP BOARD CONFIRMATION''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''NAME'''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''POSITION/REASON OF ATTENDANCE'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''COUNTRY'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''DEPARTURE (AIRPORT/CITY)'''&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP BOARD MEMBERS &amp;amp; EMPLOYEES''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Jeff Williams&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, Chair, Wiki, Management&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Washington, D.C. &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dave Wichers &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, Conferences, Financials&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Washington, D.C.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dinis Cruz &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, Firehose of Ideas and Money spender&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Tom Brennan &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, OWASP Governance&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|New York, NY&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sebastien Deleersnyder &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Board, OWASP Chapters and Projects&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Belgium&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Paulo Coimbra&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Employee, Project Manager&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kate Hartmann&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Employee, Operations Director&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Washington, D.C.&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SUMMER OF CODE 2008 PROJECT LEADERS &amp;amp; REVIEWERS''' &lt;br /&gt;
|- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Achim Hoffmann&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Skavenger Project, OWASP w3af Project  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Germany&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Frankfurt or Munich&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Alexander Fry&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Source Code Review OWASP Projects&amp;lt;br&amp;gt;OWASP Teachable Static Analysis Workbench&amp;lt;br&amp;gt;OWASP WeBekci Project  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arshan Dabirsiaghi&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP AntiSamy Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Baltimore, MD&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Andrew Petukhov &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Access Control Rules Tester Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Russia&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Moscow&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dmitry Kozlov &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Teachable Static Analysis, OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Russia&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Moscow&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arturo Alberto Busleiman &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Enigform and mod_Openpgp &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Argentina&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Carlo Pelliccioni &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Backend Security Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Italy &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rome (FCO)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Deb, LX Studios&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Book Cover &amp;amp; Sleeve Design, OWASP Individual &amp;amp; Corporate Member Packs, Conference Attendee Packs&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Eduardo Vianna de Camargo Neves  &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Positive Security  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brazil &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Curitiba (CWB)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Wagner Elias  &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviwer, OWASP Positive Security  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brazil &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|São Paulo(GRU)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Eoin Keary&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Code Review Guide, Chapter Leader &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ireland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dublin (DUB)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Esteban Ribicic&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Backend Security Project&amp;lt;br&amp;gt;OWASP Classic ASP Security Project&amp;lt;br&amp;gt;OWASP AntiSamy .NET&amp;lt;br&amp;gt;OWASP Interceptor Project - 2008 Update&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Croatia&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Wien&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Fabio Cerullo&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Internationalization Guidelines Project&amp;lt;br&amp;gt;OWASP Spanish Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ireland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dublin (DUB)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Frederick Donovan&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Application Security Desk Reference (ASDR) &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|United States&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Heiko Webers&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Ruby on Rails Security Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Germany&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Frankfurt&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Anthony Shireman&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project reviewer, OWASP Ruby on Rails Security Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Portland, OR (PDX)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Justin Derry&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader &amp;amp; Project Leader, OWASP Interceptor Project &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sydney Australia&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sydney Australia &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kevin Fuller&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Testing Guide v3&amp;lt;br&amp;gt;OWASP SQL Injector Benchmarking Project (SQLiBENCH)&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sacramento Ca &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Leonardo Cavallari Militelli&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Application Security Desk Reference (ASDR)&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brazil &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sao Paulo (GRU)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Mark Roxberry&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Leader, OWASP .NET Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Matt Tesauro&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP Live CD 2008&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Austin, TX or Dallas, TX&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Matteo Meucci&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP Testing Guide&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Italy&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rome&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Matthias Rohr&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Skavenger Project &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Germany &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Michael Coates&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP AppSensor &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chicago&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Nam Nguyen&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Testing Guide v3, Python Static Analysis, OWASP Education&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Vietnam&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ho Chi Minh City&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|P.Satish Kumar&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Code Review Guide &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|India&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Hyderabad/Mumbai/Chennai&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Paolo Perego&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP Orizon Project  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Italy&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Parvathy Iyer &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Corporate Application Security Guide &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Newark (New Jersey)or Newyork (Newyork city)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Pierre Parrend&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP OpenSign Server Project&amp;lt;br&amp;gt;OWASP Application Security Verification Standard &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|France&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Stephen Craig Evans&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Securing WebGoat using ModSecurity &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Singapore&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Singapore&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Jason Li&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP JSP Testing Tool&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Baltimore&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Gandhi Aryavalli Sriranga Narasimha&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Application Security Desk Reference (ASDR)&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|India &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Bangalore&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rodrigo Marcos&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP Internationalization Guidelines Project&amp;lt;br&amp;gt;OWASP Spanish Project&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Marcin Wielgoszewski&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Reviewer, OWASP AntiSamy.NET&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|New York, NY&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|James Walden&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP Source Code Review OWASP Projects&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Highland Heights, KY&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SUMMER OF CODE 2008 SPECIAL PROJECT CONTRIBUTORS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SUMMER OF CODE 2008/LOGISTICS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sarah Cruz&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, Graphic Design &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP SPRING OF CODE 2007 PROJECT LEADERS &amp;amp; REVIEWERS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Joshua Perrymon&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader, OWASP LiveCD, OWASP Phishing Framework, Alabama Chapter Lead&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Birmingham,AL&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP AUTUMN OF CODE 2006 PROJECT LEADERS &amp;amp; REVIEWERS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rogan Dawes &lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, WebScarab-NG &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|South Africa&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Johannesburg, South Africa&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Simon Roses Femerling&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project leader, OWASP Pantera&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Spain&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''ACTIVE PROJECT LEADERS (NOT CURRENTLY PARTICIPATING ON SOC 08)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Alex Smolen&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Project leader, .NET ESAPI &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
  |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''ACTIVE CHAPTER LEADERS (NOT CURRENTLY PARTICIPATING ON SOC 08)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Steve Antoniewicz&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter Board Member, NY/NJ Metro  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kuai Hinojosa&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader, Twin-Cities &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Jim Manico&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader/founder, Hawaii&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Hawaii, USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Anahola, Island of Kauai&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rex Booth&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader, Washington DC  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|USA&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Washington DC&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Andrzej Targosz&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Chapter leader, Poland  &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Poland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Cracow&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''SIGNIFICANT PAST OWASP CONTRIBUTOR (NOT ALREADY COVERED BY ONE OF THE ABOVE CATEGORIES)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|David Rook&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Code Review Guide Contributor, Irish Chapter Contributor&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ireland&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Dublin (DUB)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;''''KEY INDUSTRY PLAYERS' INVITED TO THE WORKING SESSIONS (NOT ALREADY COVERED BY ONE OF THE ABOVE CATEGORIES)''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Colin Watson&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Awards Contributor &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|UK&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|London&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|?&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;left&amp;quot; style=&amp;quot;background:white; color:black&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP NON-INDIVIDUAL MEMBERS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Name&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=32460</id>
		<title>OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=32460"/>
				<updated>2008-06-26T18:07:39Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page contains Projects, Authors, Status Target and Reviewers of the sponsored programme [[OWASP Summer of Code 2008]].&lt;br /&gt;
== DOCUMENTATION PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Verification Standard Project|OWASP Application Security Verification Standard]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mike Boberski &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.williams(at)owasp.org Jeff Williams]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend(at)insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AppSensor Project|OWASP AppSensor - Detect and Respond to Attacks from Within the Application]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:michael.coates(at)aspectsecurity.com Michael Coates]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eric.sheridan(at)aspectsecurity.com Eric Sheridan]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:thrynn404(at)gmail.com Randy Janinda]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Backend Security Project|OWASP Backend Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Carlo Pelliccioni&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Classic ASP Security Project|OWASP Classic ASP Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rodrigo@rmarcos.com Rodrigo Marcos]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Review Project|OWASP Code review guide, V1.1]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eoin Keary&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:psatishkumar(at)gmail.com P.Satish Kumar]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Corporate Application Security Rating Guide|OWASP Corporate Application Security Rating Guide]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Parvathy Iyer&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Neal Kirschner&amp;lt;br&amp;gt;Email address?&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Omar.Sherin(at)infosec2.com Omar Sherin]&amp;lt;br&amp;gt;TBC &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Education Project|OWASP Education Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Martin Knobloch&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:sebastien.gioria@owasp.fr Sebastien Gioria]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn(at)bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Internationalization|OWASP Internationalization Guidelines Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP .NET Project#OWASP .NET Project Leader|OWASP .NET Project Leader]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mark Roxberry &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary(at)gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dennis.hurst(at)hp.com Dennis Hurst]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Positive Security Project|OWASP Positive Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eduardo Vianna de Camargo Neves &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:welias(at)conviso.com.br Wagner Elias]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Ruby on Rails Security Guide V2|OWASP Ruby on Rails Security Guide v2]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Heiko Webers &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:steve.jones(at)unf.edu Steve Jones]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.cabaniss(at)gmail.com Jeff Cabaniss]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Securing WebGoat using ModSecurity Project|OWASP Securing WebGoat using ModSecurity]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Stephen Evans &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ivan.ristic(at)breach.com Ivan Ristic] &amp;amp; Breach Group&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:christian.folini(at)netnea.com Christian Folini]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot;|'''[[:Category:OWASP Source Code Review OWASP Projects Project|OWASP Source Code Review OWASP Projects]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | James Walden&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:marco.m.morana(at)gmail.com Marco M. Morana]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Spanish|OWASP Spanish Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Testing Project|OWASP Testing Guide v3]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matteo Meucci &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;400&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;120&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''3rd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''4th&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP ASDR Project|OWASP Application Security Desk Reference (ASDR)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Leonardo Cavallari Militelli &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:williamtsmith(at)gmail.com William Smith]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#William Smith | Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Kenneth R. van Wyk| Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kcfredman(at)gmail.com Frederick Donovan]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Frederick Donovan | Bio]]&amp;lt;br&amp;gt;  (Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TOOLS PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:GTK plus GUI for w3af Project|GTK+ GUI for w3af project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Facundo Batista&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:andres.riancho(at)gmail.com Andres Riancho]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/ariancho Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah@securenet.de Achim Hoffmann]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Access Control Rules Tester Project|OWASP Access Control Rules Tester]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Andrew Petukhov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:caughron(at)gmail.com Mat Caughron]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/A84/998 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mg_chen(at)yahoo.com Min Chen]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/mgchen Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AntiSamy Project .NET| OWASP AntiSamy .NET]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arshan Dabirsiaghi&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dallasspohn(at)sbcglobal.net Dallas Spohn]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project|OWASP Application Security Tool Benchmarking Environment and Site Generator refresh]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dmitry Kozlov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:medelibero(at)gmail.com Mike de Libero]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Crawler|OWASP Code Crawler ]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Alessio Marziali &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Interceptor Project|OWASP Interceptor Project - 2008 Update]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Justin Derry&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dallasspohn(at)sbcglobal.net Dallas Spohn]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP JSP Testing Tool Project|OWASP UI Component Verification Project (a.k.a. OWASP JSP Testing Tool)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jason Li&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:markkerzner(at)gmail.com Mark Kerzner]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabricio.fujikawa(at)infoglobo.com.br Fabrício Fujikawa]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Live CD 2008 Project|OWASP Live CD 2008 Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matt Tesauro&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:admin@wirefall.com Dustin Dykes]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/607/6b1 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jkpoots(at)rogers.com Kent Poots] &amp;lt;br&amp;gt; [http://www.linkedin.com/pub/5/25B/114 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenSign Server Project|OWASP Online code signing and integrity verification service for open source community (OpenSign Server)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Phil Potisk and Richard Conway&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend@insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:a_campani@yahoo.fr Antonio Campanile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arturo 'Buanzo' Busleiman&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | (need one)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Orizon Project|OWASP Orizon Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Paolo Perego&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:seba@deleersnyder.eu Sebastien Deleersnyder]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz@owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Python Static Analysis Project|OWASP Python Static Analysis]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Georgy Klimov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn@bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:diepvien00thayh@gmail.com P.Q.Huy]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Skavenger Project|OWASP Skavenger]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mro(at)securenet.de Matthias Rohr]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Rogan Dawes&amp;lt;br&amp;gt;Email address?&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah@securenet.de Achim Hoffmann]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Sqlibench Project|OWASP SQL Injector Benchmarking Project (SQLiBENCH)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:urgunb@hotmail.com Bedirhan Urgun]&amp;lt;br&amp;gt;[mailto:mesut@h-labs.org Mesut Timur]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ferruh@mavituna.com Ferruh Mavituna]&amp;lt;br/&amp;gt; [[Project Information:Sqlibench:Ferruh|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kfuller@dmv.ca.gov Kevin Fuller] &amp;lt;br/&amp;gt;[[Project Information:Sqlibench:Kevin|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Teachable Static Analysis Workbench Project|OWASP Teachable Static Analysis Workbench]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ddk(at)cs.msu.su Dmitry Kozlov]&amp;lt;br&amp;gt;Igor Konnov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alex Fry]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP WeBekci Project|OWASP WeBekci Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:bunyamin@owasp.org Bunyamin Demir]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== DESIGN/CORPORATE PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Book Cover &amp;amp; Sleeve Design|OWASP Book Cover &amp;amp; Sleeve Design]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Individual and Corporate Member Packs plus Conference Attendee Packs Brief|OWASP Individual &amp;amp; Corporate Member Packs, Conference Attendee Packs Brief]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32459</id>
		<title>Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32459"/>
				<updated>2008-06-26T18:03:30Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. To what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
#Team finalized (Maureen Doyle, James Walden, Michael Whelan.)&lt;br /&gt;
#Projects selected for initial analysis (AntiSamy, WebScarab, OWASP Enterprise Security API (ESAPI) Project)&lt;br /&gt;
#Preliminary workflow.&lt;br /&gt;
#No projects submitted to Fortify Open Source Review, as Fortify is updating the application.  We have talked extensively with Fortify and OWASP about the changes and how they match our workflow.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. To what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
The current status of tasks planned for the end of June is:&lt;br /&gt;
#Team finalized (100%)&lt;br /&gt;
#Projects selected (100%)&lt;br /&gt;
#Preliminary workflow (100%)&lt;br /&gt;
#Projects submitted (0%)&lt;br /&gt;
Since the Fortify open source review is not currently accepting projects, we have not been able to submit any projects.  However, we are currently analyzing the following tools using Fortify's commercial source code analyzer (SCA) tool.  &lt;br /&gt;
#AntiSamy&lt;br /&gt;
#WebScarab&lt;br /&gt;
#OWASP Enterprise Security API (ESAPI) Project&lt;br /&gt;
The updated version of Fortify's web site will allow us to upload the FPR files generated by this tool to create projects immediately, instead of waiting a week.  The following tasks remain to be done:&lt;br /&gt;
#Revise workflow based on reviews.&lt;br /&gt;
#Submit initial project to Fortify site once its online for testing.&lt;br /&gt;
#Submit 3 OWASP projects as continuously analyzed projects on Fortify site.&lt;br /&gt;
#Select additional OWASP and non-OWASP projects to analyze.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|We need feedback and direction on the preliminary workflow.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=32458</id>
		<title>Project Information:template Source Code Review OWASP Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=32458"/>
				<updated>2008-06-26T17:55:15Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Source Code Review OWASP-Projects Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The objectives of this project are: 1. Develop and document a workflow for open source projects to incorporate static analysis into the Software Development Life Cycle (SDLC); 2. Apply the above workflow as a required step for OWASP projects; 3. Aid in auditing select open source projects to create a baseline for comparing security amongst open source projects. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:dan@denimgroup.com '''Dan Cornell''']&amp;lt;br&amp;gt;SoC's Project Leader&amp;lt;br&amp;gt;[mailto:waldenj1@nku.edu '''James Walden''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;[mailto:jderry@owasp.org '''Justin Derry''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:doylem3@nku.edu '''Maureen Doyle''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:whelanm87@gmail.com '''Michael Whelan''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-SCode-Review-OWASP-Projects(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:afry(at)strongcrypto.biz '''Alex Fry''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:marco.m.morana(at)gmail.com '''Marco M. Morana''']&amp;lt;br&amp;gt;&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* [[Image:Workflow_Draft1.pdf]]&lt;br /&gt;
* [[Image:CreateProjectExample.pdf]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[https://opensource.fortify.com/teamserver/welcome.fhtml Fortify Code Review Application]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:CreateProjectExample.pdf&amp;diff=32457</id>
		<title>File:CreateProjectExample.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:CreateProjectExample.pdf&amp;diff=32457"/>
				<updated>2008-06-26T17:54:35Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: Example flow diagram for creating a new project to be reviewed.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Example flow diagram for creating a new project to be reviewed.&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Workflow_Draft1.pdf&amp;diff=32456</id>
		<title>File:Workflow Draft1.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Workflow_Draft1.pdf&amp;diff=32456"/>
				<updated>2008-06-26T17:52:05Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: Draft source code review workflow.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Draft source code review workflow.&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=32454</id>
		<title>Project Information:template Source Code Review OWASP Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects&amp;diff=32454"/>
				<updated>2008-06-26T17:33:57Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Source Code Review OWASP-Projects Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The objectives of this project are: 1. Develop and document a workflow for open source projects to incorporate static analysis into the Software Development Life Cycle (SDLC); 2. Apply the above workflow as a required step for OWASP projects; 3. Aid in auditing select open source projects to create a baseline for comparing security amongst open source projects. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:dan@denimgroup.com '''Dan Cornell''']&amp;lt;br&amp;gt;SoC's Project Leader&amp;lt;br&amp;gt;[mailto:waldenj1@nku.edu '''James Walden''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;[mailto:jderry@owasp.org '''Justin Derry''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:doylem3@nku.edu '''Maureen Doyle''']&amp;lt;br&amp;gt;&lt;br /&gt;
[mailto:whelanm87@gmail.com '''Michael Whelan''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-scode-review-owasp-projects '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:OWASP-SCode-Review-OWASP-Projects(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:afry(at)strongcrypto.biz '''Alex Fry''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:marco.m.morana(at)gmail.com '''Marco M. Morana''']&amp;lt;br&amp;gt;(TBC)&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* (If appropriate, links to be added)&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[https://opensource.fortify.com/teamserver/welcome.fhtml Fortify Code Review Application]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Source Code Review OWASP Projects - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32339</id>
		<title>Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32339"/>
				<updated>2008-06-24T20:11:12Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. To what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
#Team finalized (Maureen Doyle, James Walden, Michael Whelan.)&lt;br /&gt;
#Projects selected for initial analysis (AntiSamy, WebScarab, OWASP Enterprise Security API (ESAPI) Project)&lt;br /&gt;
#Preliminary workflow.&lt;br /&gt;
#No projects submitted to Fortify Open Source Review, as Fortify is updating the application.  We have talked extensively with Fortify and OWASP about the changes and how they match our workflow.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. To what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
#Team finalized (100%)&lt;br /&gt;
#Projects selected (100%)&lt;br /&gt;
#Preliminary workflow (100%)&lt;br /&gt;
#Projects submitted (0%)&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|We need feedback and direction on the preliminary workflow.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32338</id>
		<title>Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32338"/>
				<updated>2008-06-24T19:41:10Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. To what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
#Team finalized (Maureen Doyle, James Walden, Michael Whelan.)&lt;br /&gt;
#Projects selected for initial analysis (WebScarab, OWASP Enterprise Security API (ESAPI) Project, OWASP CSRFGuard Project.)&lt;br /&gt;
#Preliminary workflow.&lt;br /&gt;
#No projects submitted to Fortify Open Source Review, as Fortify is updating the application.  We have talked extensively with Fortify and OWASP about the changes and how they match our workflow.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. To what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
#Team finalized (100%)&lt;br /&gt;
#Projects selected (100%)&lt;br /&gt;
#Preliminary workflow (100%)&lt;br /&gt;
#Projects submitted (0%)&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|We need feedback and direction on the preliminary workflow.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32337</id>
		<title>Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32337"/>
				<updated>2008-06-24T19:39:27Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. To what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|-Team finalized (Maureen Doyle, James Walden, Michael Whelan.)&lt;br /&gt;
-Projects selected for initial analysis (WebScarab, OWASP Enterprise Security API (ESAPI) Project, OWASP CSRFGuard Project.)&lt;br /&gt;
-Preliminary workflow.&lt;br /&gt;
-No projects submitted to Fortify Open Source Review, as Fortify is updating the application.  We have talked extensively with Fortify and OWASP about the changes and how they match our workflow.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. To what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|-Team finalized (100%)&lt;br /&gt;
-Projects selected (100%)&lt;br /&gt;
-Preliminary workflow (100%)&lt;br /&gt;
-Projects submitted (0%)&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|We need feedback and direction on the preliminary workflow.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32336</id>
		<title>Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32336"/>
				<updated>2008-06-24T19:35:55Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|-Team finalized (Maureen Doyle, James Walden, Michael Whelan.)&lt;br /&gt;
-Projects selected for initial analysis (WebScarab, OWASP Enterprise Security API (ESAPI) Project, OWASP CSRFGuard Project.)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32335</id>
		<title>Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32335"/>
				<updated>2008-06-24T19:30:37Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|foo&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32334</id>
		<title>Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32334"/>
				<updated>2008-06-24T19:29:25Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
foo&lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32333</id>
		<title>Project Information:template Source Code Review OWASP Projects - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Source_Code_Review_OWASP_Projects_-_50_Review_-_Self_Evaluation_-_A&amp;diff=32333"/>
				<updated>2008-06-24T19:28:53Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Source Code Review OWASP Projects|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|OWASP Source Code Review OWASP-Projects Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- foo&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
&lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Source Code Review OWASP Projects|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=27041</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=27041"/>
				<updated>2008-03-25T17:47:14Z</updated>
		
		<summary type="html">&lt;p&gt;Walden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli &lt;br /&gt;
* Proposal: Make [[OWASP ASDR Project|OWASP ASDR Project]] a release quality document.&lt;br /&gt;
&lt;br /&gt;
The ASDR is a reference volume that contains basic information about all the foundational topics in application security. It intends to replace and refresh [[OWASP Honeycomb Project|Honeycomb Project]] with a new structure for articles and relationship between categories, thus making it a release quality doc.&lt;br /&gt;
&lt;br /&gt;
This idea raised when finished the [[Attack|Attack Reference Guide]] for [[OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]], where it was identified that OWASP reference articles need some special attention. Jeff Williams is totally supporting this project.&lt;br /&gt;
&lt;br /&gt;
We already have defined which type of article we should include on Desk Reference, as follows:&lt;br /&gt;
* [[:Category:Principle|Principles]]&lt;br /&gt;
* [[:Category:Threat_Agent|Threat Agents]]&lt;br /&gt;
* [[:Category:Attack|Attacks]]&lt;br /&gt;
* [[:Category:Vulnerability|Vulnerabilities]]&lt;br /&gt;
* [[:Category:Countermeasure|Countermeasures]]&lt;br /&gt;
* [[:Category:Technical Impact|Technical Impacts]]&lt;br /&gt;
* [[:Category:Business Impact|Business Impacts]]&lt;br /&gt;
&lt;br /&gt;
*Road Map: A complete project roadmap can be found on '''[[ASDR Table of Contents|ASDR Table of Contents]]'''. Basically, the following activities should be performed, some of them already started:&lt;br /&gt;
** Define articles templates for each reference type&lt;br /&gt;
** Define subcategories for articles classification&lt;br /&gt;
** Compile first DRAFT version of ASDR Book&lt;br /&gt;
** Articles development &amp;amp; Call for Volunteers&lt;br /&gt;
** Articles revision&lt;br /&gt;
** First version of OWASP ASDR book&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life Cycle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
This proposal is to request approval for leading the OWASP .NET project.  The project will contain information, materials and software that are relevant to building secure .NET web applications and services. The goal of the project is to provide deep content for all roles related to .NET web applications and services including: &lt;br /&gt;
&lt;br /&gt;
*Architectural guidance &lt;br /&gt;
*Developer tools, information and checklists &lt;br /&gt;
*IT professional content (for those that deploy and maintain .NET websites) &lt;br /&gt;
*Penetration testing resources &lt;br /&gt;
*Incident response resources &lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem. Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project. Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux). &lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project. &lt;br /&gt;
&lt;br /&gt;
'''Deliverables'''&lt;br /&gt;
&lt;br /&gt;
April 2, 2008 - May 3, 2008&lt;br /&gt;
*Project site layout reorganization&lt;br /&gt;
*Presentation materials for OWASP chapters for integrating the OWASP .NET project tools and references into a project life cycle&lt;br /&gt;
*Bullet points for community and media outreach plans&lt;br /&gt;
&lt;br /&gt;
April 13, 2008 - May 16, 2008&lt;br /&gt;
*Community outreach - contact .NET user groups, OWASP chapters to get feedback about tools and references that are needed for security in their fields of expertise.  Distribute materials for integrating OWASP .NET into their project plans and toolboxes.&lt;br /&gt;
*Media outreach - contact .NET media resources to talk about the .NET project and request content and contributors&lt;br /&gt;
*Start a special projects section for emerging projects in the .NET space, including Silverlight (Moonlight), WPF XBAP applications, Windows Communication Foundation,  ADO.NET Data Services, Enterprise Library 4.0, Policy and Dependency Injection, Agile methodologies.&lt;br /&gt;
&lt;br /&gt;
May 17, 2008 - June 14, 2008&lt;br /&gt;
*Reach out to other SoC .NET projects, try to find resources if the projects need them.&lt;br /&gt;
*Contribute to other SoC .NET projects, where needed.&lt;br /&gt;
*Gather feedback and follow up from first round of outreach effort.&lt;br /&gt;
&lt;br /&gt;
June 15, 2008&lt;br /&gt;
*Status report for Project&lt;br /&gt;
&lt;br /&gt;
June 16, 2008 - August 31, 2008&lt;br /&gt;
*Expand community and media outreach efforts.&lt;br /&gt;
*Continue to recruit and help other OWASP projects with resources.&lt;br /&gt;
*Update promotional materials to include emerging projects.&lt;br /&gt;
&lt;br /&gt;
August 31, 2008&lt;br /&gt;
*Retrospective of the first 5 months of the OWASP .NET Project.&lt;br /&gt;
&lt;br /&gt;
'''Long Term Vision'''&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project will be a valuable resource for securing .NET applications and services.  I want people to think of this project first when they need to gather information or find tools for designing, developing, maintaining, pen-testing software developed with .NET.  This project will be the hub for all .NET security resources, and of course with content created and maintained by the Open Source community.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications and the OWASP WebScarab tool for vulnerability analysis.  As a security practictioner, I care about the OWASP mission and I want to contribute to securing the Internet for everyone.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead software development teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker (C|EH).  I am on top of current trends and I am required to be up to speed regarding .NET web development and security.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;br /&gt;
&lt;br /&gt;
== OWASP Classic ASP Security Project  ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
I am interested in making P018 - OWASP Classic ASP Security Project happen, Classic ASP 2.0 and 3.0 applications are still largely used as this technology is more than 10 years old and was largely used. there are thousands of sites on the wild that need guidance on the security arena. This is where OWASP can come up and provide help for “making the Web a better place” and continue spreading the word on security. I have always be a passionate of the technology (regardless of its inconveniences such as being old and DLL-hell prone) and I am really exited on the idea of sharing my knowledge of this area to the world and what best that though OWASP.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
Create a secure framework for Classic ASP application by complementing existing OWASP projects with documentation for this particular technology and the creation of security libraries. More specifically:&lt;br /&gt;
* Creation of a Common Object Repository for ASP applications based on OWASP ESAPI Project including objects and/or references to libraries for security applications all this aligned with OWASP Top10 and OWASP Guide .&lt;br /&gt;
* Create Documentation aligned to OWASP Code Review Project Checklist providing additional technology-specific checks.&lt;br /&gt;
* Addition of expression for Code Review Tool to support Classic ASP applications.&lt;br /&gt;
* Implementation of Version 1 of Stinger for ASP either by using an installable COM library or ISAPI.&lt;br /&gt;
* This same module will compliment the OWASP Validation Documentation Project.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver. &lt;br /&gt;
&lt;br /&gt;
Also I’ve had close contact with OWASP since 2005&lt;br /&gt;
[https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html] by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish.&lt;br /&gt;
&lt;br /&gt;
== Internationalization Guidelines and OWASP-Spanish Project ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
The main goal of OWASP is to spread the word about security (“Our mission is to make application security &amp;quot;visible,&amp;quot; so that people and organizations can make informed decisions about application security risks.”) and OWASP has done great work so far :). And now it’s time for a next big step.&lt;br /&gt;
&lt;br /&gt;
The number of native and secondary speakers in the world for Chinese, Spanish, French, Russian, Arabic and Indi languages are estimated in similar number to English speaking or even more (Some References at [http://en.wikipedia.org/wiki/Ethnologue_list_of_most_spoken_languages Ethnologue], [http://encarta.msn.com/media_701500404/Languages_Spoken_by_More_Than_10_Million_People.html Encarta], [http://en.wikipedia.org/wiki/List_of_languages_by_number_of_native_speakers Wikipedia]). I think is a good time for OWASP to reach those that do not speak English to have full access to all the OWASP materials, not just a couple of documents.&lt;br /&gt;
&lt;br /&gt;
OWASP, while open to translations, do not have clear guidelines on how to translate OWASP contents and (AFAIK) there is no multi-language support in OWASP.org site. This is understandable as there is no formal project for internationalization so far. &lt;br /&gt;
&lt;br /&gt;
'''Oportunity and Effort'''&amp;lt;br&amp;gt;&lt;br /&gt;
This is great opportunity to make Spanish the first language on which the OWASP site and documentation is fully translated and at the same time share the experience with other people interested in the same objective, Bring OWASP to the world.  And this is something I’ve being pushing for some time ago and that could be possible “at once” via SoC 2008.&lt;br /&gt;
&lt;br /&gt;
I understand this is significant effort so to have it done I will count with the help of 6 people (friend of mine, all of them Security auditors with excellent English level) plus a few well known contributors from OWASP-Spanish effort, so the founding will be divided among the people involved in the same proportion of the work they do for the completion of this effort. This, to encourage delivery.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
* Team up with Larry Casey to implement Multilanguage support in OWASP.org Mediawiki.&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to start a new language translation for OWASP Document and Site Pages&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to implement internationalization and localization ([http://www.w3.org/International/ i18n]) on OWASP Software &lt;br /&gt;
* Full translation to Spanish of all the release-level document projects. Those are:&lt;br /&gt;
** Top 10 2007&lt;br /&gt;
** Guide 2 (Already translated)&lt;br /&gt;
** Testing Guide (Already Translated)&lt;br /&gt;
** Legal&lt;br /&gt;
** FAQ&lt;br /&gt;
* Full Translation of major sections of OWASP Site&lt;br /&gt;
** Project Main Pages (Release, Beta and Alpha levels for both documents and tools projects)&lt;br /&gt;
** Principles&lt;br /&gt;
** References Section&lt;br /&gt;
** Conferences&lt;br /&gt;
** News (Those currently displayed in OWASP site)&lt;br /&gt;
** About OWASP&lt;br /&gt;
* Evaluation of Spanish translation approach for WebGoat and WebScarab and delivery of this document to Bruce and Rogan for possible implementation in near future.&lt;br /&gt;
* Leverage for deploy of es.owasp.org, the domain already exists but is not redirecting correctly.&lt;br /&gt;
* Create a Communication strategy to help and keep track on new pages or changes in significant pages so all the translations are in sync.&lt;br /&gt;
&lt;br /&gt;
'''Out of Scope'''&amp;lt;br&amp;gt;&lt;br /&gt;
Translation of the following sections are NOT in Scope&lt;br /&gt;
* Local Chapters Pages&lt;br /&gt;
* Presentations&lt;br /&gt;
* Conferences&lt;br /&gt;
* Videos&lt;br /&gt;
* Blogs&lt;br /&gt;
* All the projects deliverables in Alpha and Beta Stages&lt;br /&gt;
* All the documentation “on development” like Guide Version 3.0&lt;br /&gt;
* Translation of Pages, documentation or tools to other language other than Spanish according to the stated in above section.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I’ve being part of contributions to OWASP documents on the translation arena since 2005 [https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html], a few of them by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish. It is time to make the full job done :).&lt;br /&gt;
&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver.&lt;br /&gt;
&lt;br /&gt;
== The Ruby on Rails Security Guide v2 ==&lt;br /&gt;
Heiko Webers&lt;br /&gt;
&lt;br /&gt;
The last security guide for Rails [http://www.owasp.org/index.php/Category:OWASP_Web_Application_Security_Put_Into_Practice] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The Ruby on Rails Security Project [http://www.rorsecurity.info/] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a book [http://www.lulu.com/content/1412042]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.&lt;br /&gt;
&lt;br /&gt;
In the new Rails Security Guide I'd like to&lt;br /&gt;
* update the entire book to match Rails 2.0&lt;br /&gt;
* cover new topics, including, but not limited to:&lt;br /&gt;
** Intranet and administration interface security,&lt;br /&gt;
** phishing,&lt;br /&gt;
** real-world attack situations,&lt;br /&gt;
** short excursus on server monitoring,&lt;br /&gt;
** the new CookieStore session management,&lt;br /&gt;
** vulnerabilities in popular plug-ins,&lt;br /&gt;
** denial-of-service attacks&lt;br /&gt;
* cover all OWASP Top Ten security vulnerabilities&lt;br /&gt;
* a more compact writing style, more examples and &amp;quot;questions-and-answers&amp;quot;&lt;br /&gt;
* introduce the OWASP and Rails security to a greater audience&lt;br /&gt;
&lt;br /&gt;
== OWASP Application Security Verification Standard ==&lt;br /&gt;
&lt;br /&gt;
*Mike&lt;br /&gt;
&lt;br /&gt;
'''OWASP Application Security Verification Standard Proposal'''&lt;br /&gt;
&lt;br /&gt;
'''Educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
The applicant is a hands-on senior professional services manager with a trademark of&lt;br /&gt;
developing creative solutions to complex application security-related technical problems. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a background in trusted product evaluation:&lt;br /&gt;
&lt;br /&gt;
*CC evaluation&lt;br /&gt;
*CC evidence development, including operating system test code development&lt;br /&gt;
*CC project management&lt;br /&gt;
*TCSEC evaluation&lt;br /&gt;
*TCSEC project management&lt;br /&gt;
*TEF management&lt;br /&gt;
*CCTL management&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in security-related software development and integration:&lt;br /&gt;
&lt;br /&gt;
*PKI toolkit development&lt;br /&gt;
*PK-E application integration&lt;br /&gt;
*Secure web portal application development&lt;br /&gt;
*Secure web portal integration&lt;br /&gt;
*Secure instant messaging application development, including three patents&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in cryptomodule testing:&lt;br /&gt;
&lt;br /&gt;
*FIPS 140 evaluation&lt;br /&gt;
*FIPS 140 evidence development&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
The applicant does not have experience in contributing to open communities.&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
OWASP is looking for a commercially-workable open standard for performing application security verification efforts. The problem is that there is a huge range in the coverage and level of rigor available in the market, and consumers have no way to tell the difference between someone just running a grep tool, and someone doing painstaking code review and manual testing. So, a standard is needed.&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s)'''&lt;br /&gt;
&lt;br /&gt;
The applicant’s proposal will address the above challenges as follows:&lt;br /&gt;
&lt;br /&gt;
*The applicant will define an evaluation framework that may be used to conduct OWASP Application Security Verification Standard certifications.&lt;br /&gt;
*The applicant will define an OWASP Application Security Verification Standard which defines levels that applications may be certified against.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
The applicant will carry out these activities. Please see below for a proposed list of specific deliverables.&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following deliverables:&lt;br /&gt;
&lt;br /&gt;
*'''Scheme Overview document.''' This will define the overall framework with roles, responsibilities, and processes.&lt;br /&gt;
*'''Evaluation and Certification document.''' This will describe the evaluation and certification process.&lt;br /&gt;
*'''Conditions for the Use of Trademarks.''' This will describe OWASP’s name, logo, and certificate may be used and referenced.&lt;br /&gt;
*'''Evaluation Report Content Requirements.''' This will describe the content requirements of evaluation reports.&lt;br /&gt;
*'''OWASP Application Security Verification Standard.''' This will define the levels that applications may be certified against.&lt;br /&gt;
*'''OWASP Application Security Verification Standard Appendix A.''' This will define the required content of the OWASP Application Security Verification Standard Security Policy.&lt;br /&gt;
*'''Policy Letter #1. Acceptance of Security Policies into OWASP Evaluation''' This will define the requirements to be listed as in evaluation on the OWASP web site.&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following rough project schedule:&lt;br /&gt;
&lt;br /&gt;
*2nd April. Project kickoff.&lt;br /&gt;
*15th June. Alpha Quality drafts of Scheme Overview document and of OWASP Application Security Verification Standard document completed.&lt;br /&gt;
*31st August. Project completion. Beta Quality drafts of all documents completed.&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
The long-term vision for the project is to normalize the range in the coverage and level of rigor available in the market when it comes to performing application security verification.&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected.'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a uniquely-qualified perspective given his experience with TCSEC, TTAP, CC, FIPS 140-1, and FIPS 140-2 evaluation programs, and his real-world perspective as a developer and integrator of security-related applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== GTK+ GUI for w3af project ==&lt;br /&gt;
&lt;br /&gt;
''Facundo Batista''&lt;br /&gt;
&lt;br /&gt;
'''Your educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
I'm Electronic Engineer with a Master in Engineer Innovation in&lt;br /&gt;
Bologna University, Italy. I live in Buenos Aires, Argentina, and love&lt;br /&gt;
reading books, playing tennis, and programming Python.&lt;br /&gt;
&lt;br /&gt;
I worked in a mobile company for six years, in the Network Management&lt;br /&gt;
department, then I was Chief Developer of a Mobile Content Provider,&lt;br /&gt;
and now I'm Solution Architect in Multimedia &amp;amp; Systems Integration in&lt;br /&gt;
Ericsson. Also I was professor in several universities, high schools&lt;br /&gt;
and other institutions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
None, more than working in w3af. However, my proposal here is not&lt;br /&gt;
related to the security part of the product, but to its graphical&lt;br /&gt;
interface and usability.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I'm very involved in the free software and open source community. I'm&lt;br /&gt;
a Python Core Developer and member of the Python Software Foundation&lt;br /&gt;
by merit. I have a long history of talks given in several&lt;br /&gt;
international (PyCon, EuroPython) and national (a lot!) conferences. I&lt;br /&gt;
also teach Python in educational institutions, enterprises and as a&lt;br /&gt;
private instructor. I founded Python Argentina, the national users&lt;br /&gt;
groups, and I'm a very active member of it.&lt;br /&gt;
&lt;br /&gt;
I also lead other open source projects (SMPPy, SiGeFi, etc.) and&lt;br /&gt;
particpate in others (Docutils, w3af itself, etc.).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
My main objective is to minimize the effort and learning curve of&lt;br /&gt;
using w3af, providing a very usable graphical interface.&lt;br /&gt;
&lt;br /&gt;
Note that as the interface is cross platform, being usable also in the&lt;br /&gt;
win32 environment, it will help to popularize the w3af project.&lt;br /&gt;
&lt;br /&gt;
This will allow users without information security knowledge to verify&lt;br /&gt;
that their web applications are correctly programmed and configured.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
I will carry the following activities, detailed later in smaller steps:&lt;br /&gt;
&lt;br /&gt;
- Design and code new windows and interfaces to increase the functionality of the project.&lt;br /&gt;
&lt;br /&gt;
- Tuning of the process workflow, allowing a more intuitive way of working.&lt;br /&gt;
&lt;br /&gt;
- Visual polishing for a more pleasant and intuitive tool.&lt;br /&gt;
&lt;br /&gt;
- Usability tests and improvements.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
''New features implemented in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Local proxy to trap and modify requests and responses sent from a browser.&lt;br /&gt;
&lt;br /&gt;
- Manually send a request and analyze the response.&lt;br /&gt;
&lt;br /&gt;
- Manually create a fuzzed requests based on tokens, so user can construct easily differents HTTP request with a regex-like semantics.&lt;br /&gt;
&lt;br /&gt;
- Wizard to perform a vulnerability assessment.&lt;br /&gt;
&lt;br /&gt;
- Graphical display of site map and vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
- Reload a plugin after its edited from within the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Embebed tool to encode/decode URL/Base64 and to hash sha1/md5.&lt;br /&gt;
&lt;br /&gt;
- HTTP response side by side content compare.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Usability improvements in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Meetings with a usability expert that the w3af team leader has already contacted and worked with.&lt;br /&gt;
&lt;br /&gt;
- Kill all pending bugs and make a stable release.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Documentation:''&lt;br /&gt;
&lt;br /&gt;
- Users guide for the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Help system for the GUI itself&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
To provide the web application security community with a stable and fully &lt;br /&gt;
featured framework to perform all the tasks included in a penetration test&lt;br /&gt;
from within the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected'''&lt;br /&gt;
&lt;br /&gt;
w3af is one of the most active web application security projects;&lt;br /&gt;
the community that supports it is growing and we need the support of &lt;br /&gt;
already established organizations like OWASP to keep working at the &lt;br /&gt;
rate that we want to.&lt;br /&gt;
&lt;br /&gt;
== P025 OWASP Positive Security Project ==&lt;br /&gt;
&lt;br /&gt;
by Eduardo Vianna de Camargo Neves&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
A common approach on most companies is to increase the protection of their assets after the occurrence of a considerable impact. However some companies learned that a positive approach on IT Security is most effective and can reduce the financial costs on responses to security incidents. Benchmarking the application security practices on the corporate world will allow us to understand what steps are required to keep the IT environment protected, using this knowledge to support the development of a campaign to spread a positive security posture in the market. The liaison with companies that maintain good security practices  will help to start this initiative from a higher degree and involve several actors on the security stage for the same direction to a market were security is understood as a business value.&lt;br /&gt;
&lt;br /&gt;
'''Approach'''&lt;br /&gt;
&lt;br /&gt;
Assessing results from the Corporate Application Security Rating Guide Project and other public sources will be used to support the development of the Positive Security Project with facts from a real analysis.&lt;br /&gt;
&lt;br /&gt;
'''Benefits'''&lt;br /&gt;
&lt;br /&gt;
The whole community will be benefited from this initiatives. With the adequate support from OWASP to maintain the project active and liaise with big players on the market, we can expect the following:&lt;br /&gt;
&lt;br /&gt;
• The community will receive a guide to practice the &amp;quot;Positive Approach&amp;quot; that will allow them to compare their own security practices within the market. As this will be a public document, suppliers and buyers worldwide will share the same information allowing them to adequate the expectations on the usage of security services and tools.&lt;br /&gt;
&lt;br /&gt;
• Compliance and alignment with Positive Approach can be used as a marketing tool by the companies, allowing them to sell security as a business value and avoiding the old-fashion and inadequate FUD approach.&lt;br /&gt;
&lt;br /&gt;
• The knowledge and relationship developed during the development will support the Positive Security Project with real information, increasing the credibility of the initiative for the market.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide and the Positive Security Project can be walk in parallel, merging their information to support a concise and continuous marketing campaign to encourage a positive approach on the market.&lt;br /&gt;
&lt;br /&gt;
• As an open community free from commercial pressures, OWASP can use both projects to support the evaluation of security products for the market, allowing the organization to receive profits from these services and support current and future projects.&lt;br /&gt;
&lt;br /&gt;
'''Summarized Work Breakdown Structure (WBS)'''&lt;br /&gt;
&lt;br /&gt;
All the activities will be leaded by Eduardo V. C. Neves, which will be responsible as a single point of contact with the sponsors and to manage a team of compromised volunteers from OWASP community and participants from security communities and associations (i.e. ISSA, SANS and ISC2).&lt;br /&gt;
&lt;br /&gt;
The activities will be carried on WBS summarized bellow. Dates presented should be considered as deadlines for the activities:&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and definition of the marketing material and support documents (April 11)&lt;br /&gt;
&lt;br /&gt;
• Approval of marketing templates for Positive Security Project (April 25) (1)&lt;br /&gt;
&lt;br /&gt;
• Development of the Positive Security Project material (i.e. blog and marketing sheets) (May 30)&lt;br /&gt;
&lt;br /&gt;
• Liaison with the OWASP Members and analyzed companies to present the project and negotiate their participation as supporters, sponsors or contributors. (June 27)&lt;br /&gt;
&lt;br /&gt;
• Update on Positive Security approach deliverables(July 4)&lt;br /&gt;
&lt;br /&gt;
• Presentation of the Positive Security Project approach on the market (July 31) (2)&lt;br /&gt;
&lt;br /&gt;
• Conference calls with team members to evaluate the results of the initiatives in all countries and produce project´s documents (i.e. lessons learned, update on marketing material and evaluation of alternative approaches for the future steps). (August 15)&lt;br /&gt;
&lt;br /&gt;
• Prepare project documentation and present to the OWASP community on the web site (August 31)&lt;br /&gt;
&lt;br /&gt;
''(1) Support from OWASP Foundation and community are required to evaluate adequate marketing templates and translate original documents for their own languages''&lt;br /&gt;
&lt;br /&gt;
''(2) Support from OWASP community is required to spread the word on all countries were OWASP members are located.''&lt;br /&gt;
'''''&lt;br /&gt;
&lt;br /&gt;
'''Project Control'''&lt;br /&gt;
&lt;br /&gt;
The project will be managed following PRINCE2 Process Model and all control documents published for the OWASP community. The following mandatory project control documents are planned:&lt;br /&gt;
&lt;br /&gt;
• Project Initiation Document: To document project´s background, definition, objectives, approach, etc.&lt;br /&gt;
&lt;br /&gt;
• Communication Plan: To assure that OWASP Community are being continuous communicated about project status and deliverables achievement.&lt;br /&gt;
&lt;br /&gt;
• Highlight Report: To provide the OWASP Community with a summary of the project status, progress and potential problems or areas where help may be required.&lt;br /&gt;
&lt;br /&gt;
• End Project Report: To present project achievements. Should be considered the final project report.&lt;br /&gt;
&lt;br /&gt;
More documents may be included during project development to support the control and assure a high quality level (i.e. issue log, project approach).&lt;br /&gt;
&lt;br /&gt;
'''Long Range Plan'''&lt;br /&gt;
&lt;br /&gt;
The project should be used as a tool to support efforts to encourage and make the positive approach a reality on the IT Security field. These initiatives shall be supported by OWASP as long term plans and grow to a continuous world-wide campaign in this direction that must achieve big players on the market and be recognized by the community as a tool that must be used to evaluate security enabled companies and products. &lt;br /&gt;
&lt;br /&gt;
'''Why me?'''&lt;br /&gt;
&lt;br /&gt;
Can be me, you or anyone that carries this project in a professional fashion and assure that all deliverables are being achieved. The most important parts is to make it happen, talk and get the support from reputable associations and large companies (OWASP Members are a good start) and lead it as a long range responsibility.&lt;br /&gt;
&lt;br /&gt;
I am running to win this project because I believe in all of this. I see both as very valuable initiatives that can help companies to make more business; people to get more jobs and the whole community to win in a scenario where our contributions on the security market are recognized as business tools.&lt;br /&gt;
&lt;br /&gt;
'''About me'''&lt;br /&gt;
&lt;br /&gt;
Information Security professional and enthusiastic with 15 years dedicated to achieve expressive results in the areas of IT, Information Security, Compliance and Project Management. A CISSP in good stand and Officer at the ISSA Brazilian Chapter, my professional career gave me extensive knowledge in several fields of Information Security with accumulated experience at consulting firms, as CSO at a world player company on consumer goods market and now as an entrepreneur at Latin American market.&lt;br /&gt;
&lt;br /&gt;
''Application security experience and accomplishments''&lt;br /&gt;
&lt;br /&gt;
My work experience is on Security Management, Risk Assessment, Business Continuity and Disaster Recovery, Security Awareness and other managed-related fields on our industry. I don’t have hands-on experience on application security and this is the main reason why I am running to be qualified on the project described bellow, where I believe that my skills can be used to achieve an excellent result for the community.&lt;br /&gt;
&lt;br /&gt;
''Participation and leadership in open communities''&lt;br /&gt;
&lt;br /&gt;
• Member of OWASP Brazil where I made some small contributions in a recent past.&lt;br /&gt;
&lt;br /&gt;
• Member of ABNT/CB-21/SC02 committee, Brazilian ISO representative for 27001 and 17799 standards&lt;br /&gt;
&lt;br /&gt;
• Officer of ISSA Brazil Chapter where I am responsible for the South Region and as the editor of Antebellum, the ISSA Brazil Journal&lt;br /&gt;
&lt;br /&gt;
• Founder and member of GISI-PR, an open community focused on discuss and promote Information Security initiatives within Paraná State, Brazil&lt;br /&gt;
&lt;br /&gt;
== P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application ==&lt;br /&gt;
'''Name'''&lt;br /&gt;
&lt;br /&gt;
Michael Coates&lt;br /&gt;
&lt;br /&gt;
'''Project'''&lt;br /&gt;
&lt;br /&gt;
P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses, '''&lt;br /&gt;
&lt;br /&gt;
As critical applications continue to become more accessible and inter-connected, it is paramount that the information be protected. We must also realize that our defenses may not be perfect. Given enough time, attackers can identify security flaws in the design or implementation of an application. In addition to implementing layers of defense within an application, it is critical that we identify malicious individuals before they are able to identify any gaps in our defenses. The best place to identify malicious activity against the application is within the application itself.&lt;br /&gt;
Network based intrusion detection systems are not appropriate to handle the custom and intricate workings of an enterprise application and are ill-suited to detect attacks focusing on application logic such as authentication, access control, etc.  The application itself is the best place to identify and respond to malicious activity.&lt;br /&gt;
This project will create the framework which can be used to build a robust system of attack detection, analysis, and response within an enterprise application&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s), '''&lt;br /&gt;
&lt;br /&gt;
I plan to use a methodical approach throughout the creation of this resource. I will reference my own professional experience, OWASP resources, ESAPI, and academic materials to identify a robust set of potential attacks and identification methods. Thresholds will be recommended for each of the detected attacks. Each recommended threshold value and response recommendation will be accompanied with additional information to describe the purpose of the threshold and recommendation. This additional information will allow the reader to determine if the threshold is appropriate for their implementation.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities, '''&lt;br /&gt;
&lt;br /&gt;
I will complete the following activities:&lt;br /&gt;
1. Identify and define attack patterns against applications&lt;br /&gt;
2. Document points of detection within the application for the attack patterns &amp;amp; identify key information to log&lt;br /&gt;
3. Create thresholds for generating security alerts&lt;br /&gt;
4. Define recommended response actions for the security alerts&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress, '''&lt;br /&gt;
&lt;br /&gt;
April 2, 2008 - Project Begins&lt;br /&gt;
&lt;br /&gt;
April 2, 2008-April 12, 2008 - High level planning &amp;amp; design 	&lt;br /&gt;
&lt;br /&gt;
April 12, 2008-May 1, 2008 - Identify and define attack patterns against applications	&lt;br /&gt;
&lt;br /&gt;
May 1, 2008-June 1, 2008 - Document points of detection within the application for the attack patterns &amp;amp; identify key information to log	&lt;br /&gt;
&lt;br /&gt;
June 1, 2008-June 13, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
June 15, 2008 - Status Report	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Create thresholds for generating security alerts	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Define recommended response actions for the security alerts	&lt;br /&gt;
&lt;br /&gt;
Aug 16, 2008-Aug 30, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
Aug 31, 2008 - Project Complete	&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project, '''&lt;br /&gt;
&lt;br /&gt;
1.  I’d like to include a tiered type approach of thresholds and responses. This is would be similar to the approach used by FISMA of defining different controls for High, Medium, and Low systems.&lt;br /&gt;
&lt;br /&gt;
2. Building on item #1, I want to eventually include a system which lets the user provide information about their system.  This information could include rating or prioritizing different security concerns. a customized set of monitoring points, thresholds and response actions can be recommended for the application based on the provided data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About Me'''&lt;br /&gt;
&lt;br /&gt;
'''Education &amp;amp; Professional Background'''&lt;br /&gt;
&lt;br /&gt;
Masters of Science in Computer, Information and Network Security – DePaul University &lt;br /&gt;
(Expected Graduation 2009)&lt;br /&gt;
Bachelor of Science in Computer Science – University of Illinois&lt;br /&gt;
Extensive experience in conducting black and white box security reviews of complex applications and networks for major financial organizations and international telecoms. I also have experience working as the primary investigator of attacks against a multi-national organization with IDS sensors in networks throughout the world. In addition, I have experience working with several regulatory controls and security standards (FISMA, NIST, GLBA etc). My experience as an ethical hacker and incident responder puts me in an excellent position to tackle this project. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
I am a Senior Computer Security Engineer with Aspect Security where I perform security code reviews and application security testing against a variety of platforms. Prior to working with Aspect Security, I was heavily involved in the discovery and exploitation of application vulnerabilities during black box ethical hacking assessments for numerous clients.&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I am a member of OWASP and attend Chicago OWASP chapter meetings. I also attend ChiSec, an informal meet-up of security professionals in the Chicago area. In addition, I interact with the community through my security blog. http://michaelcoates.wordpress.com. &lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected. '''&lt;br /&gt;
&lt;br /&gt;
I created a similar framework while working within a Security Operation Center. I created attack scenarios, identified relevant IDS events, defined thresholds and appropriate response action for the Security analysts.&lt;br /&gt;
&lt;br /&gt;
'''Requested Reviewer - Eric Sheridan, Application Security Consultant at Aspect Security, Inc.'''&lt;br /&gt;
&lt;br /&gt;
Eric Sheridan is an Application Security Consultant at Aspect Security, a consulting services company specializing in application security. At Aspect Security, Eric specializes in execution of security verification assessments and the establishment of security activities throughout the development lifecycle. In addition, Eric is an instructor in Aspect’s portfolio of Application Security Courses. Eric is also an active participant in OWASP whose contributions include work with projects such as WebGoat, Stinger, CSRFGuard, CSRFTester, and the SASAP project from OWASP SPoC 2007. Eric was also a featured speaker at the 2007 OWASP/WASC San Jose conference.&lt;br /&gt;
&lt;br /&gt;
Contact Information: eric dot sheridan 'at' owasp dot org&lt;br /&gt;
&lt;br /&gt;
== OWASP Interceptor Project - 2008 Update ==&lt;br /&gt;
&lt;br /&gt;
by Justin Derry&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_Interceptor_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
The OWASP Interceptor project was originally written by myself and donated to the OWASP project. Since it has been online numerous people have downloaded the tools and used the code/toolkit. Currently the industry has very limited “XML” or SOAP client testing tools that are designed specifically to perform XML interception and manipulation. The Objective of the Interceptor project is to provide a strong tool for performing XML penetration tests against Web Service (or XML/SOAP) endpoints. The tool should not replace other proxy interception tools such as Charles, Web Scarab and so on, but be purely focused on handling and reading XML structures from clients.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Interceptor tool includes a “swiss-army” knife of features that will help with decoding/hash generation and interpretation of XML code. The key objective is to make a tool that can assist with the collection, inspection and attack replay of XML requests against service endpoints. This year it’s time for an update. The tool doesn’t run on Vista and needs a number of back-end features addressed as well as some help files etc. (Help to get the tool out of BETA status).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Objectives this year'''&lt;br /&gt;
&lt;br /&gt;
This year I see the following objectives in the application code base.&lt;br /&gt;
•	Get the Interface to run on all Window Platforms (.NET) Win2000, XP and Vista;&lt;br /&gt;
&lt;br /&gt;
•	Update the TCP handle libraries to be faster&lt;br /&gt;
&lt;br /&gt;
•	Update the XML Parser engine to support the latest structures&lt;br /&gt;
&lt;br /&gt;
•	Provide a “default” attack database of known XML attack methods (this is a big one)&lt;br /&gt;
&lt;br /&gt;
•	Write a number of help files on how to use the tool&lt;br /&gt;
&lt;br /&gt;
•	Update the toolkit BASE64 Decoder, XML Generators etc with further tools&lt;br /&gt;
&lt;br /&gt;
•	Write a better “reporting” engine to show the result of simulated attack responses&lt;br /&gt;
&lt;br /&gt;
•	Better HTTP support for Manipulation, Authentication and Header Injection etc&lt;br /&gt;
&lt;br /&gt;
•	Better support for interception and handling AJAX XML requests&lt;br /&gt;
&lt;br /&gt;
These are the core features I would like to introduce, with also further to probably come as a part of the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&lt;br /&gt;
&lt;br /&gt;
The current development cycle stopped due to limited time and the need to purchase the IDE tools to develop the interface in .NET. As a Summer of Code 2008 sponsored project we can get the IDE interface tools to implement “Vista” features that will see the tool run on all .NET platforms (Win2000, XP and Vista). Recent changes in my job will allow me to spend more time on developing the toolkit.&lt;br /&gt;
&lt;br /&gt;
Over a number of years I have been involved with OWASP, whilst most recently getting involved with running the OWASP Australia Security Conference for 2008, as well as the Brisbane Chapter. I am also working in the Asia Pacific RIM to further increase the awareness of OWASP and Application Security. My Conference duties for the year have finished up (till planning starts again in a couple of months) so my time can be invested in updating the toolkit.&lt;br /&gt;
&lt;br /&gt;
I believe during the previous years, i have shown OWASP that i am willing and able to produce a quality outcome and i am prepared to put the effort into OWASP to acheive the goals set out for this project. &lt;br /&gt;
&lt;br /&gt;
Some of the Sponsorship money for the project would go to purchasing a specific toolkit for the UI. (The UI is important simply because we want the application to be user friendly). Xceed Components provide a Smart UI as well as some of the decoding and compression features the tool needs. This would require us to approach them upfront for a “free” licence or use some of the Sponsorship money to buy the toolkit. But we can tackle that problem when we come to it.&lt;br /&gt;
&lt;br /&gt;
== SQL Injector Benchmarking Project (SQLiBENCH) ==&lt;br /&gt;
&lt;br /&gt;
by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
'''Prelude'''&lt;br /&gt;
&lt;br /&gt;
There're a lot of and great open source tools (takeover/dumpers/hybrid) for taking advantage of an sql injection vulnerability both used by web application security specialists and attackers. &lt;br /&gt;
Techniques used, databases supported, algorithms employed and abilities implemented by these &amp;quot;sql injectors&amp;quot; greatly varies. Standardization is one of the abstract goals of OWASP and we think it's important to standardize general vulnerability techniques exists in web applications and one of the biggest one is sql manipulation. &lt;br /&gt;
In our effort, we aim to produce a standardization of techniques used in exploiting sql injection by automatic tools. &lt;br /&gt;
&lt;br /&gt;
'''Proposal'''&lt;br /&gt;
&lt;br /&gt;
The goal of the project is to create a detailed set of benchmarking criterias for automatic sql injection tools and applying these to a set of open source sql injectors, producing analysis/benchmarking reports.&lt;br /&gt;
Additionaly, in a semi-academic manner, algorithms used by several sql injectors will be analyzed both implementation and complexity vise.&lt;br /&gt;
&lt;br /&gt;
'''Deliverables And Project Schedule Milestones'''&lt;br /&gt;
&lt;br /&gt;
Two set of documents will be produced. One of them will include the benchmarking criterias and the other will comprise of analysis of selected sql injectors against the benchmarking criterias.&lt;br /&gt;
Moreover, an interactive visual data flow diagram, giving hints to testers about which tool should be used under which circumstances, will be implemented with web-based technologies such as jquery library. &lt;br /&gt;
&lt;br /&gt;
April 03    Project Kickoff&lt;br /&gt;
&lt;br /&gt;
April 03-30 Determination of the benchmarking criterias &lt;br /&gt;
&lt;br /&gt;
May   01-15 Producing a test environment image with 5-6 rdbms (MSSQL Express, Oracle Express, DB2 Express, MySQL, PgSQL, etc.) and a vulnerable application (which will support different sql injection types, databases and include logging capabilities)&lt;br /&gt;
&lt;br /&gt;
May   15-31 Selecting and installing automatic sql injectors onto the test system and starting to use them on vulnerable application&lt;br /&gt;
&lt;br /&gt;
June  01-30 Analysing tools and applying benchmarking criterias, contacting the authors as we proceed &lt;br /&gt;
&lt;br /&gt;
July  01-31 Producing reports for benchmarking criterias and tool analysis&lt;br /&gt;
&lt;br /&gt;
'''About Us'''&lt;br /&gt;
&lt;br /&gt;
We're part of OWASP-Turkey. [http://www.h-labs.org Mesut Timur] is a junior in the Computer Engineering Dept. of [http://www.gyte.edu.tr University of GYTE] and [http://www.webguvenligi.org Bedirhan Urgun] is a web/application security specialist in [http://www.uekae.tubitak.gov.tr TUBITAK-UEKAE].&lt;br /&gt;
&lt;br /&gt;
== OWASP-WeBekci Project ==&lt;br /&gt;
&lt;br /&gt;
by Bunyamin Demir&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_WeBekci_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
Web application firewalls (WAF) are gaining importance among the information security technologies designed to protect web sites from attack. WAF solutions prevent attacks that network firewalls and intrusion detection systems can't and they require no modification of application source code. ModSecurity [http://www.modsecurity.org/] is an open source web application firewall that runs as an Apache module. It is an embeddable web application firewall and it provides protection from a range of attacks against web applications. It is an open source project available to everyone; it however does not come with an admin panel. &lt;br /&gt;
&lt;br /&gt;
I decided to provide this essential tool with a control panel which I believe will ease and thus encourage its usage.&lt;br /&gt;
&lt;br /&gt;
ModSecurity allows for HTTP traffic monitoring and real-time analysis with no changes to existing infrastructure. My main goal is to analyze attacks and generate rules to change the configuration of the ModSecurity accordingly.&lt;br /&gt;
&lt;br /&gt;
ModSecurity  has a feature called “flexible rule engine” as its heart of Attack Prevention capability . It uses ModSecurity’s “Rule Language,” (a programming language designed to work with HTTP transaction data). It is easy to use and flexible; yet the system administrators need to learn its own rules to create what is called “Certified ModSecurity Rules” to be implemented. My control panel will automate the major code-generation in Rule Language. &lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&lt;br /&gt;
&lt;br /&gt;
* '''Configuration'''        : Most of the configuration parameters will be managed through the web interface&lt;br /&gt;
* '''Rule Generator'''       : Basic rules will be generated using the web interface&lt;br /&gt;
* '''Core Rule Integration''': Core rules will be added to the database for use&lt;br /&gt;
* '''Logging and Reporting''': Apache error log and modsec_audit log will be parsed and presented to the user thru the web interface&lt;br /&gt;
* '''DB Support'''           : MySQL&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
Being a SpoC2007 project, it couldn't be implemented mainly due to a job change and therefore lack of time. With the help of Bedirhan Urgun we'll be able to produce a quality web admin panel GUI for a same host modsec installation infrastructure. We are both part of OWASP Turkey [http://www.owasp.org/index.php/Turkey] and tried to produce a great deal of awareness both about web security and OWASP with both documents/chapter meetings/email list and mini-conferences.&lt;br /&gt;
&lt;br /&gt;
== Teachable Static Analysis Workbench ==&lt;br /&gt;
&lt;br /&gt;
By Dmitry Kozlov, Igor Konnov&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''&lt;br /&gt;
&lt;br /&gt;
This application covers two OWASP Project proposals: P002 Teachable Static Analysis Workbench and P023 Code Review Tree. These project proposals look complementary and the key idea was to create ONE tool for code review instead of number non-integrated tools.&lt;br /&gt;
Note: this project is very close to P024 Attack Surface Metric too – based on web application entry points and used backends it is easy to compute such a metric.&lt;br /&gt;
&lt;br /&gt;
'''Project objectives and deliverables:'''&lt;br /&gt;
&lt;br /&gt;
Project is intended two deliverables: research technical report (publication ready article) and a workbench prototype.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The research will be intended to answer the following questions: &lt;br /&gt;
* Can we integrate existing open source static analysis tools (OWASP and third-party) to work altogether? We plan analysis to cover the following tools: LAPSE, Orizon, ESAPI, FindBugs.&lt;br /&gt;
* How static analysis workbench can be taught by security analyst?&lt;br /&gt;
* How static analysis workbench can support web-applications built using MVC frameworks?&lt;br /&gt;
&lt;br /&gt;
Workbench prototype will be Java-based Eclipse plug-in which aim is to help security analyst/code reviewer validation of web application. At prototype step we suggest to analyze J2EE Web tier applications build on Java Servlets, JSP (without business logic in it) and one MVC framework (Apache Struts).  We plan workbench prototype to have the following functionality:&lt;br /&gt;
* Input validation vulnerabilities analysis: identification of web application entry points (aka attack surface in P024), call graph for each entry point (see “Packages -&amp;gt; Classes -&amp;gt; Methods -&amp;gt; callsites” in P023), identification of data validation routines, teachable taint analysis. &lt;br /&gt;
* Authentification and access control analysis: identification of code related to access control and it’s analysis.&lt;br /&gt;
* Pattern-based code analysis.&lt;br /&gt;
* Teachability: analyst indicates security-related code (sources of tainted data, sensitive sinks, input validation and sanitizing functions, access control code, etc.) and workbench automatically recomputes possible vulnerabilities list. The second idea is to spread knowledge gathered from analyst to other web applications.&lt;br /&gt;
&lt;br /&gt;
Project budget: $10K (note: this project combines two OWAPS Project Proposals)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Future development:'''&lt;br /&gt;
&lt;br /&gt;
Further, workbench can be extended to support various Java web application frameworks and to support Python web applications (it seems to us that teachable tool is much more valuable for Python and other languages where the notion of web application is not so formal as in J2EE).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Background: '''&lt;br /&gt;
&lt;br /&gt;
Dmitry Kozlov is a postdoc researcher at Moscow State &lt;br /&gt;
University. Since 2003 he leads a group performing research in the area of web &lt;br /&gt;
application security. In 2007 this group took part in OWASP Spring of &lt;br /&gt;
Code on project &amp;quot;Python Dynamic Analysis&amp;quot;. This project was implemented &lt;br /&gt;
mostly by Dmitry’s PhD student Andrew Petukhov. Also in 2007 this group created static analysis tool for Python language, based on Pixy PHP analyser (publication is upcoming).&lt;br /&gt;
&lt;br /&gt;
Igor Konnov is PhD student at Moscow State University he has strong background in program analysis and verification.&lt;br /&gt;
&lt;br /&gt;
== OpenPGP Extensions for HTTP - Enigform and mod_openpgp ==&lt;br /&gt;
By Arturo 'Buanzo' Busleiman&lt;br /&gt;
&lt;br /&gt;
=== Introduction to the project ===&lt;br /&gt;
My name is Arturo Busleiman, a.k.a Buanzo. Last year I worked with OWASP to take Enigform (The OpenPGP Firefox Extension) and mod_openpgp (The Apache counterpart) to an usable level. This year, I want to focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP.&lt;br /&gt;
&lt;br /&gt;
For that to happen, OWASP support is essential. I'm very happy to submit my application for Summer of Code 2008.&lt;br /&gt;
&lt;br /&gt;
=== About Buanzo ===&lt;br /&gt;
&lt;br /&gt;
I am a 26 year old Independent security consultant from Buenos Aires, Argentina, that has contributed to the world of information systems security since 1994. Linux and Security are my life.&lt;br /&gt;
&lt;br /&gt;
A quick search for buanzo on google [http://www.google.com/search?hl=en&amp;amp;q=buanzo&amp;amp;btnG=Google+Search] will provide all necessary details about my professional and community background. For comprobable experience, you could also check my Rent a Coder profile.[http://www.rentacoder.com/RentACoder/SoftwareCoders/showBioInfo.asp?lngAuthorId=735204] or my &amp;quot;Customer Comments&amp;quot; page at [http://www.buanzo.com.ar/pro/].&lt;br /&gt;
&lt;br /&gt;
I've contributed scripts, fixes and translations to the Nmap project. I've also acted as Expert Contributor for SANS TOP-20 2004, 2005, 2006 and 2007. I've developed &lt;br /&gt;
tools and written documentation that can be found in Freshmeat, mozdev.org and addons.mozilla.org. Also I've written&lt;br /&gt;
the Unix chapter of the OISSG's Information Systems Security Assessment Framework, v1.0 [http://www.oissg.org/content/view/71/71/].&lt;br /&gt;
&lt;br /&gt;
In my free time, I &amp;quot;run&amp;quot; the 2600 Argentina meetings, write articles, give talks and play the guitar.&lt;br /&gt;
&lt;br /&gt;
I'm an active member of the FLOSS community since 1996, having written articles in magazines http://www.net-security.org/dl/articles/Detecting_and_Understanding_rootkits.txt, made TV, radio and newspaper appearances [http://codigoabierto.bitacoras.com/archivos/2005/04/01/buanzo-hacks] and led different security research groups of Spain, Mexico and Argentina. Currently I contribute time thorugh my sites, forums and blogs, answering questions in mailing lists and helping coordinate some local LUGs. I do also manager the Linux Counter for Argentina [http://counter.li.org/reports/place.php?place=AR].&lt;br /&gt;
&lt;br /&gt;
=== About Enigform ===&lt;br /&gt;
&lt;br /&gt;
The project has draw attention from the IETF OpenPGP Working Group, and even Vinton Cerf (The Father of the Internet) said that Enigform and mod_openpgp &amp;quot;[this] strikes me as a really interesting idea and I hope you (Buanzo) will pursue it with the W3C.&amp;quot; (February 18, 2008). [http://en.wikipedia.org/wiki/Enigform]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP AntiSamy .NET ==&lt;br /&gt;
* Arshan Dabirsiaghi&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
The OWASP AntiSamy Project was well received at the OWASP/WASC San Jose 2007 conference, and the momentum carried forward as the project was noted in several popular blogs and had its various distributions downloaded in aggregate thousands of times.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
All the platforms, not just Java, need this functionality. The Zend group is currently working on getting a PHP version started, so naturally the only platform remaining for major sites is .NET. Therefore, I propose that OWASP sponsor me in creating a .NET version of the OWASP AntiSamy Project.    It should also be noted that the OWASP ESAPI .NET project requires this API to be created.&lt;br /&gt;
&lt;br /&gt;
'''Background'''&amp;lt;br&amp;gt;&lt;br /&gt;
I'm currently a Senior Application Security Engineer at Aspect Security, an industry leading application security company. I've delivered tutorials all over the country at various commercial organizations and conferences like OWASP and Blackhat.&lt;br /&gt;
&lt;br /&gt;
'''Proposed Project Reviewer: Jeff Williams/Dinis Cruz'''&amp;lt;br&amp;gt;&lt;br /&gt;
Jeff Williams will be the easiest reviewer due to proximity, but Dinis Cruz's or another OWASP .NET project member's knowledge of .NET may prove useful to the project.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables''' &amp;lt;br&amp;gt;&lt;br /&gt;
The aim of the project would be to deliver a functionally identical version of the AntiSamy project in .NET. Secondarily, we would hope to deliver a Release quality product by the end of the Summer of Code timeframe in line with the Java version.&lt;br /&gt;
&lt;br /&gt;
== Online code signing and integrity verification service for open source community (OpenSign Server) ==&lt;br /&gt;
&lt;br /&gt;
by ''Phil Potisk'' and ''Richard Conway''&lt;br /&gt;
&lt;br /&gt;
It is the opinion of this pair that there is a decided lack of code signing and integrity checking support for the open source community. The purpose of this project would be to build and host a feature-rich server and suite of client utilities with adequate secure hardware to ensure the integrity of code modules.&lt;br /&gt;
&lt;br /&gt;
'''Summary'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The service will allow all .NET and Java code modules to be uploaded to the service to be signed by a community code signing key. Each community (such as OWASP) will have a key and corresponding Software Publishing Certificate (SPC) which can optionally be embedded in the code module itself. Generally, however, the service is intended for developers and the wider community of concerned users that want to ensure that their downloaded portable executable is exactly what it purports to be. The root key will be stored in an HSM and will sign an SPC from a locally generated key-pair of which the public key will be sent to the service. Key pair generation can be made and submitted using standard .NET delay signing and jar signing tools distributed with the SDKs, however, the project remit will ensure that a client-side graphical tool for each environment is available to generate the keys pairs needed to sign code with and allow submission to the code signing service for signing and generation of SPC by the server's proprietary CA. Anonymity will not be allowed so the project will include a database of users which will be the basis of directory for SPCs. &lt;br /&gt;
&lt;br /&gt;
There will be a web and web services interface using an online login and WS-Security respectively which will allow the code to be uploaded on demand and signed by a code signing key with the option to embed the certificate or not. &lt;br /&gt;
&lt;br /&gt;
'''Problem domain'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
- Current download of portable executables inherently insecure with only a CRC/MD5 check &amp;lt;br/&amp;gt;&lt;br /&gt;
- No open source standard for code signing and delivery of portable executables between developers to test for tamper evidence &amp;lt;br/&amp;gt;&lt;br /&gt;
- No managed service for code signing outside of verisign or other paid for X509 signing service &amp;lt;br/&amp;gt;&lt;br /&gt;
- Process currently very mechanical with use of command line tools or PKCS#10 software requests which should be abstracted from developer &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Ideal Solution''' &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
- Ensure third party verification of code modules through a dedicated PKI backbone &amp;lt;br/&amp;gt;&lt;br /&gt;
- Educate the OWASP and wider open source community in the use of code signing &amp;lt;br/&amp;gt;&lt;br /&gt;
- Replace standard CRC/MD5 hash usage with some more secure that can be repudiated if challenged &lt;br /&gt;
- Use an internet infrastructure to allow the dissemination of certificates (potentially multipurpose in later versions) &amp;lt;br/&amp;gt;&lt;br /&gt;
- Ensure accountability through actions logging and authentication &amp;lt;br/&amp;gt;&lt;br /&gt;
- Standardise a set of open source client tools for the creation of keys and manipulation of certificates &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Graphical Interfaces'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
- Client tool to generate RSA key pair and request signing certificate by return via a secure connection, secure connection will authenticate user after a dedicated registration process and also use mutual authentication SSL to avoid man-in-the-middle - returning certificate to user in real time. Registered developer can then submit their SPC online to verify the SPC. &amp;lt;br/&amp;gt;&lt;br /&gt;
- Client tool to download software that will do a proper verification on the software against the code signing service &amp;lt;br/&amp;gt;&lt;br /&gt;
- Website interface for the code signing service &amp;lt;br/&amp;gt;&lt;br /&gt;
- Set of Admin tools to manage the code signing service, user and certificate repository &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Added advantage''' &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Environment can be secured and tested regularly by members of Owasp to ensure the security of the server and infrastructure haven't been hijacked! The project will only be as secure the server environment!&lt;br /&gt;
&lt;br /&gt;
'''Breakdown of tasks'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
- Server setup and installation of OpenLDAP &amp;lt;br/&amp;gt;&lt;br /&gt;
- Installation of Mock HSM (eAladdin token) &amp;lt;br/&amp;gt;&lt;br /&gt;
- Creation of PKCS#11 for key management and key creation activities &amp;lt;br/&amp;gt;&lt;br /&gt;
- Installation of Java/.NET SDKs &amp;lt;br/&amp;gt;&lt;br /&gt;
- Development of codebase for signing using SDK tools (later versions will reverse engineer this into jar/assemblies directly) &amp;lt;br/&amp;gt;&lt;br /&gt;
- Library for creating SPC (CA) &amp;lt;br/&amp;gt;&lt;br /&gt;
- User registration, authentication, activity logging, database support &amp;lt;br/&amp;gt;&lt;br /&gt;
- OpenLDAP user/certificate repository, access using mutual-authentication SSL &amp;lt;br/&amp;gt;&lt;br /&gt;
- Development of client tool suite &amp;lt;br/&amp;gt;&lt;br /&gt;
- Development of administrator tools &amp;lt;br/&amp;gt;&lt;br /&gt;
- Procurement of FIPs compliant HSM and installation &amp;lt;br/&amp;gt;&lt;br /&gt;
- Administrator/user manuals &amp;lt;br/&amp;gt;&lt;br /&gt;
- Pen testing of solution by OWASP members &amp;lt;br/&amp;gt;&lt;br /&gt;
- Go live! &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Post July completion tasks''' &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
- Support for Microsoft office documents with macros and others&amp;lt;br/&amp;gt;&lt;br /&gt;
- Full support for community management (i.e. OWASP differentiated from other developer communities)&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Background and Experience of project team''' &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Richard Conway has 13 years commercial development experience in messaging and financial/investment banking systems having managed teams to deliver complex Agile solutions. He has degrees and PGDip in computer science and another in physics (finishing 2009) and has taught at Westminster university and written 7 books 3 of which are on security related topics (and numerous articles). &lt;br /&gt;
&lt;br /&gt;
Phil Potisk has an academic background from Graz university, degree and masters and is currently looking at doing a pHD in the UK all on computer science/information security. He has several years commercial experience all in the security space for major companies in Austria and the UK.&lt;br /&gt;
&lt;br /&gt;
Both Richard and Phil have worked together for 4 years in the space of ePassports/smart cards where they have an impact on ICAO standards and have fulfilled consultancy and product development in the area of passport inspection, cryptography, ePassport/smart card protocols testing and more. They have a wealth of knowledge and experience in PKI and development of applications using secure hardware and cryptography.&lt;br /&gt;
&lt;br /&gt;
== Lockpick ==&lt;br /&gt;
*Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Summary'''&lt;br /&gt;
&lt;br /&gt;
Lockpick is an open source penetration testing project management tool.  There are plenty of tools that do specific functions, or a range of technical functions (NMAP, Nessus).  However, there are not many open source tools to help manage the scope of the testing a system.  Lockpick will fill that role.  When I start a penetration test, Lockpick will provide my checklists and script resources and update my tools.  For intelligence gathering, Lockpick will let me create profiles for target companies and persons.  I can shell out to my normal tool suite and organize my log files and other output with the tool.  Eventually, I can use Lockpick to pull all of the testing data together and generate an executive summary and detail report with the logs and profiles for addenda.&lt;br /&gt;
&lt;br /&gt;
'''Project Roadmap'''&lt;br /&gt;
&lt;br /&gt;
April 2, 2008 - April 30, 2008 (Sprint 1)&lt;br /&gt;
*Architecture, technical design (use cases, db design) and UI design&lt;br /&gt;
&lt;br /&gt;
May 1, 2008 - May 31, 2008 (Sprint 2)&lt;br /&gt;
*Project framework (modular design - use an dependency injection (IoC) architecture, so we can rip and replace components)&lt;br /&gt;
*GUI framework&lt;br /&gt;
*GUI for pen-test overview (use NIST or OSSTMM for process milestones)&lt;br /&gt;
&lt;br /&gt;
June 1, 2008 - June 30, 2008 (Sprint 3)&lt;br /&gt;
*Competitive intelligence feature (Company and individual profile builder)&lt;br /&gt;
&lt;br /&gt;
July 1, 2008 - July 31, 2008 (Sprint 4)&lt;br /&gt;
*Checklist and scripting repository feature (with rss synchronization feed)&lt;br /&gt;
(Unit Tests, Code, and QA)&lt;br /&gt;
&lt;br /&gt;
July 15, 2008&lt;br /&gt;
Project Status Report&lt;br /&gt;
&lt;br /&gt;
August 1, 2008 - August 31, 2008 (Sprint 5)&lt;br /&gt;
*3rd Party tool integration (shell out and log management)&lt;br /&gt;
&lt;br /&gt;
'''Project Wishlist'''&lt;br /&gt;
&lt;br /&gt;
*Report generator (integrated with open office, google docs)&lt;br /&gt;
*OVAL (Open Vulnerability and Assessment Language) database reader&lt;br /&gt;
*Testing log GUI&lt;br /&gt;
&lt;br /&gt;
'''Project Team'''&lt;br /&gt;
&lt;br /&gt;
Mark Roxberry, CISSP, CEH, MCP - independent software vendor.  I've been writing code since infancy.  It would be great to have OWASP sponsor the project and give me the opportunity to create something that other testers can use.&lt;br /&gt;
&lt;br /&gt;
== OWASP Live CD 2008 Project ==&lt;br /&gt;
&lt;br /&gt;
* Matt Tesauro&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The previous OWASP Live CD project distributions have laid a good foundation for the 2008 Project.  I'd like to take the existing Live CD and further enhance it.  I see the 2008 Live CD as filling the Web App Sec niche not the more general  Pen Tester niche.  I'd concede general Pen Testing to Backtrack [http://www.remote-exploit.org/backtrack.html].  However, Backtrack has a different audience and is not specifically tailored for web application security professionals.  This is the role I think this Live CD could fulfill with great success.  I'd like to take the OWASP Live CD 2008 Project in that direction and see the OWASP Live CD become to Web App Sec what Backtrack is to Pen Testing.&lt;br /&gt;
&lt;br /&gt;
'''Proposal'''&lt;br /&gt;
&lt;br /&gt;
I'd like to take the existing applications and documentation in the current Live CD and add significantly more tools and documentation specifically focused on Web application security.  I think OWASP's Phoenix/Tools page [http://www.owasp.org/index.php/Phoenix/Tools] would be a good starting point for potential tools.  I'd also like to use WASC [http://www.webappsec.org/] and ISECOM/OSSTMM [http://www.isecom.org/] as sources for material.  &lt;br /&gt;
&lt;br /&gt;
The project would first enumerate a list of tools to include on the CD where licensing, supported OS and space will determine what is included on the Live CD.  After determining a reasonable list of tools, the next phase would be to create modules for the tools and merge these modules with the Live CD.  Then documentation and tutorials would be added (also as space allows) followed by any remaining OWASP branding.  Additional polishing could include pre-installation (license permitting) of the VMware tools.&lt;br /&gt;
&lt;br /&gt;
'''Deliverables'''&lt;br /&gt;
&lt;br /&gt;
April 2 to May 15, 2008&lt;br /&gt;
* Enumerated tools and reference material for installation verifying that the software license allows permits distribution.&lt;br /&gt;
&lt;br /&gt;
May 16 to July 4, 2008&lt;br /&gt;
* Create modules for each tool and begin to merge the modules with the base distribution.&lt;br /&gt;
* Begin testing of the Live CD.&lt;br /&gt;
&lt;br /&gt;
July 5 to August 31, 2008&lt;br /&gt;
* Complete the merging of modules and install any remaining documentation.&lt;br /&gt;
* Further testing of the Live CD particularly installation of new/updated modules.&lt;br /&gt;
&lt;br /&gt;
'''Challenges / Outstanding Issues'''&lt;br /&gt;
&lt;br /&gt;
While the current Live CD is base on Morphix – a Knoppix derivative created to allow easy creation of custom Live CDs, I'm not sure it it provides the flexibility needed to keep the CD tools updated.  While I'm fine with keeping the Live CD on Morphix, I also see value in switching to another distribution:  SLAX.  Here's the brief pros and cons of each as I see them.&lt;br /&gt;
&lt;br /&gt;
Pros of Mophix:  &lt;br /&gt;
* no change to current LiveCD - principally just updates to existing and augment.   &lt;br /&gt;
* Modular Live CD&lt;br /&gt;
* Based on Knoppix which is the granddaddy of live CDs (tons of documentation)&lt;br /&gt;
&lt;br /&gt;
Cons of Morphix:  &lt;br /&gt;
* While modular, uses a modular structure which isn't compatible with other well established live CDs - particularly Backtrack&lt;br /&gt;
* Modules are not as granular as SLAX (lower ease of updating)&lt;br /&gt;
&lt;br /&gt;
Pros of SLAX:  &lt;br /&gt;
* Modular Live CD (more modular then Morphix though I'm more familiar with SLAX then Morphix from using/modifying Backtrack)&lt;br /&gt;
* Same modular format as Backtrack and other SLAX variants.  This allows module sharing between OWASP and other live CDs&lt;br /&gt;
* As tools are updated, only the module for that tools would need to be updated - not the entire live CD.&lt;br /&gt;
&lt;br /&gt;
Con of SLAX:&lt;br /&gt;
* Would have to re-do the work done for the current Live CD&lt;br /&gt;
&lt;br /&gt;
As said above, I'm not sold on either distro but I do think going forward, the more granular modules of SLAX will allow for easier updates of the included tools and documentation.  Backtrack is a good example of this.  I think the migration would represent a short term loss for a long term gain.&lt;br /&gt;
&lt;br /&gt;
'''A bit about me'''&lt;br /&gt;
&lt;br /&gt;
I've been using Linux since somewhere around 1996 when I got my first “Mega Distro pack” which included 6+ distro CDs, a bumper sticker and a t-shirt for $29.95.  I think it was in the RedHat 5.2 time frame.  I've had Linux as my primary OS since 2000 and have used many, many different distros.  Also, I am a RHCE (#803005588313799) as well as Linux+ certified so I believe I'm qualified the Linux aspects of the project.  &lt;br /&gt;
&lt;br /&gt;
I got started with creating static HTML pages in 1999 and my first job out of college was a Web application developer for an international telecom company in 2000.  Later, I took a developer job at Texas A&amp;amp;M University and also taught Web application development courses at the undergraduate and graduate level.  Next, I spent some time as a Pen Tester where I discovered WHAX, Auditor and Backtrack live CDs and realized how useful they can be.  Currently, I work on Web Application Security for an agency with ~75 internally developed web apps and 500,000+ users.  I'm involved in application development from preliminary design reviews to pre-production security testing.  I also have a CISSP (Cert # 67636) and CEH (Certified Ethical Hacker) security certifications.  I've been enjoying OWASP since I first discovered Web Goat (then at version 3.7) and thought it was high time I gave something back to OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Education Project  ==&lt;br /&gt;
&lt;br /&gt;
*Martin Knobloch&lt;br /&gt;
'''OWASP Education Project / OWASP Boot Camp'''&lt;br /&gt;
&lt;br /&gt;
The project will continuously deliver education material about OWASP tooling and documentation. This aims to create an easy entrance towards understanding application security and usage of the OWASP tooling. By creating education documentation papers, screen scrape video courses and setting up an OWASP Boot camp, a controlled education process of a standardized quality can be created continuously. With the setup of a OWASP Boot camp, the OWASP word can be spread in a controlled manner and deliver high quality training., both inside and outside of the OWASP community. The OWASP Education Project will setup and standardize OWASP trainings manuals and materials to ensure a certain level of quality of the trainings. Trainings about the OWASP tooling and projects will have to be reviewed by the Projects.&lt;br /&gt;
&lt;br /&gt;
'''Complexity - What is the project Complexity and Size? '''&lt;br /&gt;
&lt;br /&gt;
Deliverables to focus on are, in first place, to set up an OWASP Boot camp. For this the project will create a training and video (screen scrape) training material about Application Security basics, using the OWASP WebGoat and OWASP WebScarab tooling on the OWASP Top Ten vulnerabilities. Next, creating training material on the main OWASP Project's as the OWASP Guide and OWASP Testing Guide.&lt;br /&gt;
&lt;br /&gt;
'''Member Value - How big is the potential added value to OWASP Members? '''&lt;br /&gt;
&lt;br /&gt;
The OWASP Education project ensures a common shared set of knowledge about application security in general and the OWASP tooling in detail. The OWASP Boot camp helps new OWASP members to get on track fast and on a guaranteed quality level.&lt;br /&gt;
&lt;br /&gt;
'''Brand Value - How big is the potential added value to the OWASP Brand? '''&lt;br /&gt;
&lt;br /&gt;
The OWASP Education projects Boot camp deliverable can help to spread the OWASP word beyond the OWASP community. Holding OWASP Boot camps can generate additional venue. The OWASP Education project will extend the knowledge about the OWASP tooling and the usage of those. In the current discussion of the OWASP certification, the OWASP Education project can support and certify training. The OWASP certification can be supported by special OWASP Certification Boot camps.&lt;br /&gt;
&lt;br /&gt;
'''On the Candidate: '''&lt;br /&gt;
&lt;br /&gt;
Past Work - Value of past contributions to OWASP Projects; previously, as OWASP On The Move project lead, I was involved in setting up the OWASP On The Move rules. I am involved in the Dutch local chapter inside the chapter board, focusing on the content, speakers and feedback of the local chapter meeting. On the AppSec Australia conference I was speaker on the subject on what to consider when implementing a Secure Development Process. On my daily job, being Software Architect at Sogeti Nederland B.V., I have set up a Secure Development Taskforce. I have succeeded to make Sogeti Nederland B.V. and member of the OWASP community. Sogeti sponsored previous local Dutch chapter meetings and my trip to Australia. The deliverables of the Sogeti Secure Development Taskforce (PaSS, Proactive Security Strategy) are given to the OWASP community, as we will continue to do in the future.&lt;br /&gt;
&lt;br /&gt;
== Fortify Code Review Project ==&lt;br /&gt;
&lt;br /&gt;
'''Your educational and professional background: '''&lt;br /&gt;
&lt;br /&gt;
I have worked in IT for over 8 years now with 5 years Information Security experience. I have obtained and taught many IT certifications in my career so far.&lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments: '''&lt;br /&gt;
&lt;br /&gt;
Work experience as an Information Security Analyst implementing application security in a highly sensitive environment. I'm currently contributing to an OWASP project (Code Review guide) and spoken on the subject of Application Security at a developers conference.&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities: '''&lt;br /&gt;
&lt;br /&gt;
As mentioned above I'm currently contributing to one other OWASP project.&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses: '''&lt;br /&gt;
&lt;br /&gt;
My proposal is to help Fortify and OWASP achieve the goals set out in the objectives for this project. The project has the ability to deliver a clear guide on static analysis and subsequently how to add this into the SDLC. The auditing of open source software can help to enhance the security of this software and possibly improve its ability to increase its user base. &lt;br /&gt;
&lt;br /&gt;
'''Milestones and objectives: '''&lt;br /&gt;
&lt;br /&gt;
Process all OWASP Java developments through the Fortify scanner&lt;br /&gt;
Review the output of the Fortify scans on the OWASP projects that have been submitted&lt;br /&gt;
Produce the first draft of the three documents that need to be delivered&lt;br /&gt;
Liaise with OWASP/major Java Open Source project contacts to involve them in reviewing the output of Fortify scans of their developments&lt;br /&gt;
Provide final documentation&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities: '''&lt;br /&gt;
&lt;br /&gt;
I will carry out all the activities for this project myself.&lt;br /&gt;
&lt;br /&gt;
Research current methods of static analysis in the application security arena and combine this with my own knowledge. This research will allow me to define a workflow which illustrates how static analysis will be integrated into the SDLC.&lt;br /&gt;
&lt;br /&gt;
Identify which OWASP applications have been submitted for analysis and identify which other projects can be scanned. I will contact the relevant project leads to get them to submit the projects for review.&lt;br /&gt;
&lt;br /&gt;
Review the results of the scans and analyse any issues found. I will provide feedback on any issues found to the relevant project lead. &lt;br /&gt;
&lt;br /&gt;
Identify major Open Source Java projects and liaise with these projects to involve them in scans of their code. We will provide feedback on the results and ensure that future code revisions are also scanned by the Fortify system.&lt;br /&gt;
&lt;br /&gt;
Provide revised guides based on feedback from the draft documents and the use of the Fortify system.&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress: '''&lt;br /&gt;
&lt;br /&gt;
The deliverables for this project would see me firstly provide draft guides once I have used the Fortify system to review any recently scanned OWASP projects. &lt;br /&gt;
&lt;br /&gt;
I would also seek to involve major java Open Source projects in the Fortify project which will help the Fortify Scanner become part of many Open Source developments.&lt;br /&gt;
&lt;br /&gt;
Providing report documents to the relevant OWASP project leads which would explain any issues found in the Fortify scan of their code&lt;br /&gt;
&lt;br /&gt;
Deliver the final guides for review&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project: '''&lt;br /&gt;
&lt;br /&gt;
I would see this project firstly serving as a focal point for anyone wishing to implement Static Analysis into their own SDLC. Secondly I see this project as a launching pad for the Fortify scanner to increase its use by Open Source projects. &lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected: '''&lt;br /&gt;
&lt;br /&gt;
I'm very passionate about Application Security and I want to use this passion to help the Application Security community. I think the project should be selected so that the  objectives of both the OWASP and Fortify can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Source Code Review OWASP Projects ==&lt;br /&gt;
* James Walden&lt;br /&gt;
&lt;br /&gt;
'''Educational and professional background: '''&lt;br /&gt;
&lt;br /&gt;
I am an assistant professor of computer science at Northern Kentucky University, and I previously worked as a visiting assistant professor at the University of Toledo.  Before entering academia, I worked for Intel as a software engineer for five years.  I hold a Ph.D. in theoretical physics from Carnegie Mellon University.&lt;br /&gt;
&lt;br /&gt;
'''Application Security experience: '''&lt;br /&gt;
&lt;br /&gt;
My primary area of interest in research and teaching is application security.  I have worked with application security issues since 1993 when I was developing secure CGI scripts in perl at CMU, and much of my work at Intel involved application security.  I have used Fortify's Source Code Analysis tool in my teaching and research since 2005, and I served as a technical reviewer for the book ''Secure Programming with Static Analysis'' by Brian Chess and Jakob West.&lt;br /&gt;
&lt;br /&gt;
I have developed workshops on secure programming, software security, and web application security, including both slides and demonstration web applications, which I have taught to computer science faculty at conferences since 2005 and to software developers through my university since 2006.  I have given many talks on application security during the last three years to local professional groups like IEEE, ISACA, and ISSA and at conferences such as the Ohio Information Security Conference and Recent Advances in Information Assurance, Network and Software Security 2007.&lt;br /&gt;
&lt;br /&gt;
'''Open Communities: '''&lt;br /&gt;
&lt;br /&gt;
I have contributed to the OWASP Guide and OWASP Code Review Guide, and I participate in the OWASP Cincinnati chapter.  I have also submitted a number of small patches to fix bugs in open source projects over the years.&lt;br /&gt;
&lt;br /&gt;
'''Opportunity and Challenges'''&lt;br /&gt;
&lt;br /&gt;
There will be other contributors to this project, including one professor and  several students.  Dr. Maureen Doyle will work with one student to develop and document the workflow to incorporate Fortify Java Open Source static analysis into the SDLC.  Anticipated issues include detecting false positives that result from the analysis and reporting the security errors to the appropriate developers for future correction (e.g., through Bugzilla or similar system).  It is uncertain how much of the workflow can be automated.  The workflow documentation will require that static analysis be a part of the SDLC.  &lt;br /&gt;
&lt;br /&gt;
Dr. Doyle has twenty years of industry experience working with various development lifecycles and has implemented software processes at General Electric and Alphatech, Inc.  Dr. Doyle keeps current on software development paradigms as part of her course preparation for graduate and undergraduate software engineering courses. Dr. James Walden, whose background is described above, will lead the auditing task and collaborate on the workflow development.  &lt;br /&gt;
&lt;br /&gt;
'''Milestones and Objectives'''&lt;br /&gt;
&lt;br /&gt;
The objectives of this project are:&lt;br /&gt;
* Develop and document a workflow for open source projects to incorporate static analysis into the Software Development Life Cycle (SDLC).&lt;br /&gt;
* Apply the above workflow as a required step for OWASP projects.&lt;br /&gt;
* Aid in auditing select open source projects to create a baseline for comparing security amongst open source projects. &lt;br /&gt;
&lt;br /&gt;
The milestones for this project are:&lt;br /&gt;
* '''Three projects''' selected for initial analysis by May 1.&lt;br /&gt;
* '''Project 1''' submitted to Fortify Java Open Review Project by June 1&lt;br /&gt;
* '''Workflow''' sent out for review by June 1&lt;br /&gt;
* '''Projects 2 and 3''' submitted to Fortify Java Open Review Project by July 1&lt;br /&gt;
* '''Additional projects''' identified for analysis with the revised workflow by July 1.&lt;br /&gt;
* '''Workflow''' available at OWASP by August 15&lt;br /&gt;
* '''Additional projects''' submitted to Fortify Java Open Review by August 15&lt;br /&gt;
&lt;br /&gt;
'''Project Schedule'''&lt;br /&gt;
&lt;br /&gt;
* May 1, 2008: Team finalized, three projects selected for initial analysis.&lt;br /&gt;
* June 1, 2008: Team of workflow reviewers finalized, preliminary workflow sent out for review, project 1 analysis complete using initial workflow.&lt;br /&gt;
* July 1, 2008: Project 2 and 3 analysis completed, workflow finalized, additional projects selected for creating baseline.&lt;br /&gt;
* August 15, 2008: Analysis of projects for baseline security measures complete, workflow documented on OWASP web site.&lt;br /&gt;
&lt;br /&gt;
'''Long Term Vision'''&lt;br /&gt;
&lt;br /&gt;
We would like to analyze the classes of security bugs found through static analysis to determine if patterns exist, so that we could develop measures to prevent the introduction of such bugs into projects.  We would also like to implement a security metrics collection process for projects, recording data on static analysis usage, number of security bugs, lifetime of security bugs, and so forth.&lt;br /&gt;
&lt;br /&gt;
'''Supporting Information'''&lt;br /&gt;
&lt;br /&gt;
Dr. Walden and Dr. Doyle bring a combination of industrial and academic experience to this task.  They both regularly mentor undergraduate students working on research projects, and they have already recruited students to work on a project using static analysis tools.  The funds offered by OWASP will be used solely to fund our undergraduate students.&lt;/div&gt;</summary>
		<author><name>Walden</name></author>	</entry>

	</feed>