This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Summit 2011 Working Sessions/Session043
From OWASP
Global Summit 2011 Home Page
Global Summit 2011 Tracks
WAF Mitigations for XSS | ||||||
---|---|---|---|---|---|---|
Please see/use the 'discussion' page for more details about this Working Session | ||||||
Working Sessions Operational Rules - Please see here the general frame of rules. |
WORKING SESSION IDENTIFICATION | ||||||
---|---|---|---|---|---|---|
Short Work Session Description | To discuss if/when/how web application firewalls can help to prevent XSS attacks | |||||
Related Projects (if any) |
| |||||
Email Contacts & Roles | Chair Ryan Barnett @ |
Operational Manager |
Mailing list Subscription Page |
WORKING SESSION SPECIFICS | ||||||
---|---|---|---|---|---|---|
Objectives |
| |||||
Venue/Date&Time/Model | Venue/Room OWASP Global Summit Portugal 2011 |
Date & Time
|
Discussion Model participants and attendees |
|
---|
WORKING SESSION OPERATIONAL RESOURCES | ||||||
---|---|---|---|---|---|---|
Projector, whiteboards, markers, Internet connectivity, power |
|
---|
WORKING SESSION ADDITIONAL DETAILS | ||||||
---|---|---|---|---|---|---|
WORKING SESSION OUTCOMES / DELIVERABLES | ||
---|---|---|
Proposed by Working Group | Approved by OWASP Board | |
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. |
Working Session Participants
(Add you name by clicking "edit" on the tab on the upper left side of this page)
WORKING SESSION PARTICIPANTS | ||||||
---|---|---|---|---|---|---|
Name | Company | Notes & reason for participating, issues to be discussed/addressed | ||||
Lucas C. Ferreira @ |
|
| ||||
Achim Hoffmann @ |
sic[!]sec |
| ||||
Justin Clarke @ |
Gotham Digital Science |
How can we package, and/or make this easier for noobs to deploy? | ||||
Giorgio Fedon |
| |||||
Abraham Kang |
| |||||
Mario Heiderich |
Ruhr University Bochum / NDS |
Filter Evasions | ||||
Gareth Heyes |
Businessinfo |
| ||||
Eduardo Vela @ |
Google |
ACS etc.. | ||||
Stefano Di Paola |
Minded Security |
| ||||
David Lindsay |
Cigital Inc |
Filter Evasions | ||||
Juan Jose Rider @ |
WUL4 |
What about merging ESAPI capabilities in a WAF? | ||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
|