<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=FLOSSHack_for_Software_Maintainers</id>
		<title>FLOSSHack for Software Maintainers - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=FLOSSHack_for_Software_Maintainers"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=FLOSSHack_for_Software_Maintainers&amp;action=history"/>
		<updated>2026-04-30T08:39:24Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=FLOSSHack_for_Software_Maintainers&amp;diff=139028&amp;oldid=prev</id>
		<title>TimMorgan at 21:14, 7 November 2012</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=FLOSSHack_for_Software_Maintainers&amp;diff=139028&amp;oldid=prev"/>
				<updated>2012-11-07T21:14:44Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 21:14, 7 November 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l13&quot; &gt;Line 13:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 13:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;## Their opinion on the best version of software to test against (latest release version vs. source code repository version, etc)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;## Their opinion on the best version of software to test against (latest release version vs. source code repository version, etc)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;## Instructions on the typical deployment/installation configuration (or better yet, provide organizers with a pre-installed virtual machine!)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;## Instructions on the typical deployment/installation configuration (or better yet, provide organizers with a pre-installed virtual machine!)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;## An overview of the &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;applications &lt;/del&gt;authorization model: what roles exist and ''who'' should be allowed to do ''what''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;## An overview of the &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;application's &lt;/ins&gt;authorization model: what roles exist and ''who'' should be allowed to do ''what''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;## Any information on what attack scenarios are most likely against the software&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;## Any information on what attack scenarios are most likely against the software&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# FLOSSHack organizers schedule the workshop event, publish details&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# FLOSSHack organizers schedule the workshop event, publish details&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>TimMorgan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=FLOSSHack_for_Software_Maintainers&amp;diff=131507&amp;oldid=prev</id>
		<title>TimMorgan: Created page with &quot;== FLOSSHack for Software Maintainers ==  If your software project been selected for a FLOSSHack event, then '''congratulations'''!  This means that we're interested in br...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=FLOSSHack_for_Software_Maintainers&amp;diff=131507&amp;oldid=prev"/>
				<updated>2012-06-16T16:41:29Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;== FLOSSHack for Software Maintainers ==  If your software project been selected for a &lt;a href=&quot;/index.php/FLOSSHack&quot; title=&quot;FLOSSHack&quot;&gt;FLOSSHack&lt;/a&gt; event, then &amp;#039;&amp;#039;&amp;#039;congratulations&amp;#039;&amp;#039;&amp;#039;!  This means that we&amp;#039;re interested in br...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== FLOSSHack for Software Maintainers ==&lt;br /&gt;
&lt;br /&gt;
If your software project been selected for a [[FLOSSHack]] event, then '''congratulations'''!  This means that we're interested in breaking your code, in a good way.  &lt;br /&gt;
&lt;br /&gt;
FLOSSHack events are designed to accomplish two primary goals:&lt;br /&gt;
* Help those who want to learn more about security auditing of software&lt;br /&gt;
* Improve the security posture of a worthy software project (like yours) at low or no cost&lt;br /&gt;
&lt;br /&gt;
For the event to be the most successful, we encourage close collaboration with software maintainers.  While we could operate completely autonomously (relying solely on software and documentation that software maintainers have already published), we think an ''ideal'' FLOSSHack event would go something like this:&lt;br /&gt;
&lt;br /&gt;
# FLOSSHack &amp;quot;target&amp;quot; software selected&lt;br /&gt;
# Software maintainers contacted and provide FLOSSHack organizers with:&lt;br /&gt;
## Their opinion on the best version of software to test against (latest release version vs. source code repository version, etc)&lt;br /&gt;
## Instructions on the typical deployment/installation configuration (or better yet, provide organizers with a pre-installed virtual machine!)&lt;br /&gt;
## An overview of the applications authorization model: what roles exist and ''who'' should be allowed to do ''what''&lt;br /&gt;
## Any information on what attack scenarios are most likely against the software&lt;br /&gt;
# FLOSSHack organizers schedule the workshop event, publish details&lt;br /&gt;
# About one week before the workshop date, participants begin auditing the software based on details provided by maintainers&lt;br /&gt;
# On the day of the workshop:&lt;br /&gt;
## Participants gather face-to-face and remotely for an intensive hack session&lt;br /&gt;
## Friendly competition on who can find the &amp;quot;most&amp;quot; or &amp;quot;best&amp;quot; bugs is encouraged&lt;br /&gt;
## Software maintainers are encouraged to send a representative or join remotely.  This can be very helpful for participants as questions about the software's intended use cases arise.&lt;br /&gt;
## At the end of the hack session, awards may be given to the most successful participants, based on number or types of vulnerabilities found.  (Software maintainers are welcome to provide small prizes to be given away as awards.  Small incentives can go a long way!)&lt;br /&gt;
# FLOSSHack organizers gather up all of the vulnerabilities and other security-related flaws found by participants and are provided to the software maintainer through a [http://en.wikipedia.org/wiki/Responsible_disclosure responsible disclosure] process:&lt;br /&gt;
## In most cases, CVE identifiers will be assigned to the vulnerabilities found&lt;br /&gt;
## After the flaws have been corrected in the source code, software maintainers release patches and/or new versions of the software to help secure their userbase.  At that time, the original FLOSSHack participants who found the flaws ''should be credited with the finding, unless they choose to remain anonymous''.  A simple credit is all that is necessary, such as &amp;quot;Thanks to Jane Participant for bringing CVE-XXXX-XXXX to our attention.&amp;quot;&lt;br /&gt;
## After all flaws have been corrected, a listing of the flaws found will be posted to the FLOSSHack event page&lt;/div&gt;</summary>
		<author><name>TimMorgan</name></author>	</entry>

	</feed>