<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Kansas_City_June_2007_Meeting</id>
		<title>Kansas City June 2007 Meeting - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Kansas_City_June_2007_Meeting"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_June_2007_Meeting&amp;action=history"/>
		<updated>2026-05-16T20:19:49Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_June_2007_Meeting&amp;diff=20294&amp;oldid=prev</id>
		<title>Rknell: Linked keyword: HTTPOnly</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_June_2007_Meeting&amp;diff=20294&amp;oldid=prev"/>
				<updated>2007-07-27T17:40:56Z</updated>
		
		<summary type="html">&lt;p&gt;Linked keyword: HTTPOnly&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 17:40, 27 July 2007&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l5&quot; &gt;Line 5:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 5:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Dave Ferguson of FishNet Security started the meeting with a welcome and overview of OWASP.&amp;#160; Attendee Rohini Sulatycki briefly described the new OWASP AJAX project, for which she is the project leader.&amp;#160; Next, Dave Ferguson announced that he would be stepping down as the OWASP Kansas City chapter leader due to the fact that he is relocating to the Dallas, TX area.&amp;#160; A search for a new chapter leader will begin.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Dave Ferguson of FishNet Security started the meeting with a welcome and overview of OWASP.&amp;#160; Attendee Rohini Sulatycki briefly described the new OWASP AJAX project, for which she is the project leader.&amp;#160; Next, Dave Ferguson announced that he would be stepping down as the OWASP Kansas City chapter leader due to the fact that he is relocating to the Dallas, TX area.&amp;#160; A search for a new chapter leader will begin.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Our first speaker was Jake Reynolds from FishNet Security.&amp;#160; Jake described more than a dozen different Firefox extensions that involve some aspect of web application security.&amp;#160; Some, such as TamperData and Web Developer, provide useful functionality for auditing/assessing the security of an application.&amp;#160; Others, such as &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;httpOnly &lt;/del&gt;and NoScript, are specialized extensions that can keep you safer when surfing the Internet.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Our first speaker was Jake Reynolds from FishNet Security.&amp;#160; Jake described more than a dozen different Firefox extensions that involve some aspect of web application security.&amp;#160; Some, such as TamperData and Web Developer, provide useful functionality for auditing/assessing the security of an application.&amp;#160; Others, such as &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[HTTPOnly]] &lt;/ins&gt;and NoScript, are specialized extensions that can keep you safer when surfing the Internet.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Following a break, Barry Archer from American Century Investments presented on the topic of web application firewalls.&amp;#160; Specifically, Barry talked about his experience with evaluating mod_security for Apache and a particular commercial WAF product.&amp;#160; Issues such as negative vs. positive security models, the importance of having a well-designed log format, and how to handle updates to an application were discussed.&amp;#160;  Barry also explained why you need to understand HTTP in order to properly &amp;quot;tune&amp;quot; a WAF.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Following a break, Barry Archer from American Century Investments presented on the topic of web application firewalls.&amp;#160; Specifically, Barry talked about his experience with evaluating mod_security for Apache and a particular commercial WAF product.&amp;#160; Issues such as negative vs. positive security models, the importance of having a well-designed log format, and how to handle updates to an application were discussed.&amp;#160;  Barry also explained why you need to understand HTTP in order to properly &amp;quot;tune&amp;quot; a WAF.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rknell</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_June_2007_Meeting&amp;diff=19187&amp;oldid=prev</id>
		<title>Owaspdavef: New page: The OWASP Kansas City chapter meeting in June 2007 was held from 6:30 to 8:30 pm on 6/13/2007.  The location of the meeting was at the offices of FishNet Security at 1627 M...</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_June_2007_Meeting&amp;diff=19187&amp;oldid=prev"/>
				<updated>2007-06-14T20:50:10Z</updated>
		
		<summary type="html">&lt;p&gt;New page: The OWASP &lt;a href=&quot;/index.php/Kansas_City&quot; title=&quot;Kansas City&quot;&gt;Kansas City chapter&lt;/a&gt; meeting in June 2007 was held from 6:30 to 8:30 pm on 6/13/2007.  The location of the meeting was at the offices of FishNet Security at 1627 M...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;The OWASP [[Kansas City|Kansas City chapter]] meeting in June 2007 was held from 6:30 to 8:30 pm on 6/13/2007.  The location of the meeting was at the offices of FishNet Security at 1627 Main Street in Kansas City, MO.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
Dave Ferguson of FishNet Security started the meeting with a welcome and overview of OWASP.  Attendee Rohini Sulatycki briefly described the new OWASP AJAX project, for which she is the project leader.  Next, Dave Ferguson announced that he would be stepping down as the OWASP Kansas City chapter leader due to the fact that he is relocating to the Dallas, TX area.  A search for a new chapter leader will begin.&lt;br /&gt;
&lt;br /&gt;
Our first speaker was Jake Reynolds from FishNet Security.  Jake described more than a dozen different Firefox extensions that involve some aspect of web application security.  Some, such as TamperData and Web Developer, provide useful functionality for auditing/assessing the security of an application.  Others, such as httpOnly and NoScript, are specialized extensions that can keep you safer when surfing the Internet.&lt;br /&gt;
&lt;br /&gt;
Following a break, Barry Archer from American Century Investments presented on the topic of web application firewalls.  Specifically, Barry talked about his experience with evaluating mod_security for Apache and a particular commercial WAF product.  Issues such as negative vs. positive security models, the importance of having a well-designed log format, and how to handle updates to an application were discussed.   Barry also explained why you need to understand HTTP in order to properly &amp;quot;tune&amp;quot; a WAF.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;br /&gt;
[[Media:KC_June_2007_Firefox_as_AppSec_Tool.zip|Firefox as a Web Application Security Assessment Tool]] (ppt within a zip)&amp;lt;br/&amp;gt;&lt;br /&gt;
[[Media:KC_June_2007_Evaluating_and_Tuning_WAFs.pdf|Evaluating and Tuning Web Application Firewalls]] (pdf)&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Owaspdavef</name></author>	</entry>

	</feed>