|
|
(226 intermediate revisions by 20 users not shown) |
Line 1: |
Line 1: |
− | == Welcome to the OWASP Washington, DC-Maryland Local Chapter ==
| + | __NOTOC__ |
| | | |
− | The original DC Chapter was founded in June 2004 by [mailto:jeff.williams@owasp.org Jeff Williams] and has had members from Virginia to Delaware. In April 2005 a new chapter, DC-Virginia, was formed and the DC Chapter was renamed to DC-Maryland. The two are sister chapters with common members and shared discourse. The chapters meet in opposite halves of the month to facilitate this relationship. | + | {{Chapter Template|chaptername=Washington DC|extra=The chapter leaders are [mailto:emily.verwee@owasp.org Emily Verwee], [mailto:andrew.weidenhamer@owasp.org Andrew Weidenhamer] and [mailto:Bryan.Batty@owasp.org Bryan Batty].|mailinglistsite=http://lists.owasp.org/mailman/listinfo/Owasp-washington|emailarchives=http://lists.owasp.org/pipermail/Owasp-washington}} |
− | | |
− | Chapter meetings are held several times a year, typically in the offices of our sponsor. Please subscribe to the [http://lists.sourceforge.net/lists/listinfo/owasp-washington/ mailing list] for meeting announcements.
| |
− | | |
− | Our chapter is sponsored by [http://www.aspectsecurity.com Aspect Security].
| |
− | | |
− | == Participation ==
| |
− | | |
− | OWASP Local Chapter meetings are free and open. Our chapter's meetings are informal and encourage open discussion of all aspects of application security. Anyone in our area interested in web application security is welcome to attend. We encourage attendees to give short presentations about specific topics. If you would like to make a presentation, or have any questions about the DC-Maryland Chapter, send an email to [mailto:mattfisher@comcast.net Matt Fisher] or [mailto:aludwig@packetspy.com Andre Ludwig].
| |
− | | |
− | Between meetings we keep the discussion going via mailing list. To join our chapter [http://lists.sourceforge.net/lists/listinfo/owasp-washington/ mailing list], visit our mailing list page. List membership is kept private.
| |
| | | |
| == Local News == | | == Local News == |
| | | |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| + | '''Next Meeting - The Groovy Landscape & Grails Security''' 6:30PM Thursday, July 10th UberOffices - 1200 18th Street, NW, Suite 700, Washington, DC |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'>[[Image:Document.gif]] Meeting: March 23rd</span></b></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Thu Feb 16 15:41:45
| |
− | EST 2006 </span></b></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>March Meeting
| |
− | Announcement</span></b></p>
| |
− | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><br>
| |
− | <br>
| |
− | Our next meeting is on Thursday March 23rd at 1800 hours in the offices of
| |
− | Aspect Security. <br>
| |
− | <br>
| |
− | This is going to be a technical meeting focusing on AJAX Security. <br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | In case you weren't aware, AJAX is a clever use of existing technologies to
| |
− | provide richer interfaces on the web (think Google Maps). It's growing in
| |
− | popularity and "buzz", so be sure to make this meeting and learn all
| |
− | you can about it. <br>
| |
− | <br>
| |
− | If you have some AJAX science you'd like to drop on us, then email me directly
| |
− | at mfisher at spidynamics dot com <br>
| |
− | <u><br>
| |
− | The Agenda:</u><br>
| |
− | <br>
| |
− | <br>
| |
− | 1. Opening, introductions<br>
| |
− | <br>
| |
− | 2. Presentation by Rick Pries: An introduction to AJAX <br>
| |
− | <br>
| |
− | 3. Overview and Review of the new OWASP AJAX Security Guide <br>
| |
− | <br>
| |
− | 4. BoF discussion on AJAX and AJAX security <br>
| |
− | <br>
| |
− | 5. Everything Else: Current Events, OWASP news, Industry News, Recent Hacks in
| |
− | the News, Closing, etc. <br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | <u>Food:</u><br>
| |
− | <br>
| |
− | As usual, geek food will be provided. This usually means pizza and soda. <br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | <u>Getting there</u><br>
| |
− | <br>
| |
− | <br>
| |
− | Aspect is located at 9175 Guilford Road (Suite 300) in Columbia. Driving
| |
− | directions are: <br>
| |
− | <br>
| |
− | <br>
| |
− | From I-95: <br>
| |
− | <br>
| |
− | <br>
| |
− | Exit 38 B : Rt. 32 West towards Columbia (1.5 miles)<br>
| |
− | <br>
| |
− | Take the Broken Land Parkway exit <br>
| |
− | <br>
| |
− | Turn left off the ramp onto Broken Land Parkway<br>
| |
− | <br>
| |
− | Turn left at the light onto Guilford Road (0.5 miles)<br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | After a sharp left, enter the parking lot at 9175 Guilford Road. [Note: if you
| |
− | go under the bridge, you've gone too far]<br>
| |
− | <br>
| |
− | We're on the third floor in Suite 300<br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | Unfortunatley being out in the far 'burbs there is very limited public
| |
− | transport. <br>
| |
− | <br>
| |
− | If you need help getting to the meeting, try emailing the list at:
| |
− | | |
− | <br>
| |
− | There are two MARC stations within a twenty minute drive, and the MTA
| |
− | contracted commuter busses drop off within 2 miles of the offices. <br>
| |
− | <br>
| |
− | <u>Wireless</u><br>
| |
− | <br>
| |
− | <br>
| |
− | I am please to announce that we may just have wireless access for the meeting.
| |
− | No promises, but if you're the type who likes to look stuff up realtime then
| |
− | you may want to bring the laptop. <br>
| |
− | <br>
| |
− | If we *are* lucky to enough to get wireless access, there will be a serious
| |
− | "no playing around" policy in place, and anyone breaking it will be
| |
− | kick/banned for life, y'all hear ? <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | | |
− | <html xmlns:v="urn:schemas-microsoft-com:vml"
| |
− | xmlns:o="urn:schemas-microsoft-com:office:office"
| |
− | xmlns:w="urn:schemas-microsoft-com:office:word"
| |
− | xmlns="http://www.w3.org/TR/REC-html40">
| |
− | | |
− | <head>
| |
− | <meta http-equiv=Content-Type content="text/html; charset=iso-8859-1">
| |
− | <meta name=ProgId content=Word.Document>
| |
− | <meta name=Generator content="Microsoft Word 11">
| |
− | <meta name=Originator content="Microsoft Word 11">
| |
− | <link rel=File-List href="washington_files/filelist.xml">
| |
− | <link rel=Edit-Time-Data href="washington_files/editdata.mso">
| |
− | <!--[if !mso]>
| |
− | <style>
| |
− | v\:* {behavior:url(#default#VML);}
| |
− | o\:* {behavior:url(#default#VML);}
| |
− | w\:* {behavior:url(#default#VML);}
| |
− | .shape {behavior:url(#default#VML);}
| |
− | </style>
| |
− | <![endif]-->
| |
− | <title>Washington (Maryland)</title>
| |
− | <!--[if gte mso 9]><xml>
| |
− | <o:DocumentProperties>
| |
− | <o:Author>esheridan</o:Author>
| |
− | <o:Revision>1</o:Revision>
| |
− | <o:TotalTime>0</o:TotalTime>
| |
− | <o:Created>2006-05-12T18:56:00Z</o:Created>
| |
− | <o:Pages>1</o:Pages>
| |
− | <o:Words>8550</o:Words>
| |
− | <o:Characters>48739</o:Characters>
| |
− | <o:Company>Aspect Security</o:Company>
| |
− | <o:Lines>406</o:Lines>
| |
− | <o:Paragraphs>114</o:Paragraphs>
| |
− | <o:CharactersWithSpaces>57175</o:CharactersWithSpaces>
| |
− | <o:Version>11.5606</o:Version>
| |
− | </o:DocumentProperties>
| |
− | </xml><![endif]--><!--[if gte mso 9]><xml>
| |
− | <w:WordDocument>
| |
− | <w:Zoom>0</w:Zoom>
| |
− | <w:ValidateAgainstSchemas/>
| |
− | <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
| |
− | <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
| |
− | <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
| |
− | <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel>
| |
− | </w:WordDocument>
| |
− | </xml><![endif]--><!--[if gte mso 9]><xml>
| |
− | <w:LatentStyles DefLockedState="false" LatentStyleCount="156">
| |
− | </w:LatentStyles>
| |
− | </xml><![endif]-->
| |
− | <link rel=Stylesheet type="text/css" media=all
| |
− | href="../../../../../Desktop/washington_files/news.css">
| |
− | <link rel=Stylesheet type="text/css" media=all
| |
− | href="../../../../../Desktop/washington_files/main.css">
| |
− | <link rel=Stylesheet type="text/css" media=all
| |
− | href="../../../../../Desktop/washington_files/menu_icons.css">
| |
− | <link rel=Stylesheet type="text/css" media=all
| |
− | href="../../../../../Desktop/washington_files/menu.css">
| |
− | <style>
| |
− | <!--
| |
− | /* Font Definitions */
| |
− | @font-face
| |
− | {font-family:Wingdings;
| |
− | panose-1:5 0 0 0 0 0 0 0 0 0;
| |
− | mso-font-charset:2;
| |
− | mso-generic-font-family:auto;
| |
− | mso-font-pitch:variable;
| |
− | mso-font-signature:0 268435456 0 0 -2147483648 0;}
| |
− | @font-face
| |
− | {font-family:Tahoma;
| |
− | panose-1:2 11 6 4 3 5 4 4 2 4;
| |
− | mso-font-charset:0;
| |
− | mso-generic-font-family:swiss;
| |
− | mso-font-pitch:variable;
| |
− | mso-font-signature:1627421319 -2147483648 8 0 66047 0;}
| |
− | @font-face
| |
− | {font-family:"Lucida Console";
| |
− | panose-1:2 11 6 9 4 5 4 2 2 4;
| |
− | mso-font-charset:0;
| |
− | mso-generic-font-family:modern;
| |
− | mso-font-pitch:fixed;
| |
− | mso-font-signature:-2147482993 6144 0 0 31 0;}
| |
− | @font-face
| |
− | {font-family:"Lucida Sans Unicode";
| |
− | panose-1:2 11 6 2 3 5 4 2 2 4;
| |
− | mso-font-charset:0;
| |
− | mso-generic-font-family:swiss;
| |
− | mso-font-pitch:variable;
| |
− | mso-font-signature:-2147476737 14699 0 0 63 0;}
| |
− | /* Style Definitions */
| |
− | p.MsoNormal, li.MsoNormal, div.MsoNormal
| |
− | {mso-style-parent:"";
| |
− | margin:0in;
| |
− | margin-bottom:.0001pt;
| |
− | line-height:normal;
| |
− | mso-pagination:widow-orphan;
| |
− | font-size:12.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-fareast-font-family:"Times New Roman";}
| |
− | h1
| |
− | {mso-margin-top-alt:auto;
| |
− | margin-right:0in;
| |
− | mso-margin-bottom-alt:auto;
| |
− | margin-left:0in;
| |
− | line-height:normal;
| |
− | mso-pagination:widow-orphan;
| |
− | mso-outline-level:1;
| |
− | font-size:24.0pt;
| |
− | font-family:"Times New Roman";
| |
− | font-weight:bold;}
| |
− | h2
| |
− | {mso-margin-top-alt:auto;
| |
− | margin-right:0in;
| |
− | mso-margin-bottom-alt:auto;
| |
− | margin-left:0in;
| |
− | line-height:normal;
| |
− | mso-pagination:widow-orphan;
| |
− | mso-outline-level:2;
| |
− | font-size:18.0pt;
| |
− | font-family:"Times New Roman";
| |
− | font-weight:bold;}
| |
− | h3
| |
− | {mso-margin-top-alt:auto;
| |
− | margin-right:0in;
| |
− | mso-margin-bottom-alt:auto;
| |
− | margin-left:0in;
| |
− | line-height:normal;
| |
− | mso-pagination:widow-orphan;
| |
− | mso-outline-level:3;
| |
− | font-size:13.5pt;
| |
− | font-family:"Times New Roman";
| |
− | font-weight:bold;}
| |
− | p
| |
− | {font-size:12.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-fareast-font-family:"Times New Roman";}
| |
− | code
| |
− | {mso-fareast-font-family:"Times New Roman";
| |
− | mso-bidi-font-family:"Courier New";}
| |
− | pre
| |
− | {font-size:10.0pt;
| |
− | mso-fareast-font-family:"Times New Roman";
| |
− | mso-bidi-font-family:"Courier New";}
| |
− | p.itemglobe, li.itemglobe, div.itemglobe
| |
− | {mso-style-name:itemglobe;
| |
− | font-size:12.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-fareast-font-family:"Times New Roman";}
| |
− | p.itemdocument, li.itemdocument, div.itemdocument
| |
− | {mso-style-name:itemdocument;
| |
− | font-size:12.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-fareast-font-family:"Times New Roman";}
| |
− | p.itemsearch, li.itemsearch, div.itemsearch
| |
− | {mso-style-name:itemsearch;
| |
− | font-size:12.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-fareast-font-family:"Times New Roman";}
| |
− | p.itemstar, li.itemstar, div.itemstar
| |
− | {mso-style-name:itemstar;
| |
− | font-size:12.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-fareast-font-family:"Times New Roman";}
| |
− | p.itemhelp, li.itemhelp, div.itemhelp
| |
− | {mso-style-name:itemhelp;
| |
− | font-size:12.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-fareast-font-family:"Times New Roman";}
| |
− | p.itemmail, li.itemmail, div.itemmail
| |
− | {mso-style-name:itemmail;
| |
− | font-size:12.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-fareast-font-family:"Times New Roman";}
| |
− | p.iteminfo, li.iteminfo, div.iteminfo
| |
− | {mso-style-name:iteminfo;
| |
− | font-size:12.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-fareast-font-family:"Times New Roman";}
| |
− | p.itemhistory, li.itemhistory, div.itemhistory
| |
− | {mso-style-name:itemhistory;
| |
− | font-size:12.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-fareast-font-family:"Times New Roman";}
| |
− | @page Section1
| |
− | {size:8.5in 11.0in;
| |
− | margin:1.0in 1.25in 1.0in 1.25in;
| |
− | mso-header-margin:.5in;
| |
− | mso-footer-margin:.5in;
| |
− | mso-paper-source:0;}
| |
− | div.Section1
| |
− | {page:Section1;}
| |
− | /* List Definitions */
| |
− | @list l0
| |
− | {mso-list-id:316421181;
| |
− | mso-list-template-ids:-2143404858;}
| |
− | @list l0:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l0:level2
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:o;
| |
− | mso-level-tab-stop:1.0in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:"Courier New";
| |
− | mso-bidi-font-family:"Times New Roman";}
| |
− | @list l1
| |
− | {mso-list-id:352807342;
| |
− | mso-list-template-ids:59295898;}
| |
− | @list l1:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l1:level2
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:o;
| |
− | mso-level-tab-stop:1.0in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:"Courier New";
| |
− | mso-bidi-font-family:"Times New Roman";}
| |
− | @list l1:level3
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0A7;
| |
− | mso-level-tab-stop:1.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Wingdings;}
| |
− | @list l1:level4
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0A7;
| |
− | mso-level-tab-stop:2.0in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Wingdings;}
| |
− | @list l2
| |
− | {mso-list-id:566913955;
| |
− | mso-list-template-ids:1073645234;}
| |
− | @list l2:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l3
| |
− | {mso-list-id:734545486;
| |
− | mso-list-template-ids:-478672564;}
| |
− | @list l3:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l4
| |
− | {mso-list-id:745688644;
| |
− | mso-list-template-ids:-1886236700;}
| |
− | @list l4:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l4:level2
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:o;
| |
− | mso-level-tab-stop:1.0in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:"Courier New";
| |
− | mso-bidi-font-family:"Times New Roman";}
| |
− | @list l4:level3
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0A7;
| |
− | mso-level-tab-stop:1.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Wingdings;}
| |
− | @list l4:level4
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0A7;
| |
− | mso-level-tab-stop:2.0in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Wingdings;}
| |
− | @list l4:level5
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0A7;
| |
− | mso-level-tab-stop:2.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Wingdings;}
| |
− | @list l5
| |
− | {mso-list-id:750741999;
| |
− | mso-list-template-ids:2094436024;}
| |
− | @list l5:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l6
| |
− | {mso-list-id:822548035;
| |
− | mso-list-template-ids:-1604937518;}
| |
− | @list l6:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l6:level2
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:o;
| |
− | mso-level-tab-stop:1.0in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:"Courier New";
| |
− | mso-bidi-font-family:"Times New Roman";}
| |
− | @list l6:level3
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0A7;
| |
− | mso-level-tab-stop:1.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Wingdings;}
| |
− | @list l7
| |
− | {mso-list-id:860508930;
| |
− | mso-list-template-ids:-2053202376;}
| |
− | @list l7:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l8
| |
− | {mso-list-id:1066608704;
| |
− | mso-list-template-ids:-1014212564;}
| |
− | @list l8:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l9
| |
− | {mso-list-id:1096054018;
| |
− | mso-list-template-ids:1000787652;}
| |
− | @list l9:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l9:level2
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:o;
| |
− | mso-level-tab-stop:1.0in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:"Courier New";
| |
− | mso-bidi-font-family:"Times New Roman";}
| |
− | @list l10
| |
− | {mso-list-id:1138231515;
| |
− | mso-list-template-ids:-661380900;}
| |
− | @list l10:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l11
| |
− | {mso-list-id:1157961288;
| |
− | mso-list-template-ids:541649854;}
| |
− | @list l11:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l12
| |
− | {mso-list-id:1309819849;
| |
− | mso-list-template-ids:1490691168;}
| |
− | @list l12:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l13
| |
− | {mso-list-id:1473911790;
| |
− | mso-list-template-ids:1509094940;}
| |
− | @list l13:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l14
| |
− | {mso-list-id:1560096670;
| |
− | mso-list-template-ids:313004116;}
| |
− | @list l14:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l15
| |
− | {mso-list-id:1875078222;
| |
− | mso-list-template-ids:-1770220104;}
| |
− | @list l15:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l15:level2
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:o;
| |
− | mso-level-tab-stop:1.0in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:"Courier New";
| |
− | mso-bidi-font-family:"Times New Roman";}
| |
− | @list l16
| |
− | {mso-list-id:1897667137;
| |
− | mso-list-template-ids:-1454605008;}
| |
− | @list l16:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l17
| |
− | {mso-list-id:1902593455;
| |
− | mso-list-template-ids:51912178;}
| |
− | @list l17:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l18
| |
− | {mso-list-id:1914922900;
| |
− | mso-list-template-ids:-486622514;}
| |
− | @list l18:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l19
| |
− | {mso-list-id:2087803268;
| |
− | mso-list-template-ids:-439826374;}
| |
− | @list l19:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | @list l19:level2
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:o;
| |
− | mso-level-tab-stop:1.0in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:"Courier New";
| |
− | mso-bidi-font-family:"Times New Roman";}
| |
− | @list l20
| |
− | {mso-list-id:2141457508;
| |
− | mso-list-template-ids:-276536746;}
| |
− | @list l20:level1
| |
− | {mso-level-number-format:bullet;
| |
− | mso-level-text:\F0B7;
| |
− | mso-level-tab-stop:.5in;
| |
− | mso-level-number-position:left;
| |
− | text-indent:-.25in;
| |
− | mso-ansi-font-size:10.0pt;
| |
− | font-family:Symbol;}
| |
− | ol
| |
− | {margin-bottom:0in;}
| |
− | ul
| |
− | {margin-bottom:0in;}
| |
− | -->
| |
− | </style>
| |
− | <!--[if gte mso 10]>
| |
− | <style>
| |
− | /* Style Definitions */
| |
− | table.MsoNormalTable
| |
− | {mso-style-name:"Table Normal";
| |
− | mso-tstyle-rowband-size:0;
| |
− | mso-tstyle-colband-size:0;
| |
− | mso-style-noshow:yes;
| |
− | mso-style-parent:"";
| |
− | mso-padding-alt:0in 5.4pt 0in 5.4pt;
| |
− | mso-para-margin:0in;
| |
− | mso-para-margin-bottom:.0001pt;
| |
− | mso-pagination:widow-orphan;
| |
− | font-size:10.0pt;
| |
− | font-family:"Times New Roman";
| |
− | mso-ansi-language:#0400;
| |
− | mso-fareast-language:#0400;
| |
− | mso-bidi-language:#0400;}
| |
− | </style>
| |
− | <![endif]-->
| |
− | <meta name=author content="OWASP Portal Team">
| |
− | <meta name=description
| |
− | content="The Open Web Application Security Project: All things related to web application security">
| |
− | <meta name=keywords content="web, application, security, java, .net, c++">
| |
− | <!--[if gte mso 9]><xml>
| |
− | <o:shapedefaults v:ext="edit" spidmax="2050"/>
| |
− | </xml><![endif]--><!--[if gte mso 9]><xml>
| |
− | <o:shapelayout v:ext="edit">
| |
− | <o:idmap v:ext="edit" data="1"/>
| |
− | </o:shapelayout></xml><![endif]-->
| |
− | </head>
| |
− | | |
− |
| |
− | | |
− |
| |
− | | |
− | <body bgcolor=white background="../../../../../../../docroot/owasp/img/wasp.gif"
| |
− | lang=EN-US link=black vlink=black style='tab-interval:.5in'>
| |
− | | |
− | <div class=Section1>
| |
− | | |
− | <div id=container>
| |
− | | |
− | <div id=header>
| |
− | | |
− | <table class=MsoNormalTable border=0 cellpadding=0 width="100%"
| |
− | style='width:100.0%;mso-cellspacing:1.5pt'>
| |
− | <tr style='mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
| |
− | <td style='padding:.75pt .75pt .75pt .75pt'>
| |
− | <p class=MsoNormal><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/"><span style='text-decoration:
| |
− | none;text-underline:none'><img border=0 width=325 height=60 id="_x0000_i1025"
| |
− | src="../../../../../Desktop/washington_files/owasp_logo.gif"></span></a><o:p></o:p></span></p>
| |
− | </td>
| |
− | <td width="100%" style='width:100.0%;padding:.75pt .75pt .75pt .75pt'>
| |
− | <p class=MsoNormal><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'> <o:p></o:p></span></p>
| |
− | </td>
| |
− | <td style='padding:.75pt .75pt .75pt .75pt'>
| |
− | <p class=MsoNormal align=center style='margin-bottom:12.0pt;text-align:center'><span
| |
− | style='font-size:7.0pt;font-family:Arial;color:#333333;letter-spacing:.75pt'><a
| |
− | href="http://www.acunetix.com/"><span style='text-decoration:none;text-underline:
| |
− | none'><img border=0 width=468 height=60 id="_x0000_i1026"
| |
− | src="../../../../../Desktop/washington_files/acunetix0106.gif"></span></a><o:p></o:p></span></p>
| |
− | <div style='margin-left:3.75pt'>
| |
− | <p class=MsoNormal><span style='font-size:6.0pt;font-family:"Lucida Sans Unicode";
| |
− | color:#333333;letter-spacing:.75pt'>Sponsored <a
| |
− | href="http://www.owasp.org/about/advertising.html">advertisement</a>. OWASP
| |
− | does not endorse commercial products or services.<o:p></o:p></span></p>
| |
− | </div>
| |
− | </td>
| |
− | </tr>
| |
− | </table>
| |
− | | |
− | </div>
| |
| | | |
− | <div style='border-top:solid #CCCCCC 1.0pt;border-left:none;border-bottom:solid #CCCCCC 1.0pt;
| + | Everyone is welcome to join us at our chapter meetings. |
− | border-right:none;mso-border-top-alt:solid #CCCCCC .75pt;mso-border-bottom-alt:
| |
− | solid #CCCCCC .75pt;padding:0in 0in 0in 0in' id=menu>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:1.5pt;margin-bottom:0in;
| |
− | margin-left:51.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level1 lfo1;
| |
− | tab-stops:list .5in;background:whitesmoke'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:black'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/index.html"><span style='border:
| |
− | none windowtext 1.0pt;mso-border-alt:none windowtext 0in;padding:0in;
| |
− | text-decoration:none;text-underline:none'>OWASP - Home</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | Welcome to the Home Page of the Washington DC OWASP Chapter.<br><br> |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/index/archives.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archives</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | * Please checkout our Meetup page (http://www.meetup.com/OWASPDC/) for the latest announcements or subscribe to the [http://lists.owasp.org/mailman/listinfo/owasp-washington mailing list] for meeting information. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/index/archives/news.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive December 13</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | * You can follow us on Twitter as [http://twitter.com/owaspdc @OWASPDC] |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/index/archives/news2.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive January 28</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | * Our recent meetings are documented on the News & Meetings tab. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span | |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/index/archives/news3.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive April 27
| |
− | 2005</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | * You can also check out the archives of this page here [[Washington_DC Archives]]. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/index/archives/news4.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive Sept 2 2005</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/index/archives/news5.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive Nov 13 2005</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | = Meetings & Events = |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/index/archives/new6.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive Dec 18 2005</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:6.0pt;margin-bottom:0in;
| + | Chapter meetings are held several times a year, typically at a location provided by our current facility sponsor.<br><br> |
− | margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level4 lfo1;
| |
− | tab-stops:list 2.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/index/archives/new6/archives.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archives</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:7.5pt;margin-bottom:0in;
| + | '''Next Meeting - The Groovy Landscape & Grails Security''' |
− | margin-left:54.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level5 lfo1;
| |
− | tab-stops:list 2.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/index/archives/new6/archives/news.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive December 13</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:7.5pt;margin-bottom:0in;
| + | The next meeting will be on Thursday, July 10, 2014 from 6:30 PM to 8:30 PM (EDT) at |
− | margin-left:54.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level5 lfo1;
| |
− | tab-stops:list 2.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/index/archives/new6/archives/news2.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive January 28</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:7.5pt;margin-bottom:0in;
| + | '''Location:''' UberOffices - 1200 18th Street, NW, Suite 700, Washington, DC |
− | margin-left:54.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level5 lfo1;
| |
− | tab-stops:list 2.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/index/archives/new6/archives/news3.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive April 27
| |
− | 2005</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:7.5pt;margin-bottom:0in;
| + | Please RSVP for the event here: http://www.meetup.com/OWASPDC/ |
− | margin-left:54.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level5 lfo1;
| |
− | tab-stops:list 2.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/index/archives/new6/archives/news4.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive Sept 2 2005</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:7.5pt;margin-bottom:0in;
| + | '''Presentation Overview:''' |
− | margin-left:54.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level5 lfo1;
| + | 1st Talk - "The Groovy Landscape" |
− | tab-stops:list 2.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/index/archives/new6/archives/news5.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>News Archive Nov 13 2005</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:1.5pt;margin-bottom:0in;
| + | This talk is geared to those who are new to Groovy and the goal is to put the Groovy language in is proper context. We will try to answer the following questions: |
− | margin-left:51.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level1 lfo1;
| |
− | tab-stops:list .5in;background:whitesmoke'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:black'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Columns</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | What are the properties of the language? |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| + | When and why was it developed? |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| + | Who is using it and who maintains it? |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| + | Where can I use it? |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| + | How do I get started or contribute to development? |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/mcurphey.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Mark Curphey</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | 2nd Talk - "Grails Security" |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/mcurphey/history.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>SSL issues</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | Grails is a framework developed for Groovy in the vein of Rails for Ruby. It provides a lot of features for web app security, but does it do enough? What might you need to implement yourself, and what might be provided? This presentation will discuss tips on securing Grails applications, including tools that the framework provides by default for security. It'll also discuss several shortcomings in the current toolset, and how you can avoid them. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/mcurphey/tailored.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Documentation Framework</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | '''Speaker:''' |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| + | David James - David is a software developer and consultant who helps enterprise clients deliver software that makes a business impact. He has been developing applications on the JVM for fifteen years and leverages Groovy on a daily basis. David is involved in the Arlington coworking community and is the founder of the DC Groovy user group. |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jwilliams.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Jeff Williams</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | Cyrus Malekpour - Cyrus (@cmalekpour) is a software developer at nVisium, working on web app development and security. He's currently an undergraduate student at the University of Virginia, where he's studying computer science with an emphasis on security and backend development. Most of his passion is in designing and developing secure applications, but he also has an interest in breaking into things. In his free time, he likes to read, watch movies, and cycle. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jwilliams/jwilliams1.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Trustworthy Java</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | = Participation = |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| + | OWASP Local Chapter meetings are free and open. Our chapter's meetings are informal and encourage open discussion of all aspects of application security. Anyone in our area interested in web application security is welcome to attend. We encourage attendees to give short presentations about specific topics. |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jwilliams/jwilliams2.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Stinger</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | If you would like to make a presentation, or have any questions about the DC Chapter, send an email to one of the chapter co-chairs or the [mailto:owasp-washington__AT__lists.owasp.org Mailing List].<br><br> |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jwilliams/jwilliams3.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Access Control</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | = Twitter = |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| + | <!-- Twitter Box --> {| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jwilliams/jwilliams4.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Contracts</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | | style="border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);" | |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/george.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>George Capehart</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''You can follow us on Twitter as [http://twitter.com/owaspdc @OWASPDC]''' <twitter>23609877</twitter> |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/george/ws-services.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>More than WS-Security</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | | style="width: 110px; font-size: 95%; color: rgb(0, 0, 0);" | |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/george/twosystems.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Tale of Two Systems</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | |} |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/george/architecture.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Web Services Architecture</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | = News & Recent Meetings = |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| + | Archives from earlier meetings than contained on this page can be found in the [[Washington_DC Archives]]<br><br> |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jlima.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Joe Lima</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''May 2014 Meeting''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jlima/joelima1.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>IIS Security</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Presentation Overview:''' As mobile dating applications grow in popularity, so does our interest in the security posture behind them. There are a vast number of mobile dating applications available for use today by anyone with a smart phone. We wanted to take a look at numerous features within these apps to determine the good, the bad, and the ugly. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jlima/joelima2.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>IIS Authentication</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | We will cover popular features such as location-based services, analytics, sharing of information, in-app purchasing, and any other features we discover to be interesting. We will analyze the type of personal data being stored within these applications, communication channels used to transmit information, hardware interaction with the application, and interaction with other applications on the device. We will answer the big questions posed by those who use these apps or want to use these apps: Are these applications disclosing sensitive information? How private is the communication between me and another user? How can I be sure my data is being protected? |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jpoteet.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Jeremy Poteet</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | This talk will feature highlights from popular, obscure, and scary dating applications to answer a simple question: “Can you find love on the Internet without having your personal data exposed?” |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jpoteet/jpoteet1.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>.NET security</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Speaker:''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| + | Jack Mannino is an Application Security expert with over a decade of experience building, breaking, and securing into complex systems. Jack is Co-Founder and CEO of nVisium, while also leading research and development initiatives. With experience developing in Java, Objective-C, and C#, he performs risk assessments and penetration tests for Fortune 500 companies and government agencies. Jack also founded and leads the OWASP Mobile Application Security Project, which is a global initiative to build secure development standards for mobile. He is an active Android security researcher with a keen interest in large-scale security analysis. |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/jpoteet/jpoteet2.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Input validation</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | Abdullah Munawar is an Application Security consultant at nVisium who specializes in mobile application testing and ripping apart new things. With over 7 years of experience, Abdullah previously worked on the security teams at financial and aviation organizations. Abdullah attempts humor on a daily basis and succeeds most of the time, every time. |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/mordechai.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Ido Rosen</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''March 2014 Meeting''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/columns/mordechai/encrypted_sessions.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Encrypted Sessions</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | '''Presentation Overview:''' How is identity and access management (IAM) implemented in your in-house applications? Do the developers who implement it have IAM expertise? Does every team implement their own IAM? |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| + | Enterprise framework development teams with IAM expertise can address the problem by creating APIs that enable developers without IAM expertise to implement the IAM correctly. This presentation explains what an enterprise identity API is, why it's worthwhile to create one and how it might be done. |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/mburnett.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Mark Burnett</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Speaker:''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| + | Adam Migus (@amigus) - Adam currently works as an IT architect helping his clients devise and execute technology strategy. Prior to that he was a Principal Security Architect at E*TRADE Financial where he created APIs as a means to improve software security. Adam believes that software quality is critical to software security and that many application security concerns can be addressed through enterprise APIs. He's also held positions at McAfee and Symantec. He earned his B.Sc. in Computer Science from Memorial University of Newfoundland, where he also started his career in earnest as a network administrator. |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/mburnett/questions.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Using Secret Questions</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''February 2014 Meeting''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/columns/mburnett/brutegeneral.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Blocking Brute Force
| |
− | Attacks - General</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:1.5pt;margin-bottom:0in;
| + | '''Presentation Overview:''' Bojan Simic will provide a short background into Bitcoin and how it works. He will then provide some of his firsthand experiences with the state of Bitcoin businesses with regard to security and how many individuals are (insecurely) handling their Bitcoins. These experiences will demonstrate some "hacks" that pertain to the OWASP Top 10 as well as other types of vulnerabilities. The talk will include an overview of simple security steps that individuals and businesses who are working with Bitcoin should take to in order to mitigate the chance of hackers stealing Bitcoin and Personally Identifiable Information (PII) from them and their customers. |
− | margin-left:51.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level1 lfo1;
| |
− | tab-stops:list .5in;background:whitesmoke'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:black'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Documentation</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | '''Speaker:''' |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| + | Bojan is a security engineer in the industry as well as the founder and main contributor to the Bitcoin Security Project (https://bitcoinsecurityproject.org). The project is a free and open source resource that is dedicated to spreading security awareness across the Bitcoin community by helping individual bitcoin holders and businesses follow security best practices. These practices ensure better security of individual holders' investments and Bitcoin business customers. |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/guide.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Guide</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | Professionally, Bojan has performed hundreds of penetration tests, threat modeling, and security code reviews of different applications. These reviews identify vulnerabilities associated with software, the network software, and infrastructure they are deployed on. He also performs research in the field of web application security and teaches developer training on web application best practices, architecture, and security. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/guide/guide_about.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Guide</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''January 2014 Meeting''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/documentation/guide/guide_involved.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Getting Involved</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Summary''': |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| + | This talk will include how organizations build AppSec programs, how to gain Executive and organizational-wide acceptance to your AppSec program and the current trends within the application security industry. |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/documentation/guide/guide_milestones.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Milestones</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | If you have a specific question you would like discussed please just send Rinaldi or Mike McCabe an email and they will try to incorporate it into the talk. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/documentation/guide/guide_downloads.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Downloads</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | Let's help each other start off 2014 strong in implementing your AppSec goals/resolutions! We understand you may have an unique environment but there are common themes between disparate environments. We can learn from the those themes and you can take them to your place of development and apply them accordingly. This discussion will be appealing to developers, project/program managers, application security leads and security professionals. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/guide/guide_news.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Guide News</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | ""Bios"": |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| + | We are going to kick-off the year in a panel format with experts in the industry from the DC area. The panel will include: |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Top Ten</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | • Lee Aber, Director, Information Security at Opower |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| + | • Kevin Greene, Software Assurance Program Manager at DHS S&T |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| + | • Rich Ronston, Director, Security at Deltek |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| + | • Jack Mannino, Chief Security Officer at nVisium & OWASP NoVA Lead [Moderator] |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/commentary.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Commentary</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/documentation/topten/introduction.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Introduction</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''July 2012 Meeting''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/background.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Background</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Topic''': OWASP Top Ten Tools and Tactics |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/updates.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Updates</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Abstract''': If you've spent any time defending web applications as a security analyst, or perhaps as a developer seeking to adhere to SDLC practices, you have likely utilized or referenced the OWASP Top 10. Intended first as an awareness mechanism, the Top 10 covers the most critical web application security flaws via consensus reached by a global consortium of application security experts. The OWASP Top 10 promotes managing risk in addition to awareness training, application testing, and remediation. To manage such risk, application security practitioners and developers need an appropriate tool kit. This presentation will explore tooling, tactics, analysis, and mitigation for each of the Top 10. This discussion is a useful addition for attendees of Security 542: Web App Penetration Testing and Ethical Hacking. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/a1.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>A1 Unvalidated Input</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Bio''': Russ McRee is a senior security analyst, researcher, and founder of holisticinfosec.org, where he advocates a holistic approach to the practice of information assurance. As manager of Microsoft Online Service's Security Incident Management team his focuses are incident response and web application security. He writes toolsmith, a monthly column for the ISSA Journal, and has written for numerous other publications including Information Security, (IN)SECURE, and OWASP. Russ speaks regularly at conferences such as DEFCON, Black Hat, RSA, FIRST, RAID, SecureWorld Expo, as well as ISSA events. IBM's ISS X-Force cited him as the 6th ranked Top Vulnerability Discoverers of 2009. Additionally, Russ volunteers as a handler for the SANS Internet Storm Center (ISC). |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/a2.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>A2 Broken Access Control</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''8:15-9:15 Speaker''': Kevin Johnson |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/a3.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>A3 Broken Authentication</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Topic''': Ninja Assessments: Stealth Security Testing for Organizations |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/a4.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>A4 Cross Site Scripting</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Abstract''': Organizations today need to be able to easily integrate security testing within their existing processes. In this talk, Kevin Johnson of Secure Ideas will explore various techniques and tools to help organizations assess the security of the web applications. These techniques are designed to be implemented easily and with little impact on the work load of the staff. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/a5.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>A5 Buffer Overflows</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Bio''': Kevin Johnson is a security consultant with Secure Ideas. Kevin came to security from a development and system administration background. He has many years of experience performing security services for fortune 100 companies, and in his spare time he contributes to a large number of open source security projects. Kevin's involvement in open-source projects is spread across a number of projects and efforts. He is the founder of many different projects and has worked on others. He founded BASE, which is a Web front-end for Snort analysis. He also founded and continues to lead the SamuraiWTF live DVD. This is a live environment focused on Web penetration testing. He also founded Yokoso and Laudanum, which are focused on exploit delivery. Kevin is a senior instructor for SANS and the author of Security 542: Web Application Penetration Testing and Ethical Hacking. He also presents at industry events, including DEFCON and ShmooCon, and for various organizations, like Infragard, ISACA, ISSA, and the University of Florida. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/a6.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>A6 Injection Flaws</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''May 2012 Meeting''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/a7.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>A7 Improper Error
| |
− | Handling</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Speaker''': Rohit Sethi, Vice President, Product Development, SD Elements |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/a8.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>A8 Insecure Storage</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Topic''': Is There An End to Testing Ourselves Secure? |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/a9.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>A9 Application Denial of
| |
− | Service</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Abstract''': Despite years of research on best practices to integrate security into the early phases of the SDLC, most organizations rely on static analysis, dynamic analysis, and penetration testing as their primary means of eliminating vulnerabilities. This approach leads to discovering vulnerabilities late in the development process, thereby either causing project delays or risk acceptance. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/a10.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>A10 Insecure
| |
− | Configuration Management</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | This talk is an open discussion about the presence, if any, of scalable, measurable, approaches working to address security into the SDLC. Consideration for how Agile development impacts effectiveness will be explored. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/topten/conclusion.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Conclusion</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | Points of discussion include: |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/metrics.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Metrics</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | · Is static analysis sufficient? |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| + | · Developer awareness training |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| + | · Threat modeling / architecture analysis |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| + | · Secure requirements |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| + | · Considerations for procured applications |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/testing.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Testing</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Bio''': Rohit Sethi is a specialist in building security controls into the software development life cycle (SDLC). Rohit is a SANS course developer and instructor on Secure J2EE development. He has spoken and taught at FS-ISAC, RSA, OWASP, Shmoocon, CSI National, Sec Tor, Infosecurity New York and Toronto, TASK, the ISC2's Secure Leadership series conferences, and many others. Mr. Sethi has written articles for Dr. Dobb's Journal, TechTarget, Security Focus and the Web Application Security Consortium (WASC), and he has been quoted as an expert in application security for ITWorldCanada and Computer World. He also leads the OWASP Design Patterns Security Analysis project. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/documentation/testing/commentary.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Commentary</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | Register for the meeting at http://owaspdc.eventbrite.com/ |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/documentation/testing/application.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Web Application
| |
− | Penetration Checklist</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''March 2012 Meeting''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/testing/release.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Release Schedule</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | March 15th at 6:30-7:30pm at LivingSocial's [http://maps.google.com/maps?q=1445+New+York+Avenue+Northwest,+Washington+D.C.,+DC&hl=en&sll=37.0625,-95.677068&sspn=44.204685,93.076172&z=16 1445 New York Ave NW] office location on the first floor at the @hungryacademy.<br> |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/appsec_faq.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>AppSec FAQ</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | Please RSVP for the event here: http://owaspdc.eventbrite.com/ |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/documentation/legal.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Legal</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:1.5pt;margin-bottom:0in;
| + | '''Speaker''': Alissa Torres |
− | margin-left:51.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level1 lfo1;
| |
− | tab-stops:list .5in;background:whitesmoke'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:black'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Software</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | '''Topic''': Application Footprinting |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software/dotnet.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>.Net</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | '''Abstract''': Application footprinting is a great skill for forensic examiners (and anyone interested in binary research) because it allows you to marry artifacts in the registry/file creation/time/date stamps with specific applications or user initiated events. Eventually, during the course of an investigation, an examiner is going to run into a "new" problem - one that hasn't previously been experienced/researched by others in the field. Application footprinting is a simple method that examines the interaction of a program with the operating system. The process of footprinting will determine if the application was installed on the system being investigated, what trace evidence exists and how that can be mined. This presentation will include a demo of Active Registry Monitor and its use in tracking changes made to the Windows Registry by an open source ssh client. |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software/labs.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>oLabs</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Bio''': Alissa Torres currently works as a security researcher for KEYW Corporation in Maryland and has 10 years technical expertise in the information technology field. Previously, she was a digital forensic investigator on a government contractor security team. She has extensive experience in information security, spanning government, academic and corporate environments and holds a Bachelor’s degree from University of Virginia and a Master’s from University of Maryland in Information Technology. Alissa taught as an instructor at the Defense Cyber Investigations Training Academy (DCITA), teaching incident response and network basics to security professionals entering the forensics community. In addition, she has presented at various industry conferences and currently holds the following industry certifications: GCFA, CISSP, EnCE. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software/labs/codespy.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>CodeSpy</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''December 2011 Meeting''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software/labs/websphinx.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>WebSphinx</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''The December 21st meeting was held at [http://maps.google.com/maps?q=1445+New+York+Avenue+Northwest,+Washington+D.C.,+DC&hl=en&sll=37.0625,-95.677068&sspn=44.204685,93.076172&z=16 1445 New York Ave NW] (Living Social) in Washington DC.'''<br><br> |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software/labs/cspider.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>C# Spider</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | This location is very close to both the McPherson Square and Metro Center WMATA train stations.<br><br> |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software/labs/phpfilters.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>PHP Filters</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | * Please '''[https://www.regonline.com/owaspdcdecember2011 Register]''' for the meeting. This helps us get a head count for food and beverages |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software/webgoat.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>WebGoat</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | * '''Ken Johnson''' and (maybe) '''Chris Gates''' will speak on the '''New Features in the Web Exploitation Framework (wXf)''' |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software/webgoat/screenshots.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>WebGoat Screenshots</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | * '''Doug Wilson''' and '''Mark Bristow''' will update on current and upcoming events, including AppSecDC 2012 and chapter plans for the next year, including an '''Important Announcement''' for 2012. Don't miss it! |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software/webscarab.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>WebScarab</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| + | '''Location Info''' Please come up to the second floor, we'll just be meeting in the room off the Living Social kitchen area. |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/software/webscarab/faq2.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Frequently asked
| |
− | questions</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:1.5pt;margin-bottom:0in;
| + | '''About our Speakers''' |
− | margin-left:51.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level1 lfo1;
| |
− | tab-stops:list .5in;background:whitesmoke'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:black'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/standards.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Standards</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | :'''Ken Johnson''' |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| + | ::Ken Johnson is a Senior Security Architect for LivingSocial.com responsible for securing mobile applications, web services and web applications. Additionally he is the primary developer of the Web Exploitation Framework (wXf) and contributes to several open source security projects. He lives in Northern Virginia with his lovely wife Tracy and spends his weekends either stuffing his face with Sushi or getting demolished in Call of Duty<br><br> |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/standards/iso17799.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>ISO 17799</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | :'''Chris Gates''' |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| + | ::TBD<br> |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/standards/wass.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>WASS</span></a> <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:1.5pt;margin-bottom:0in;
| + | ::'''Abstract: Updates in wXf''' - Coming Soon<br> |
− | margin-left:51.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level1 lfo1;
| |
− | tab-stops:list .5in;background:whitesmoke'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:black'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/conferences.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>AppSec Conferences</span></a>
| |
− | <o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| + | Our '''September Meeting''' was '''September 29th 6:30pm''' at '''[http://maps.google.com/maps?q=2445+M+Street+NW+Washington,+District+of+Columbia+20037+United+States&oe=utf-8 2445 M Street NW Washington, DC 20037]''' |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/conferences/appsec2006europe.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>AppSec 2006 Europe</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/appsec2006europe/accommodations.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Accommodations</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/appsec2006europe/sponsors.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Sponsors</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/appsec2006europe/schedule.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Conference Schedule</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/appsec2006europe/training.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Training Courses</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/appsec2006europe/callforpapers.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Call For Papers</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/conferences/previous.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Previous Conferences</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/previous/appsec2004nyc.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>AppSec NYC 2004</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/previous/appsec2005europe.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>AppSec Europe 2005</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:6.0pt;margin-bottom:0in;
| |
− | margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level4 lfo1;
| |
− | tab-stops:list 2.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/previous/appsec2005europe/acceuro05.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Accommodations</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:6.0pt;margin-bottom:0in;
| |
− | margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level4 lfo1;
| |
− | tab-stops:list 2.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/previous/appsec2005europe/agendae05.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Agenda</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:6.0pt;margin-bottom:0in;
| |
− | margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level4 lfo1;
| |
− | tab-stops:list 2.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/previous/appsec2005europe/dining.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Conference Dinner</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/previous/appsec2005dc.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>AppSec DC 2005</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:6.0pt;margin-bottom:0in;
| |
− | margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level4 lfo1;
| |
− | tab-stops:list 2.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/previous/appsec2005dc/accommodations.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Accommodations</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:6.0pt;margin-bottom:0in;
| |
− | margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level4 lfo1;
| |
− | tab-stops:list 2.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/previous/appsec2005dc/sponsors.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Sponsors</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:6.0pt;margin-bottom:0in;
| |
− | margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level4 lfo1;
| |
− | tab-stops:list 2.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/previous/appsec2005dc/training.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Training Course</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:6.0pt;margin-bottom:0in;
| |
− | margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level4 lfo1;
| |
− | tab-stops:list 2.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/conferences/previous/appsec2005dc/schedule.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Conference Schedule</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:1.5pt;margin-bottom:0in;
| |
− | margin-left:51.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level1 lfo1;
| |
− | tab-stops:list .5in;background:whitesmoke'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:black'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/local.html"><span style='border:
| |
− | none windowtext 1.0pt;mso-border-alt:none windowtext 0in;padding:0in;
| |
− | text-decoration:none;text-underline:none'>Local Chapters</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/local/rules.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Chapter Guidelines</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/local/resources.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Chapter Resources</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:1.5pt;margin-bottom:0in;
| |
− | margin-left:51.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level1 lfo1;
| |
− | tab-stops:list .5in;background:whitesmoke'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:black'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about.html"><span style='border:
| |
− | none windowtext 1.0pt;mso-border-alt:none windowtext 0in;padding:0in;
| |
− | text-decoration:none;text-underline:none'>About</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about/contact.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Contact</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about/contributions.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Contributions</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about/advertising.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Advertising</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about/foundation.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>How OWASP Works</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about/licenses.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Licenses</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about/licenses/cla.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Contributor Licensing
| |
− | Agreement</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about/membership.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Membership</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about/membership/corporate.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Corporate Members</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/about/membership/educationalmembers.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Educational Members</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about/privacy.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Privacy</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/about/registration.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Registration</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:1.5pt;margin-bottom:0in;
| |
− | margin-left:51.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level1 lfo1;
| |
− | tab-stops:list .5in;background:whitesmoke'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:black'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/papers.html"><span style='border:
| |
− | none windowtext 1.0pt;mso-border-alt:none windowtext 0in;padding:0in;
| |
− | text-decoration:none;text-underline:none'>Papers</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:1.5pt;margin-bottom:0in;
| |
− | margin-left:51.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level1 lfo1;
| |
− | tab-stops:list .5in;background:whitesmoke'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:black'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/international.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>International</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/international/esp.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Español</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:4.5pt;margin-bottom:0in;
| |
− | margin-left:53.25pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level3 lfo1;
| |
− | tab-stops:list 1.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/international/esp/documentacion.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Documentación</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:6.0pt;margin-bottom:0in;
| |
− | margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level4 lfo1;
| |
− | tab-stops:list 2.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/international/esp/documentacion/appsec_faq.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>AppSec FAQ</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:6.0pt;margin-bottom:0in;
| |
− | margin-left:.75in;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level4 lfo1;
| |
− | tab-stops:list 2.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/international/esp/documentacion/testing.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Testing</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:7.5pt;margin-bottom:0in;
| |
− | margin-left:54.75pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level5 lfo1;
| |
− | tab-stops:list 2.5in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Wingdings;
| |
− | mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;color:black'><span
| |
− | style='mso-list:Ignore'>§<span style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a
| |
− | href="http://www.owasp.org/international/esp/documentacion/testing/aplicacion.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Lista de Verificacion
| |
− | para Intrusion en Aplicaciones Web de OWASP</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/international/ita.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Italian</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/international/chinese.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Chinese</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/international/greek.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Greek</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:0in;margin-right:3.0pt;margin-bottom:0in;
| |
− | margin-left:52.5pt;margin-bottom:.0001pt;text-indent:-.25in;mso-list:l4 level2 lfo1;
| |
− | tab-stops:list 1.0in;background:white'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:"Courier New";
| |
− | mso-fareast-font-family:"Courier New";color:black'><span style='mso-list:Ignore'>o<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:black'><a href="http://www.owasp.org/international/jp.html"><span
| |
− | style='border:none windowtext 1.0pt;mso-border-alt:none windowtext 0in;
| |
− | padding:0in;text-decoration:none;text-underline:none'>Japanese</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | <div id=left>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>Main</span><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l8 level1 lfo2;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/rules.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Chapter Guidelines</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l8 level1 lfo2;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/resources.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Chapter Resources</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>USA</span><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/angeles.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Los Angeles</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/boston.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Boston</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/antonio.html"><span
| |
− | style='text-decoration:none;text-underline:none'>San Antonio</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/francisco.html"><span
| |
− | style='text-decoration:none;text-underline:none'>San Francisco</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/nyc.html"><span
| |
− | style='text-decoration:none;text-underline:none'>New York City</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/rochester.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Rochester, New York</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/atlanta.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Atlanta</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/buffalo.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Buffalo, New York</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/charlotte.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Charlotte</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/chicago.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Chicago</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/kansascity.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Kansas City</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/sanjose.html"><span
| |
− | style='text-decoration:none;text-underline:none'>San Jose</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/seattle.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Seattle</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/stlouis.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Saint Louis</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/twincities.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Minneapolis/St. Paul</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/omaha.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Omaha</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/sacramento.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Sacramento</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/madison.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Madison</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/nnj.html"><span
| |
− | style='text-decoration:none;text-underline:none'>New Jersey</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/philadelphia.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Philadelphia</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/washington_va.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Washington DC (Virginia)</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/ohio.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Ohio</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/socal.html"><span
| |
− | style='text-decoration:none;text-underline:none'>SoCal</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/pittsburgh_pa.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Pittsburgh PA Local</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/memphis.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Memphis Tennessee</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/washington.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Washington (Maryland)</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/florida.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Miami/Ft FLauderdale Local
| |
− | Chapter</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/bostonfinancialdist.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Boston-Financial District</span></a>
| |
− | <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l20 level1 lfo3;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/cleveland.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Cleveland</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>Philippines</span><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l10 level1 lfo4;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/manila.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Manila</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>Asia</span><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l16 level1 lfo5;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/hongkong.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Hong Kong SAR</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l16 level1 lfo5;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/singapore.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Singapore</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l16 level1 lfo5;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/tokyo.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Tokyo</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l16 level1 lfo5;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/malaysia.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Malaysia</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l16 level1 lfo5;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/pakistan.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Pakistan</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>MidEast</span><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l18 level1 lfo6;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/israel.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Israel</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l18 level1 lfo6;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/riyadh.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Riyadh</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>Austrailia</span><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l17 level1 lfo7;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/sydney.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Sydney</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l17 level1 lfo7;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/melbourne.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Melbourne</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>South/Central
| |
− | America</span><span style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l2 level1 lfo8;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/panama.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Panama</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l2 level1 lfo8;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/argentina.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Argentina</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l2 level1 lfo8;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/brazil.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Brazil</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l2 level1 lfo8;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/colombia.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Colombia</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l2 level1 lfo8;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/chile.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Chile</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>Mexico</span><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l5 level1 lfo9;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/mexicocity.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Mexico City</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>Europe</span><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/london.html"><span
| |
− | style='text-decoration:none;text-underline:none'>London</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/germany.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Germany</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/vienna.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Austria</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/switzerland.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Switzerland</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/ireland.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Ireland</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/turkey.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Turkey</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/italy.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Italy</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/belgium.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Belgium</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/greece.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Greece</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/netherlands.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Netherlands</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/luxemburg.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Luxemburg</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l11 level1 lfo10;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/spain.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Spain</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>Canada</span><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l12 level1 lfo11;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/toronto.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Toronto</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l12 level1 lfo11;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/winnipeg.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Winnipeg</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l12 level1 lfo11;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/ottawa.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Ottawa</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l12 level1 lfo11;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/vancouver.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Vancouver</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l12 level1 lfo11;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/edmonton.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Edmonton</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>India</span><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l14 level1 lfo12;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/hyderabad.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Hyderabad</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l14 level1 lfo12;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/mumbai.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Mumbai</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l14 level1 lfo12;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/bangalore.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Bangalore</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l14 level1 lfo12;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/kolkata.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Kolkata</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l14 level1 lfo12;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/kerala.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Kerala</span></a> <o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l14 level1 lfo12;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/delhi.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Delhi</span></a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:solid #DDDDDD 1.0pt;mso-border-alt:solid #DDDDDD .75pt;
| |
− | padding:2.0pt 2.0pt 2.0pt 2.0pt;margin-left:3.75pt;margin-top:7.5pt;margin-right:
| |
− | 7.5pt;margin-bottom:7.5pt'>
| |
− | | |
− | <p class=MsoNormal style='background:#F2F2F2'><span style='font-size:8.5pt;
| |
− | font-family:"Lucida Sans Unicode";color:#333333;letter-spacing:.75pt'>Quick
| |
− | Links</span><span style='font-size:8.5pt;font-family:Tahoma;color:#333333'> <o:p></o:p></span></p>
| |
− | | |
− | <div style='mso-element:para-border-div;border-top:solid white 1.0pt;
| |
− | border-left:solid white 1.0pt;border-bottom:none;border-right:none;mso-border-top-alt:
| |
− | solid white .75pt;mso-border-left-alt:solid white .75pt;padding:2.0pt 0in 0in 15.0pt;
| |
− | background:#F9F9F9;margin-left:-.25in;margin-right:0in'>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/documentation/guide.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Guide</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/documentation/topten.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Top Ten</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/documentation/testing.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Testing</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/documentation/appsec_faq.html"><span
| |
− | style='text-decoration:none;text-underline:none'>AppSec FAQ</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/documentation/legal.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Legal</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/software/dotnet.html"><span
| |
− | style='text-decoration:none;text-underline:none'>.Net</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/software/webgoat.html"><span
| |
− | style='text-decoration:none;text-underline:none'>WebGoat</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/software/webscarab.html"><span
| |
− | style='text-decoration:none;text-underline:none'>WebScarab</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/software/validation.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Validation</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/standards/iso17799.html"><span
| |
− | style='text-decoration:none;text-underline:none'>ISO 17799</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/standards/wass.html"><span
| |
− | style='text-decoration:none;text-underline:none'>WASS</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/conferences/appsec2006europe.html"><span
| |
− | style='text-decoration:none;text-underline:none'>AppSec 2006 Europe</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/conferences/previous.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Previous Conferences</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/local/denmark.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Denmark</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/about/membership.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Membership</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/about/membership/corporate.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Corporate Members</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a
| |
− | href="http://www.owasp.org/about/membership/educationalmembers.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Educational Members</span></a><o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:1.5pt;margin-right:0in;margin-bottom:1.5pt;
| |
− | margin-left:.25in;text-indent:-.25in;mso-list:l7 level1 lfo13;tab-stops:list .5in;
| |
− | background:#F9F9F9;border:none;mso-border-top-alt:solid white .75pt;mso-border-left-alt:
| |
− | solid white .75pt;padding:0in;mso-padding-alt:2.0pt 0in 0in 15.0pt'><![if !supportLists]><span
| |
− | style='font-size:10.0pt;mso-bidi-font-size:8.5pt;font-family:Symbol;mso-fareast-font-family:
| |
− | Symbol;mso-bidi-font-family:Symbol;color:#333333'><span style='mso-list:Ignore'>·<span
| |
− | style='font:7.0pt "Times New Roman"'>
| |
− | </span></span></span><![endif]><span style='font-size:8.5pt;font-family:Tahoma;
| |
− | color:#333333'><a href="http://www.owasp.org/about/privacy.html"><span
| |
− | style='text-decoration:none;text-underline:none'>Privacy</span></a><o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <p class=MsoNormal align=center style='margin-bottom:12.0pt;text-align:center'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'>Corporate Members <br>
| |
− | <br>
| |
− | <a href="http://www.aamc.org/" id=AAMC border=0><span style='text-decoration:
| |
− | none;text-underline:none'><img border=0 width=104 height=45 id="_x0000_i1027"
| |
− | src="../../../../../Desktop/washington_files/aamcsymbol.gif"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.accessitgroup.com/" id="Access IT Group" border=0><span
| |
− | style='text-decoration:none;text-underline:none'><img border=0 width=130
| |
− | height=42 id="_x0000_i1028"
| |
− | src="../../../../../Desktop/washington_files/AITG-OWASP.gif"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.ascure.com/" id=Ascure border=0><span style='text-decoration:
| |
− | none;text-underline:none'><img border=0 width=65 height=40 id="_x0000_i1029"
| |
− | src="../../../../../Desktop/washington_files/Ascure_logo.jpg"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.aspectsecurity.com/" id="Aspect Security" border=0><span
| |
− | style='text-decoration:none;text-underline:none'><img border=0 width=150
| |
− | height=37 id="_x0000_i1030"
| |
− | src="../../../../../Desktop/washington_files/aspect_logo.gif"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.deloitte.co.za/" id=Deloitte border=0><span
| |
− | style='text-decoration:none;text-underline:none'><img border=0 width=115
| |
− | height=22 id="_x0000_i1031"
| |
− | src="../../../../../Desktop/washington_files/Deloitte-logo.gif"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.f5.com/" id=F5 border=0><span style='text-decoration:none;
| |
− | text-underline:none'><img border=0 width=57 height=54 id="_x0000_i1032"
| |
− | src="../../../../../Desktop/washington_files/f5_50px.jpg"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.fidelity.com/" id=Fidelity border=0><span style='text-decoration:
| |
− | none;text-underline:none'><img border=0 width=115 height=32 id="_x0000_i1033"
| |
− | src="../../../../../Desktop/washington_files/Fdelity_logo.gif"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.foundstone.com/" id=Foundstone border=0><span
| |
− | style='text-decoration:none;text-underline:none'><img border=0 width=115
| |
− | height=39 id="_x0000_i1034"
| |
− | src="../../../../../Desktop/washington_files/foundstone.png"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.securesoftware.com/" id="Secure Software Logo" border=0><span
| |
− | style='text-decoration:none;text-underline:none'><img border=0 width=126
| |
− | height=43 id="_x0000_i1035"
| |
− | src="../../../../../Desktop/washington_files/SS_logo.gif"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.unisys.com/" id="Unisys logo" border=0><span
| |
− | style='text-decoration:none;text-underline:none'><img border=0 width=148
| |
− | height=61 id="_x0000_i1036"
| |
− | src="../../../../../Desktop/washington_files/Unisyslogo.gif"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.visa.com/" id=Visa border=0><span style='text-decoration:
| |
− | none;text-underline:none'><img border=0 width=104 height=35 id="_x0000_i1037"
| |
− | src="../../../../../Desktop/washington_files/visa.gif"></span></a><br>
| |
− | <br>
| |
− | <a href="http://www.zionsecurity.com/index.php?id=30" id="Zion Security"
| |
− | border=0><span style='text-decoration:none;text-underline:none'><img border=0
| |
− | width=150 height=37 id="_x0000_i1038"
| |
− | src="../../../../../Desktop/washington_files/zion_150_37.jpg"></span></a><br>
| |
− | <br>
| |
− | Educational Members <br>
| |
− | <br>
| |
− | <a href="http://www.clusit.it/" id=Clusit border=0><span style='text-decoration:
| |
− | none;text-underline:none'><img border=0 width=120 height=63 id="_x0000_i1039"
| |
− | src="../../../../../Desktop/washington_files/clusit_logo_b130.gif"></span></a><o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='margin-left:123.75pt' id=body>
| |
− | | |
− | <div style='margin-top:6.0pt;margin-right:4.5pt;margin-bottom:4.5pt'
| |
− | id=breadcrumb>
| |
− | | |
− | <p class=MsoNormal><span style='font-size:8.5pt;font-family:Tahoma;color:#CCCCCC'><a
| |
− | href="http://www.owasp.org/index.html">Main</a>><a
| |
− | href="http://www.owasp.org/local.html">Local Chapters</a>><a
| |
− | href="http://www.owasp.org/local/washington.html">Washington (Maryland)</a> <o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | <p class=MsoNormal style='margin-top:3.0pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:2'><b><span style='font-size:10.5pt;
| |
− | font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'>Welcome to the OWASP
| |
− | Washington, DC-Maryland Local Chapter <o:p></o:p></span></b></p> | |
− | | |
− | <p style='margin-bottom:12.0pt'><span style='font-size:8.5pt;line-height:150%;
| |
− | font-family:Tahoma;color:#333333'>The original DC Chapter was founded in June
| |
− | | |
− | members from Virginia to Delaware. In April 2005 a new chapter, DC-Virginia,
| |
− | was formed and the DC Chapter was renamed to DC-Maryland. The two are sister
| |
− | chapters with common members and shared discourse. The chapters meet in
| |
− | opposite halves of the month to facilitate this relationship.<br>
| |
− | <br>
| |
− | Chapter meetings are held several times a year, typically in the offices of our
| |
− | sponsor. Please subscribe to the <a
| |
− | href="http://lists.sourceforge.net/lists/listinfo/owasp-washington/">mailing
| |
− | list</a> for meeting announcements. <br>
| |
− | <br>
| |
− | Our chapter is sponsored by <a href="http://www.aspectsecurity.com/">Aspect
| |
− | Security</a>.<o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='margin-top:3.0pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:2'><b><span style='font-size:10.5pt;
| |
− | font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'>Participation <o:p></o:p></span></b></p>
| |
− | | |
− | <p><span style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>OWASP
| |
− | Local Chapter meetings are free and open. Our chapter's meetings are informal
| |
− | and encourage open discussion of all aspects of application security. Anyone in
| |
− | our area interested in web application security is welcome to attend. We
| |
− | encourage attendees to give short presentations about specific topics. If you
| |
− | would like to make a presentation, or have any questions about the DC-Maryland
| |
− | | |
− | | |
− | <br>
| |
| <br> | | <br> |
− | Between meetings we keep the discussion going via mailing list. To join our
| |
− | chapter mailing list, visit our <a
| |
− | href="http://lists.sourceforge.net/lists/listinfo/owasp-washington/">mailing
| |
− | list</a> page. List membership is kept private.<o:p></o:p></span></p>
| |
| | | |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| + | '''Speakers'''<br> |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
| | | |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| + | * '''John Steven''' will speak on '''Assessing your Assessment Practice''' |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| + | * '''Krystal Moon''' and '''Quang Pham''' will speak on '''DHS Software Assurance Pocket Guides''' |
− | border=0 width=16 height=16 id="_x0000_i1040"
| + | * '''Doug Wilson''' and '''Mark Bristow''' will update on current and upcoming events. |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><span
| |
− | style='mso-field-code:" HYPERLINK \0022\0022 "'><span class=MsoHyperlink><span
| |
− | style='font-family:Tahoma'>Meeting: March 23rd</span></span></span> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | '''About our Speakers''' |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| + | :'''John Steven''' |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Thu Feb 16 15:41:45
| |
− | EST 2006 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | ::John Steven is the Senior Director, Advanced Technology Consulting at Cigital with over a decade of hands-on experience in software security. John's expertise runs the gamut of software security from threat modeling and architectural risk analysis, through static analysis (with an emphasis on automation), to security testing. As a consultant, John has provided strategic direction as a trusted advisor to many multi-national corporations. John's keen interest in automation keeps Cigital technology at the cutting edge. He has served as co-editor of the Building Security In department of IEEE Security & Privacy magazine, speaks with regularity at conferences and trade shows, and is the leader of the Northern Virginia OWASP chapter. John holds a B.S. in Computer Engineering and an M.S. in Computer Science both from Case Western Reserve University. |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>March Meeting
| |
− | Announcement<o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><br>
| |
− | <br>
| |
− | Our next meeting is on Thursday March 23rd at 1800 hours in the offices of
| |
− | Aspect Security. <br>
| |
− | <br>
| |
− | This is going to be a technical meeting focusing on AJAX Security. <br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | In case you weren't aware, AJAX is a clever use of existing technologies to
| |
− | provide richer interfaces on the web (think Google Maps). It's growing in
| |
− | popularity and "buzz", so be sure to make this meeting and learn all
| |
− | you can about it. <br>
| |
− | <br>
| |
− | If you have some AJAX science you'd like to drop on us, then email me directly
| |
− | at mfisher at spidynamics dot com <br>
| |
− | <u><br>
| |
− | The Agenda:</u><br>
| |
− | <br>
| |
− | <br>
| |
− | 1. Opening, introductions<br>
| |
− | <br>
| |
− | 2. Presentation by Rick Pries: An introduction to AJAX <br>
| |
− | <br>
| |
− | 3. Overview and Review of the new OWASP AJAX Security Guide <br>
| |
− | <br>
| |
− | 4. BoF discussion on AJAX and AJAX security <br>
| |
− | <br>
| |
− | 5. Everything Else: Current Events, OWASP news, Industry News, Recent Hacks in
| |
− | the News, Closing, etc. <br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | <u>Food:</u><br>
| |
− | <br>
| |
− | As usual, geek food will be provided. This usually means pizza and soda. <br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | <u>Getting there</u><br>
| |
− | <br>
| |
− | <br>
| |
− | Aspect is located at 9175 Guilford Road (Suite 300) in Columbia. Driving
| |
− | directions are: <br>
| |
− | <br>
| |
− | <br>
| |
− | From I-95: <br>
| |
− | <br>
| |
− | <br>
| |
− | Exit 38 B : Rt. 32 West towards Columbia (1.5 miles)<br>
| |
− | <br>
| |
− | Take the Broken Land Parkway exit <br>
| |
− | <br>
| |
− | Turn left off the ramp onto Broken Land Parkway<br>
| |
− | <br>
| |
− | Turn left at the light onto Guilford Road (0.5 miles)<br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | After a sharp left, enter the parking lot at 9175 Guilford Road. [Note: if you
| |
− | go under the bridge, you've gone too far]<br>
| |
− | <br>
| |
− | We're on the third floor in Suite 300<br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | <br>
| |
− | Unfortunatley being out in the far 'burbs there is very limited public
| |
− | transport. <br>
| |
− | <br>
| |
− | If you need help getting to the meeting, try emailing the list at:
| |
− | | |
− | <br>
| |
− | There are two MARC stations within a twenty minute drive, and the MTA
| |
− | contracted commuter busses drop off within 2 miles of the offices. <br>
| |
− | <br>
| |
− | <u>Wireless</u><br>
| |
− | <br>
| |
− | <br>
| |
− | I am please to announce that we may just have wireless access for the meeting.
| |
− | No promises, but if you're the type who likes to look stuff up realtime then
| |
− | you may want to bring the laptop. <br>
| |
| <br> | | <br> |
− | If we *are* lucky to enough to get wireless access, there will be a serious
| |
− | "no playing around" policy in place, and anyone breaking it will be
| |
− | kick/banned for life, y'all hear ? <o:p></o:p></span></p>
| |
− |
| |
− | </div>
| |
| | | |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| + | ::'''Abstract: Assessing your Assessment Practice''' - Years ago, organizations embraced Penetration Testing to find vulnerabilities in their applications. Later, vulnerabilities remained and many added a Source Code Review practice, often supported by commercial tooling. Others possess "Holistic Assessment" schemes which combine techniques in hopes of finding an even broader range of vulnerabilities their applications may possess.Years into what most consider maturation, organizations continue to let crippling vulnerability into production despite costly assessment. What's going on? |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
| | | |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| + | ::In this presentation, we'll consider assessment practices of various shapes and sizes focusing on particularly interesting Fortune 100 companies (assessing 300-1000 apps / year) as well as the single-man-shop. We'll discuss assessment coverage (code and vulnerability), cost, and measures of remediation. |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1041"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">December Meeting Notes</a> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | ::Next, we'll discuss what methodological, tool-based, measurement, and other techniques can dramatically improve cost, coverage, or successful remediation in your assessment practice. |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Sat Dec 24 09:54:05
| |
− | EST 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>[Note:
| |
− | there was no meeting in November due to the holiday crunch. We decided to hold
| |
− | just one meeting in December]. <br>
| |
− | <br>
| |
− | Greetings from the Northern side of the Beltway. I wanted to send out a note to
| |
− | everyone letting them know how great the meeting was last night. The turn out
| |
− | was the perfect size for some "fireside chats".... It was some of the
| |
− | most technical conversation I've had in a long time that didn't involve an
| |
− | instant messenging client. <br>
| |
− | <br>
| |
− | First of all, Thanks again to the ever-generous Aspect Security whom provided
| |
− | not only meeting space, but pizza and a chaperone as well. I'm glad to say that
| |
− | Chuck was there too .. Chuck is one of our most highly technical meetings, and
| |
− | shows up every time, on time. <br>
| |
− | <br>
| |
− | For those of you who didn't make it, here's what we discussed. Note that I said
| |
− | *discussed*; not presentations. The smaller size of this meeting really
| |
− | afforded some great technical conversation and the loose interactive format was
| |
− | spectacular. If you missed it , well then you missed out. <br>
| |
− | --------------------------------------------------------------------------------------------------<br>
| |
− | 1. Susan Suskin gave us her thoughts on the AppSec conference for those you who
| |
− | missed the conference. Apparently the majority of the conference rocked, except
| |
− | for some lam3r presentation on web application worms (mine) . <br>
| |
− | <br>
| |
− | 2. NIST's SAMATE project. This is a government funded project that attempts to
| |
− | a) gain serious expertise in app sec to the point of being able to 2) define
| |
− | key performance capabilities of app sec tools, 3) define metrics for those
| |
− | capabilities, 4) create test environments against those metrics, and then 5)
| |
− | evaluate and report on all app sec tools. Discussion of this spun off of the
| |
− | discussion of the conference. <br>
| |
− | <br>
| |
− | 3. **The recent GMail hack**. This was really well done (props Andre ) .
| |
− | Instead of doing a *presentation* on it, shots from the original 'explanation'
| |
− | site was passed around and we all deciphered it together, making a true
| |
− | learning and discussion opportunity. Unfortunately this also mitigated our
| |
− | ability to mock his lamer slides, but I secretly mocked his lamer xeroxing
| |
− | capabilities. I'm just kidding of course: Andre xerox's like a champ. I think
| |
− | he's certified in it or something. <br>
| |
− | <br>
| |
− | 4. **A Tutorial Walk-Through of SQL Injection and Blind SQL Injection** along
| |
− | with *nasty evasive destructive SQL Injections*, followed by the Web App Sec
| |
− | comedy hour. Those of you who missed the AppSec conference and also missed the
| |
− | meeting last night missed all the humour. Plus, you'll never understand how
| |
− | astute Donald Rumsfeld is with input validation. [ If you read this far, then
| |
− | you get an extra slice of pizza next meeting ]. My next presentation will be
| |
− | stone-cold serious, but equally lame. My presentations should improve once I
| |
− | finish my PowerPoint certification study class. <br>
| |
− | <br>
| |
− | 5. ShmooCon ! The coolest conference you'll find in the area. Be there are be
| |
− | square. http://www.shmoocon.org/<br>
| |
− | If you are already registered for the conference and aren't staying at the
| |
− | Wardman, , then please consider booking a room - they need this to lock in the
| |
− | hotel for next year. I'm local, and I have a room !<br>
| |
− | <br>
| |
− | 6. **AJAX** - what it is, what is isn't, who's using it, how it works, and the
| |
− | security implications of it. We all agreed that none of us know enough about it
| |
− | and we're looking for someone with some real expertise to educate us on it. I
| |
− | for one am willing to chip in some bucks for a serious education on it. If we
| |
− | all chipped in, we may be able to get someone to give us a couple hours of
| |
− | tutorial on it. Thoughts ? <br>
| |
− | <br>
| |
− | <br>
| |
− | ---------------------------------------------------------------<br>
| |
− | <br>
| |
− | <br>
| |
− | Next Meeting: <br>
| |
− | <br>
| |
− | For our next gig, we're trying to get none other than a Special Agent from the
| |
− | Federal Bureau of Investigations to talk to us about the real world legal and
| |
− | prosecutorial environment in relations to cyber intrusions. We will also
| |
− | discuss the latest and greatest hacks, vulns and exploit techniques. <br>
| |
− | <br>
| |
− | We'd like to see if there's a way to get internet access for the attendees as
| |
− | well. For instance, last night we really could have used a Spanish L33t to
| |
− | English L33t Dictionary while deciphering the Gmail hack. It would be great for
| |
− | doing quick googles, demo's etc. If there are any ideas on how we could secure
| |
− | some wireless that would not place us on the host's network, then please bring
| |
− | it. Netstumbling the office doesn't count. <br>
| |
− | <br>
| |
− | So now you know, and knowing's half the battle. <br>
| |
| <br> | | <br> |
− | - Matt<o:p></o:p></span></p>
| |
− |
| |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| |
− | margin-bottom:3.75pt'>
| |
− |
| |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
− |
| |
− | </div>
| |
− |
| |
− | </div>
| |
− |
| |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
− |
| |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1042"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="https://portal.%20owasp.org:8443/local/washington.html">Tuesday October
| |
− | 25th OWASP Meeting Agenda</a> <o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Mon Oct 24 17:49:45
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| + | :'''Krystal Moon''' |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>The
| |
− | next OWASP DC chapter meeting will be held Tuesday, October 25th at 6pm. The
| |
− | meeting will be held in Aspect Security's office in Columbia MD.<o:p></o:p></span></p>
| |
| | | |
− | <blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'>
| + | :: Krystal Moon is a Cyber Security Analyst at SRA International, Inc. She currently supports the Department of Homeland Security Software Assurance Program where one of her tasks is co-authoring the Secure Coding Pocket Guide. Previously, she provided certification and accreditation support for various government agencies. She completed her Bachelor of Science in IT with a concentration in Information Security and Master of Science in Applied IT at George Mason Univeristy. |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| + | :'''Quang Pham''' |
− | font-family:Tahoma;color:#333333'><br>
| |
− | <b>Aspect Security, Inc.</b><br>
| |
− | 9175 Guilford Road, Suite 300<br>
| |
− | Columbia, MD 21046-2565<br>
| |
− | Main: 301-604-4882<br>
| |
− | Fax: 443.583.0772<o:p></o:p></span></p>
| |
| | | |
− | </blockquote>
| + | :: Quang Pham is a Cyber Security Analyst at SRA International, INC. At SRA, Quang is supporting the Department of Homeland Security’s Software Assurance (SwA) program. One of his roles in the support of the SwA program is to co-author the “Architecture and Design Considerations for Secure Software” Pocket Guide and the “Requirements and Analysis for Secure Software” Pocket Guide. Quang has a Bachelor’s in Computer Engineering and Electrical Engineering at Penn State and has been at SRA for 9 months. |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><br>
| |
− | <br>
| |
− | Directions: <a href="http://www.aspectsecurity.com/contact.html">http://www.aspectsecurity.com/contact.html</a><br>
| |
| <br> | | <br> |
− | <br>
| |
− | <br>
| |
− | <b>Meeting Agenda</b><br>
| |
− | <br>
| |
− | 6:00pm – Initial Meeting kickoff<br>
| |
− | 6:30pm – Special Guest Presentation (Steve Elky, see below for more
| |
− | information)<br>
| |
− | 7:15pm – Pizza / General Discussion<br>
| |
− | 7:30pm – Discussion on AppSecDC 2005 (Jeff Williams will be presenting)<br>
| |
− | 8:15pm – Discussion on Myspace.com “worm”<br>
| |
− | <br>
| |
− | <br>
| |
− | <b>Special Guest Presentation</b><br>
| |
− | <br>
| |
− | This week we have a special guest speaker Steve Elky. Steve will be discussing
| |
− | the incorporation of security and Certification and Accreditation into the
| |
− | Software Development Life Cycle. A brief overview of the presentation is below.
| |
− | <br>
| |
− | <br>
| |
− | Certification and accreditation (C&A) mandate<br>
| |
− | Certification<br>
| |
− | Accreditation<br>
| |
− | C&A and the Software Development Life Cycle (SDLC)<br>
| |
− | Initiation<br>
| |
− | Development/Acquisition<br>
| |
− | Implementation<br>
| |
− | Operations/Maintenance<br>
| |
− | Disposal<br>
| |
− | Key Roles<br>
| |
− | Independent Approach to C&A<br>
| |
− | Integrated Approach to C&A<br>
| |
− | <br>
| |
− | <b>About Steve Elky</b><br>
| |
− | <br>
| |
− | Steve Elky is the Technical Director for Information Security at Software
| |
− | Performance Systems, a software company specializing in e-government solutions.
| |
− | Mr. Elky has his CISSP, CISM, ISSAP, ISSMP, MCSE, CNE, GCNT, CCNA and CCSA as
| |
− | well as a B.S. from the University of Baltimore. Mr. Elky acts as a security
| |
− | advisor to various company clients as well as helping company developers
| |
− | determine and meet security requirements. Mr. Elky is currently assisting the
| |
− | Library of Congress in the design and implementation of their security program.<br>
| |
− | <br>
| |
− | <br>
| |
− | <b>Discussion and review of AppSecDC 2005</b><br>
| |
− | <br>
| |
− | Jeff Williams will be reviewing and discussing the happenings of AppSecDC 2005
| |
− | for those of us who were not able to attend the conference. <br>
| |
− | <br>
| |
− | <br>
| |
− | <b>Discussion on Myspace.com “worm”</b><br>
| |
− | <br>
| |
− | If time permits we will be reviewing the recent myspace.com “worm”,
| |
− | both at a technical level as well as a higher level conceptual view including
| |
− | “what if” scenarios. <o:p></o:p></span></p>
| |
| | | |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| + | ::'''Abstract: Software Assurance Pocket Guides''' - The Software Assurance (SwA) Pocket Guide Series comprises free, downloadable documents on software assurance in acquisition and outsourcing, software assurance in development, the software assurance life cycle, and software assurance measurement and information needs. SwA Pocket Guides are developed collaboratively by the SwA Forum and Working Groups, which function as a stakeholder community that welcomes additional participation in advancing and refining software security. The Pocket Guides are offered as informative use only and a good starting point for the relevant practices. |
− | margin-bottom:3.75pt'>
| |
| | | |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| + | :::'''Secure Coding''' |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="https://portal.%20owasp.org:8443/local/washington.html">Read</a><o:p></o:p></span></p>
| |
| | | |
− | </div>
| + | :::Secure coding is a prerequisite for producing robustly secure software. The development of secure software is a complex endeavor and requires a systematic process. The most commonly exploited vulnerabilities are seemingly easily avoided defects in software. Producing secure code is not an absolute science because it depends on a wide range of variables, some of which cannot be easily or accurately measured. Such variables range from the language or platform being used to the nature of the software being developed or the data with which the software is meant to work. This guide does not prescribe answers for all possible situations. Rather, it discusses fundamental practices for secure coding, and lists resources that provide more information about these practices. Using these resources, practitioners can write more secure code for their particular environment. |
| | | |
− | </div>
| + | :::'''Architecture and Design Considerations for Secure Software''' |
| | | |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| + | :::The Guide to the Software Engineering Body of Knowledge (SWEBOK) defines the design phase as both "the process of defining the architecture, components, interfaces, and other characteristics of a system or component" and "the result of [that] process." The software design phase is the software engineering life cycle activity where software requirements are analyzed in order to produce a description of the software’s internal structure that will serve as the basis for its implementation. The software design phase consists of the architectural design and detailed design activities. These activities follow software requirements analysis phase and precedes the software implementation the Software Development Life Cycle (SDLC). This volume of the pocket guide compiles architecture and design software techniques for security and offers guidance on when they should be employed during the SDLC. |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
| | | |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span | + | Facility Sponsor: <!-- Currently Open -->Anonymous Refreshment Sponsor: {{MemberLinks|link=http://www.bluecanopy.com|logo=BlueCanopySponsoLogo.jpg}}<!-- {{MemberLinks|link=http://www.securicon.com|logo=Securicon.gif}} --> |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1043"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Next Meeting - Tuesday,
| |
− | September 27 @6pm</a> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Tue Sep 20 23:50:34
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin-top:3.75pt;margin-right:3.75pt;margin-bottom:
| |
− | 12.0pt;margin-left:3.75pt;line-height:150%;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>Everyone
| |
− | is welcome to join us at our monthly chapter meeting. It's held on the fourth
| |
− | Tuesday of each month at 6pm. If you have any items you'd like others to talk
| |
− | about, or if you'd like to make a presentation, post your ideas to our <a
| |
− | href="http://lists.sourceforge.net/lists/listinfo/owasp-washington/">mailing
| |
− | list</a> or send an email to <a href="mailto:[email protected]">Ed Tracy</a>.<o:p></o:p></span></p> | |
− |
| |
− | <p class=MsoNormal style='margin-top:3.0pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'>OWASP
| |
− | DC-Maryland Chapter Meeting<o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin-bottom:12.0pt;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><br>
| |
− | The Open Web Application Security Project, DC-Maryland Chapter holds meetings
| |
− | on the fourth Tuesday of each month.<br style='mso-special-character:line-break'>
| |
− | <![if !supportLineBreakNewLine]><br style='mso-special-character:line-break'>
| |
− | <![endif]><o:p></o:p></span></p>
| |
− |
| |
− | <p class=MsoNormal style='margin-top:3.0pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'>LOCATION:<o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin-bottom:12.0pt;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><br>
| |
− | <a href="http://www.sourcefire.com/">SOURCEfire</a><br>
| |
− | <a
| |
− | href="http://maps.google.com/maps?q=9770+Patuxent+Woods+Drive,Columbia,+MD&ll=39.178528,-76.850980&spn=0.030334,0.056793&hl=en">9770
| |
− | Patuxent Woods Drive<br>
| |
− | Columbia, MD</a><br>
| |
− | (Meeting may be in rear building, 9780.)<o:p></o:p></span></p>
| |
− |
| |
− | <p class=MsoNormal style='margin-top:3.0pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'>AGENDA:<o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><br>
| |
| <br> | | <br> |
− | The agenda for this month's meeting is:<o:p></o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l15 level1 lfo14;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Meet & Greet(6pm)<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l15 level1 lfo14;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>PIZZA<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l15 level1 lfo14;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Group Presentation (7pm)<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l15 level2 lfo14;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Jeff Williams presents the
| |
− | OWASP Guide 2.0<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l15 level1 lfo14;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Top Ten feedback survey - Help
| |
− | us test the survey before it's used at the October OWASP conference.<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><br>
| |
− | See you there! <o:p></o:p></span></p>
| |
− |
| |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| |
− | margin-bottom:3.75pt'>
| |
− |
| |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
− |
| |
− | </div>
| |
| | | |
− | </div>
| + | '''August 2011 Meeting''' |
| | | |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| + | Our next meeting is August 24th at [http://maps.google.com/maps?q=1445+New+York+Avenue+Northwest,+Washington+D.C.,+DC&hl=en&sll=37.0625,-95.677068&sspn=44.204685,93.076172&z=16 1445 New York Ave NW] (Living Social) in Washington DC. |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
| | | |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| + | Refreshments will be served starting at 6:30 PM, with the presentation starting around 7. |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1044"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 7/19/05</a> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | This location is very close to both the McPherson Square and Metro Center WMATA train stations.<br> |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Wed Aug 10 16:43:08
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>At
| |
− | the July 19th meeting, the DC-Maryland chapter took on the topic of the
| |
− | "broken top-ten". We spent 2 and a half hours and digressed many times.
| |
− | Often getting lost in the weeds. We did have some useful ideas (I do apologize
| |
− | to the rest of the chapter as these thoughts are largely influenced by my
| |
− | opinions -ed tracy).<br>
| |
− | <br>
| |
− | After discussing the problems with the many uses of the top ten, we asked what
| |
− | does the industry need. The industry needs awareness and guidance. These are
| |
− | two different things. We will admit it has been great for awareness, aka
| |
− | marketing. And, a concern of changing the top ten is given: a radical change in
| |
− | the top ten is likely to diminish its reputation and its effectiveness at
| |
− | raising awareness.<br>
| |
− | <br>
| |
− | Now back to guidance (the other thing the industry needs)...The top ten is
| |
− | being used for education, security review checklist, design/implementation
| |
− | guide, etc. Well, the industry needs these things in very concise form. We
| |
− | should give them that. OWASP<br>
| |
− | should produce these (I know some of it's been produced already). These
| |
− | shouldn't be top tens or marketed as top tens, as ten is not going to cover<br>
| |
− | everything and having ten top-tens is silly.<br>
| |
| <br> | | <br> |
− | The key is to put a big disclaimer in The top ten that advises people not to
| |
− | use it for review checklist, design guide, etc. The disclaimer should go on to
| |
− | point people in the right direction for guidance for<br>
| |
− | each of those tasks. We believe the top ten should warn people that it's not
| |
− | fit for those other tasks. Otherwise, they think it is and that creates
| |
− | "FUD."<o:p></o:p></span></p>
| |
− |
| |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| |
− | margin-bottom:3.75pt'>
| |
| | | |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| + | * Please '''[http://www.regonline.com/Register/Checkin.aspx?EventID=1003187 REGISTER HERE]''' if you are going to attend so we have an accurate head count. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| + | * Julian Cohen will speak on '''Cross-Origin Resource Inclusion in HTML5''' |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| + | * Doug Wilson & Mark Bristow will update on current and upcoming events. |
| | | |
− | </div>
| + | '''About our Speaker''' |
| + | :'''Julian Cohen''' |
| | | |
− | </div>
| + | ::Julian is a security researcher from New York City. When he isn't explaining different vulnerability classes to developers, Julian spends his time finding bugs and studying exploitation techniques. He has previously done information security work for two consulting companies, a defense contractor, a public utility and a handful of web startups, but he still hasn't found the job he's really looking for. |
| | | |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| + | ::Julian runs NYU Poly's world-renowned CSAW CTF competition. In his downtime, Julian writes technical articles for a number of security blogs and participates in CTF competitions around the world. |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
| | | |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| + | :'''Abstract''' |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1045"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Training Session Notes -
| |
− | 6/7/05</a> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | ::'''Cross-Origin Resource Inclusion in HTML5''' - Cross-Origin Resource Inclusion is an HTML5 vulnerability that takes advantage of Cross-Origin Resource Sharing to bypass Same-Site Origin Policy with XMLHttpRequest objects. This talk will cover Web 2.0 application design trends that allow for this vulnerability to be exploitable. Basic concepts that are necessary for Cross-Origin Resource Sharing to exist will be covered throughly and w3c specifications will be cited. An example web application will be used to demonstrate how this functionality is used today, how it can be implemented improperly (and properly) and how it can be exploited by a malicious attacker. |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Tue Jun 21 13:42:22
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>We
| |
− | held a training session for web app security in early June. About 15 people
| |
− | trickled in at all hours.<br>
| |
− | <br>
| |
− | Thanks Aspect Security, for providing installation CDs with WebGoat, WebScarab,
| |
− | and Paros. <br>
| |
− | <br>
| |
− | As a group, we did some of the WebGoat exercises using the WebScarab
| |
− | application proxy.<br>
| |
− | <br>
| |
− | Thanks to Chuck for demonstrating bean scripting in WebScarab. It's used to
| |
− | automate testing.<br>
| |
− | <br>
| |
− | Thanks to Matt Fisher for demonstrating Spi Dynamics' WebInspect and its web
| |
− | proxy capabilities.<br>
| |
| <br> | | <br> |
− | The session was held at:<o:p></o:p></span></p>
| |
− |
| |
− | <blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'>
| |
− |
| |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><a href="http://www.sourcefire.com/">SOURCEfire</a><br>
| |
− | 9770 Patuxent Woods Drive<br>
| |
− | Columbia, MD<o:p></o:p></span></p>
| |
− |
| |
− | </blockquote>
| |
− |
| |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| |
− | margin-bottom:3.75pt'>
| |
− |
| |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
− |
| |
− | </div>
| |
− |
| |
− | </div>
| |
− |
| |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
− |
| |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1046"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 5/24/05</a> <o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Wed Aug 10 16:17:32
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| + | Facility Sponsor: [http://www.livingsocial.com Living Social] Refreshment Sponsor: [http://www.livingsocial.com Living Social] [http://www.stratumsecurity.com Stratum Security] |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>Thanks
| |
− | to Weilin Zhong for running this meeting. <br>
| |
− | <br>
| |
− | Weilin led a discussion about security for Web Services. As of mid-august,
| |
− | someone is still trying to sanitize the presentation she gave so that it can be
| |
− | published here.<br>
| |
− | <br>
| |
− | The meeting was held at:<o:p></o:p></span></p>
| |
| | | |
− | <blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'> | + | <br><br> |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| + | '''July 2011 Meeting''' |
− | font-family:Tahoma;color:#333333'><a href="http://www.sourcefire.com/">SOURCEfire</a><br>
| |
− | 9770 Patuxent Woods Drive<br>
| |
− | Columbia, MD<o:p></o:p></span></p>
| |
| | | |
− | </blockquote>
| + | Our next meeting is July 21st 6:00pm [http://maps.google.com/maps?q=2445+M+Street+NW+Washington,+District+of+Columbia+20037+United+States&oe=utf-8 2445 M Street NW Washington, DC 20037] ('''*NOTE NEW LOCATION*''') |
| | | |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| + | * Please [http://www.regonline.com/Register/Checkin.aspx?EventID=989237 Register Here] |
− | margin-bottom:3.75pt'>
| + | * Jack Mannino will speak on '''Building Secure Android Applications''' |
| + | * Doug Wilson & Mark Bristow will update on current and upcoming events. |
| | | |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| + | '''NEW LOCATION''' Folks will need to come up to the 8th floor, when they get off the elevator, walk towards the concierge, then make a left and walk towards the university room |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
| | | |
− | </div>
| + | '''About our Speakers''' |
| | | |
− | </div>
| + | :'''Jack Mannino''' |
| | | |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| + | ::Jack Mannino is the CEO of nVisium Security, an application security services firm located within the Washington DC area. At nVisium, he provides mobile and web application security services including source code reviews, penetration testing, threat modeling, and training. He is the co-leader and founder of the OWASP Mobile Security Project, which is a global initiative to improve the state of security in the mobile industry. Jack also serves as a board member for the OWASP Northern Virginia chapter. |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
| | | |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| + | :'''Abstract''' |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1047"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 4/26/05</a> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | ::'''Building Secure Android Applications''' - Mobile platforms are gaining momentum as an attacker's favorite new playground. We are seeing huge increases in mobile malware, mobile exploits, and the ever common insecure mobile applications themselves. Mature development shops and startups alike are releasing new applications at the speed of light. Like many other rapidly booming markets, technical innovation is far outpacing the adoption of security best-practices. This is a problem we must solve sooner than later. |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Wed Aug 10 16:23:41
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:3.75pt;margin-right:3.75pt;margin-bottom:
| + | ::This presentation will highlight many of the new security and privacy challenges developers, organizations, and consumers must be aware of. Android will be our target of interest during this presentation. A threat model for the Android platform will be presented, identifying the various layers where risks are introduced. We will discuss the top mobile security risks and the security controls used to mitigate them using guidance provided by the OWASP Mobile Security Project. |
− | 12.0pt;margin-left:3.75pt;line-height:150%;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>Thanks
| |
− | to Bruce Potter for discussing a comparison of secure development on different | |
− | operating systems.<o:p></o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | ::Expect a ton of code samples and live remediation of vulnerabilities. The OWASP GoatDroid project will be used to demonstrate various Android application security flaws. GoatDroid is a fully featured training environment for exploring the attack surface of Android apps. It is highly extendable, and includes several robust RESTful web services. |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l9 level1 lfo15;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>App Sec News<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | ::At the end of this presentation, attendees will understand how to identify Android risks, how to build secure applications for the Android platform, and will be exposed to the current initiatives within the Mobile Security Project. |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l9 level2 lfo15;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Sorry, this month's notes are
| |
− | lost.<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><br>
| |
| <br> | | <br> |
− | The meeting was held at:<o:p></o:p></span></p>
| |
− |
| |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><a href="http://www.sourcefire.com/">SOURCEfire</a><br>
| |
− | 9770 Patuxent Woods Drive<br>
| |
− | Columbia, MD<o:p></o:p></span></p>
| |
| | | |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| + | Facility Sponsor: Anonymous Refreshment Sponsor: {{MemberLinks|link=http://www.securicon.com|logo=Securicon.gif}} |
− | margin-bottom:3.75pt'>
| |
| | | |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span | + | <br><br><br><br><br> |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
| | | |
− | </div>
| + | '''March 2010 Meeting''' |
| | | |
− | </div>
| + | * Our next meeting will be [http://upcoming.yahoo.com/event/5617790/DC/Washington/OWASP-DC-March-Meeting/GWU-Phillips-Hall/ March 24th at 6:30 PM, at 801 22nd Street NW, Room B149] on the GWU campus in Washington DC (*NOTE NEW LOCATION*) |
| | | |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| + | * Jeff Ennis from Veracode will be presenting on Application Risk Management |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| + | * Dan Philpott will be briefing on the upcoming NIST SP covering Web Application Security |
− | 7.5pt'>
| + | * Chuck Willis will be giving an update on the OWASP BWA project and releasing and update to BWA |
| + | * Doug Wilson will update on plans for future meetings and upcoming events. |
| | | |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| + | '''About our Speakers''' |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1048"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 3/22/05</a> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | '''Jeff Ennis''' |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Tue Jun 21 12:44:36
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| + | :Jeff Ennis is a Solutions Architect for Veracode, Inc. He has more than 20 years experience in information technology. He recently served as Security Solutions Manager for the Federal Division of IBM Internet Security Systems, where he and his team of security architects assisted DoD, Civilian, and Intel agencies with addressing their security requirements as they dealt with an ever-changing threat landscape.. Throughout his career he has represented both the end user and vendor communities, including Nortel Networks, UUNET, and Lockheed Martin. |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>Welcome
| |
− | <a href="mailto:ed.tracy@aspectsecurity.com">Ed Tracy</a>, our new chapter
| |
− | leader, and thanks again to Aspect for providing pizza!<o:p></o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | :'''Abstract''' |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level1 lfo16;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>App Sec News<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | :'''Application Risk Management''' - Application vulnerabilities are steeply on the rise. At $350 billion per year software is the largest manufacturing industry in the world yet there are no uniform standards or insight into security, risk or liability of the final product. The development environment is becoming increasingly complex – application origin ranges from internally developed code, outsourced, 3rd party, Open Source, and Commercial Off the Shelf software. Ensuring that these entities are creating secure software is becoming a daunting task. Lots of emphasis is placed on IT controls, patching, etc, but the new attack vector is your application. During this presentation we will recap the state of software security today, discuss some initiatives which are requiring application risk management, and provide suggestions on how you can begin managing the application risk at your organization. |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>SHA-1 defrocked (<a
| |
− | href="http://www.financialcryptography.com/mt/archives/000355.html">http://www.financialcryptography.com/mt/archives/000355.html</a>)<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| + | '''Dan Philpott''' |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | :Dan is the maintainer of fismapedia.org, and a recognized expert in IT standards and policy in the DC Metro Area. Dan routinely helps review and contribute to NIST SP and Report documents. |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>XSS Proxy tool described by
| |
− | Andre Ludwig (<a
| |
− | href="http://xss-proxy.sourceforge.net/Advanced_XSS_Control.txt">http://xss-proxy.sourceforge.net/Advanced_XSS_Control.txt</a>)<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | '''Chuck Willis''' |
− | <ul type=circle>
| |
− | <ul type=square>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level3 lfo16;tab-stops:list 1.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Takes XSS vulnerability and
| |
− | exploits the hell out of it<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.5in;background:whitesmoke'><span
| + | :Chuck is a Technical Director with MANDIANT, and the founder of the OWASP Broken Web Application Project (OWASP BWA). Chuck has presented on the OWASP BWA at AppSecDC 2009 and at DoD Cyber Crime 2010, and will be releasing an updated version of OWASP BWA at this meeting. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | '''December 2009 Meeting''' |
− | <ul type=circle>
| |
− | <ul type=square>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level3 lfo16;tab-stops:list 1.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Potential demonstration in
| |
− | the future<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | * Our next meeting will be December 9th at 6:30 PM, at Duques Hall (Room 553D) on the GWU campus in Washington DC |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| + | * We will be recapping and discussing AppSecDC and the OWASP Summit |
− | auto;mso-list:l6 level1 lfo16;tab-stops:list .5in;background:whitesmoke'><span
| + | * We will discuss other recent events such as the DHS Software Assurance Forum Conference |
− | style='font-size:8.5pt;font-family:Tahoma'>Ethics Discussion<o:p></o:p></span></li>
| + | * We will be talking about the coming year and upcoming events |
− | </ul>
| + | * We will open up the floor for discussion of current events or concerns. |
| | | |
− | <ul type=disc>
| + | '''Addition to Agenda''' |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Harvard applicants rejected
| |
− | for "hacking" application website (<a
| |
− | href="http://www.pcworld.com/news/article/0,aid,119938,00.asp">http://www.pcworld.com/news/article/0,aid,119938,00.asp</a>)<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | Dan Philpott and several others in and around OWASP DC are working on an OWASP effort to contribute to the NIST draft standard 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems. |
− | <ul type=circle>
| |
− | <ul type=square>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level3 lfo16;tab-stops:list 1.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Everyone was surprised at the
| |
− | many different opinions of culpability people had<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | After our normal meeting agenda, I am going to turn the space over to Dan, so that he can explain what he and his group are up to, and hold a brief discussion in our space. Any and all who are interested in this process or contributing to government security policy are welcome to stick around and observe or contribute. |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Vulnerability Sharing Clubs
| |
− | like this one: <a href="http://www.immunitysec.com/services-sharing.shtml">http://www.immunitysec.com/services-sharing.shtml</a><o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | '''September 2009 Meeting''' |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level1 lfo16;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Chapter Direction Discussion,
| |
− | Presentation Ideas<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | * The meeting was held at [http://upcoming.yahoo.com/event/4344425/ September 2nd at 6:30 PM, at Duques Hall (Room 553D) on the GWU campus in Washington DC] |
− | <ul type=circle>
| + | * Matthew Flick and Jeff Yestrumskas will give an encore of their talk on the Cross-Site Scripting Anonymous Browsers (XAB) that they have previously presented at Black Hat and at Defcon. |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| + | * Doug Wilson talking about the recent launch of the AppSec DC 2009 website, and what's going on with the conference. |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Are we advancing webappsec,
| |
− | teaching it, or both? Possible worksessions at future meetings to allow
| |
− | both to coexist<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| + | '''XAB -- The Abstract:''' |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | Earlier this year, the Cross-site Scripting Anonymous Browser (“XAB”) was presented at Black Hat DC as a new perspective on how we could extend the functionality of browser technologies, form dynamic botnets for browsing, and create an unpronounceable acronym all at once. We continued the madness with a second incarnation of the XAB framework at Defcon in August. |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Inno Eroraha suggested
| |
− | cross-polinating with other focus groups in the DC area, ideas?<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| + | XAB hasn't really revolutionized attacks or defenses in it's short lifespan, nor is it great at factoring primes. However, it has opened minds by demonstrating an interesting way to combine unlike ideas and creating a new animal all of it's own. Think of it as forced social networking, without ever really knowing who you're talking to, or what they're saying. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | During this presentation, we will explain the origins of the concept, provide a brief review of the technologies, pour over the trials and tribulations of the enhancements and additions of the past 6 months, provide a live demonstration of the improvements, and continue the conversation about the future of the framework. |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Andre Ludwig suggested a demo
| |
− | on the XSS Proxy tool, dates?<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| + | '''About our speakers:''' |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | '''Matthew Flick, Principal''' |
− | <ul type=circle>
| + | '''FYRM Associates''' |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Matt Fisher suggested
| |
− | revisiting the Secure Model Architecture discussion, volunteers to get
| |
− | this started?<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| + | Matt has more than seven years of professional experience in information assurance focusing in network and application security, assessments, and compliance. He has assessed and helped develop information assurance programs for commercial clients in several industries as well as several Federal agencies. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | Matt leads the Information Assurance team at FYRM Associates in delivering consulting services in the areas of application security, assessments, network and wireless security, and security program development. He has performed assessments of many in-house and commercial/third party developed applications, wired and wireless network infrastructures, and complex corporate environments. His primary area of expertise is in application security, which drives much of the focus of FYRM's Information Assurance research and development. |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Matt Fisher suggested Absinthe
| |
− | and other SQL testing tools demonstration, dates?<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| + | Matt’s other areas of expertise include computer programming, cryptology, and compliance with Federal standards and regulatory compliance, such as FISMA, HIPAA, Sarbanes-Oxley, and PCI-DSS. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | '''Jeff Yestrumskas''' |
− | <ul type=circle>
| + | '''Sr. Manager InfoSec @ Cvent''' |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Joe Bui suggested an outreach
| |
− | session held in DC to reach the government audience. Joe is checking for
| |
− | space availability at his office downtown.<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| + | Jeff Yestrumskas is in charge of information security for an international application service provider, but still enjoys getting his hands dirty. His professional background spanning over a decade includes forensics, leading penetration tests, application security services and teaching others to do the same. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | '''August 2009 Meeting''' |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Several people suggested
| |
− | having a Northern VA meeting. That was countered with the idea of an
| |
− | additional chapter. If someone in VA (or any other area near DC) would
| |
− | like to move one of our meetings to VA, please let me know. I think it's
| |
− | a good idea.<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | *The meeting was held at [http://upcoming.yahoo.com/event/4129351/ August 5th at 6:30 PM, at Duques Hall (Room 553D) on the GWU campus in Washington DC] |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| + | *'''Dan Cornell''' of the Denim Group spoke on Vulnerability Management in an Application Security World |
− | auto;mso-list:l6 level1 lfo16;tab-stops:list .5in;background:whitesmoke'><span
| + | *'''Mike Smith''' of Deloitte spoke on SCAP and how it can relate to web application security. |
− | style='font-size:8.5pt;font-family:Tahoma'>Penetration Testing Lab<o:p></o:p></span></li>
| + | *'''Doug Wilson''' gave an update on [[OWASP_AppSec_DC_2009 | AppSecDC 2009]] |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | About our speakers: |
− | <ul type=circle>
| + | :'''Dan Cornell''' has over twelve years of experience architecting and developing web-based software systems. He leads Denim Group's security research team in investigating the application of secure coding and development techniques to improve web-based software development methodologies. |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Introduced the OWASP
| |
− | Penetration Testing Checklist (<a
| |
− | href="http://www.owasp.org/documentation/testing/application.html">http://www.owasp.org/documentation/testing/application.html</a>)<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| + | :Dan was the founding coordinator and chairman for the Java Users Group of San Antonio (JUGSA) and currently serves as the OWASP San Antonio chapter leader, member of the OWASP Global Membership Committee and co-lead of the OWASP Open Review Project. Dan has spoken at such international conferences as ROOTs in Norway and OWASP EU Summit in Portugal. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | :'''Vulnerability Management in an Application Security World''' |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Introduced WebScarab (<a
| |
− | href="http://www.owasp.org/software/webscarab.html">http://www.owasp.org/software/webscarab.html</a>)<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| + | :This presentation outlines strategies security teams can use for communicating with development teams to manage and ultimately correct application-level vulnerabilities. Similarities and differences between the security practice of vulnerability management and the development practice of defect management are also addressed. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | :'''Michael Smith''' is a manager in Deloitte's Security and Privacy Practice. His current engagement is as an Information System Security Officer working with a government agency integrating embedded devices with a web application command and control system. He blogs at http://www.guerilla-ciso.com/ and covers security management, public policy, regulations and laws, and technical solutions. |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Introduced WebGoat (<a
| |
− | href="http://www.owasp.org/software/webgoat.html">http://www.owasp.org/software/webgoat.html</a>)<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| + | :SCAP is the Security Content Automation Protocol, a set of XML schemas designed to automate information security flows between vulnerability, patch management, and data center automation tools. Michael will be giving us an introduction to SCAP and its applicability to web application security with a call to action to make web application security products and processes compatible with SCAP. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | '''April Meeting Debrief''' |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l6 level2 lfo16;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Gil Prine and Jeff Williams
| |
− | recommended the book, "Innocent Code" by Sverre H. Huseby<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| + | We'd like to thank Jon Rose for speaking, and showing us his Deblaze tool in action. His presentation will be up on the wiki shortly. If you want it before then, please email doug.wilson AT owasp for a copy. |
− | font-family:Tahoma;color:#333333'>This meeting was held at:<o:p></o:p></span></p>
| |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| + | Our big announcement of the meeting was that we are kicking off the [[OWASP_AppSec_US_2009_-_Washington_DC| Call for Papers for AppSec DC 2009]], slated for November 10-13 at the DC Convention Center. |
− | font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.aspectsecurity.com/contact.html">Aspect Security</a><br>
| |
− | 9175 Guilford Rd<br>
| |
− | Columbia, MD<o:p></o:p></span></p>
| |
| | | |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| + | We'd also like to thank: |
− | margin-bottom:3.75pt'>
| |
| | | |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| + | * George Washington University and their great staff for the meeting space and A/V support |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| + | * Securicon and Mark Bristow for arranging refreshements. |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
| | | |
− | </div>
| + | We hope to announce something about our next meeting soon, and if you want to volunteer for the conference, join our [https://lists.owasp.org/mailman/listinfo/appsec_us_09 mailing list]! |
| | | |
− | </div>
| + | '''April 22nd 6:30 PM OWASP Meeting, Washington DC |
| | | |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| + | This month we will be holding our meeting at The George Washington University in downtown DC. |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
| | | |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| + | The meeting will be held in Room 650 D on the 6th floor of Duques Hall at the George Washington University at [http://maps.google.com/maps?hl=en&q=2201+G+St.+NW+Washington,+DC+20037 2201 G St. NW Washington, DC 20037] |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1049"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 2/22/05</a> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | This month, we will have Jon Rose speaking about Flash Remoting and [http://deblaze-tool.appspot.com/ Deblaze]. |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Tue Jun 21 12:44:11
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span | + | <blockquote>Deblaze - A remote method enumeration tool for flex servers.</blockquote> |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>No
| |
− | meeting this month due to chapter organizers being out of town. See you next
| |
− | month!<o:p></o:p></span></p>
| |
| | | |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt; | + | <blockquote>Flash applications can make request to a remote server to call server side functions, such as looking up accounts, retrieving additional data and graphics, and performing complex business operations. However, the ability to call remote methods also increases the attack surface exposed by these applications. Deblaze was developed in order to perform method enumeration and interrogation against flash remoting end points.</blockquote> |
− | margin-bottom:3.75pt'>
| |
| | | |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span | + | <blockquote>This talk will provide a basic overview of Flash remoting and cover some of the security issues found in real-world flash applications and demonstrate a new tool for testing flash applications.</blockquote> |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
| | | |
− | </div> | + | <blockquote>The latest version can be found at [http://deblaze-tool.appspot.com deblaze-tool.appspot.com]</blockquote> |
| | | |
− | </div>
| + | Doug Wilson will also discuss the recent [http://www.owasp.org/index.php/OWASP_Software_Assurance_Day_DC_2009 OWASP Software Assurance Day] that took place at Mitre in March, and discuss some of the recent milestones that OWASP has hit with maturing and evolving projects. |
| | | |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| + | We will also have a few copies of the new OWASP Live CD to hand out, first come, first serve. |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
| | | |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| + | You can RSVP for the event on [http://upcoming.yahoo.com/event/2385625/ Upcoming.org] |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1050"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 1/25/05</a> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | ''Note on Transportation and Parking'' |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Thu Feb 17 19:43:19
| |
− | EST 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| + | Parking on campus is at a premium and visitors are encouraged to use public transportation when visiting the campus. The nearest METRO stop, Foggy Bottom/GWU located on the Orange/Blue lines, is a short 3 block walk from the Marvin Center |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>This
| |
− | month's meeting saw our biggest turnout yet, with over 20 attendees. Thanks to
| |
− | | |
− | Wichers</a> for his presentation, and thanks to Aspect for providing pizza,
| |
− | soda and snacks!<br>
| |
− | <br>
| |
− | <br>
| |
− | | |
− | Wichers</a></b><o:p></o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | The Marvin Center Garage operates from 7am - midnight Monday through Friday and is closed on weekends. Make sure you have your car out by 11:45pm. A visitor's parking garage is located between 23rd and 22nd Streets and H and Eye Streets. The visitor entrance is on Eye Street. |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l13 level1 lfo17;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'><a
| |
− | href="http://www.owasp.org/software/webscarab.html">WebScarab</a>, written
| |
− | | |
− | donated to OWASP, has been around about five years in one form or another
| |
− | (please let Rogan know if you use it!)<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | '''February 5th 6:30 PM OWASP Meeting, Washington DC''' |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | This month we will be holding our meeting at The George Washington University in downtown DC. |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l13 level1 lfo17;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Current version at <a
| |
− | href="http://sourceforge.net/project/showfiles.php?group_id=64424&package_id=61823">http://sourceforge.net/project/showfiles.php?group_id=64424&package_id=61823</a><o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | The meeting is in Duques Hall, Room 553, which is located at [http://maps.google.com/maps?hl=en&q=2201+G+St.+NW+Washington,+DC+20037 2201 G St. NW Washington, DC 20037] |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | This month's agenda: |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l13 level1 lfo17;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Includes a man-in-the-middle
| |
− | proxy, HTTP request/response editor, filtering traffic logger, session ID
| |
− | analyzer, passive web spider, automatic response modifier, encoder/decoder/hasher,
| |
− | and more; it’s also scriptable with Java Beanshell<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | * 6:30 - 6:45 Introductions and OWASP Business - Mark Bristow |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| + | * 6:45 - 7:45 WAF Virtual Patching Challenge: Securing WebGoat with ModSecurity - Ryan Barnett |
| + | * 7:45 - 8:00 Break |
| + | * 8:00 - 9:00 Software Assurance Maturity Model (SAMM) - Pravir Chandra |
| | | |
− | <ul type=disc>
| + | You can RSVP for the event on Upcoming.org: http://upcoming.yahoo.com/event/1494008 |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l13 level1 lfo17;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Dave took us through several of
| |
− | the <a href="http://www.owasp.org/software/webgoat.html">WebGoat</a>
| |
− | lessons using WebScarab to manipulate traffic and explained common
| |
− | vulnerabilities like cross-site scripting<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | ''Note on Transportation and Parking'' |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | Parking on campus is at a premium and visitors are encouraged to use public transportation when visiting the campus. The nearest METRO stop, Foggy Bottom/GWU located on the Orange/Blue lines, is a short 3 block walk from the Marvin Center |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l13 level1 lfo17;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>We were showed how to use
| |
− | WebScarab to intercept browser requests and change it before sending it to
| |
− | the server<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | The Marvin Center Garage operates from 7am - midnight Monday through Friday and is closed on weekends. Make sure you have your car out by 11:45pm. A visitor's parking garage is located between 23rd and 22nd Streets and H and Eye Streets. The visitor entrance is on Eye Street. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | '''December Meeting Debrief''' |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l13 level1 lfo17;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Discussed some authentication
| |
− | and session management methods such as HTTP Basic Auth (bad), Tomcat
| |
− | JSESSIONID (good), using SSL only for the login (bad), etc.<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | I'd like to take this opportunity to once again thank Kevin for coming out to talk to us at the meeting Wednesday. I thought his presentation on Samurai, Yokoso!, Laudanum, and Social butterfly |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| + | demonstrated some of the great up and coming tools that are available to the community. As promised, I uploaded the PDF of the presentationto the Wiki, but the slides don't do the commentary justice. It can be found [https://www.owasp.org/index.php/Image:OWASP_DC_--_Web_Attack_Tools.pdf here]. |
| | | |
− | <ul type=disc>
| + | We also took care of some housekeeping stuff: |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l13 level1 lfo17;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>WebScarab will point out which
| |
− | pages on your site set cookies<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | * We'd like to thank Mike from Deloitte for offering up his space the last few months but our next meeting will instead be held at George Washington University Gelman Library. Everyone remember to thank Amy for offering up GW's meeting spaces to us. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| + | * The OWASP DC Chapter will be hosting [https://www.owasp.org/index.php/OWASP_AppSec_US_2009_-_Washington_DC OWASP AppSec 2009] sometime in October 09. More details will come out as we firm up dates/speakers/locations and calls for volunteers! |
| + | * Rex talked for a few minutes about the Portugal Summit. The debrief from the summit can be found [http://www.owasp.org/index.php/OWASP_EU_Summit_2008 here] |
| + | * Our next chapter meeting will be held in Feburary, topics TBD but we are [mailto:mark.bristow__AT___owasp.org soliciting speakers]. |
| | | |
− | <ul type=disc>
| + | To those who attended the meeting on Wednesday, thanks for coming out, we had a great turnout and I hope to have even more attendees next time. For those who were unable to attend, I hope to see you all at our next meeting. |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt: | |
− | auto;mso-list:l13 level1 lfo17;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>It will show you both raw and
| |
− | formatted HTTP requests and responses and show you a hex editor-like view
| |
− | of binary data such as images<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><b><span style='font-size:
| + | '''December 10th 6:30pm OWASP Meeting, Washington DC''' |
− | 8.5pt;font-family:Tahoma;color:#333333'>General Discussion</span></b><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p></o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | This month we will be holding our meeting at the DC offices of [http://www.deloitte.com/ Deloitte & Touche] ([http://maps.google.com/maps?f=q&hl=en&geocode=&q=1001+G+ST+NW+washington+dc 1001 G St NW Washington DC 20001]). |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level1 lfo18;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Discussed the dilemma of
| |
− | accidentally finding a vulnerability on a public site...do you disclose or
| |
− | not? Will they think you’re a cracker or a saint...or just ignore
| |
− | you?<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | The meeting will start at 1830. Upon arriving, please go to the 9th floor and sign in, someone will escort you to the meeting location, Rm. 8S026. If you are late and can not get in, please call 202.270.8715. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | This month's agenda is as follows: |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level1 lfo18;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Discussed what other tools
| |
− | people use, commercial and free: Appscan, WebInspect, Sleuth, Nstealth,
| |
− | Achilles, Odysseus, Paros, etc. Some limited use of both the commercial
| |
− | and free scanning tools was identified.<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | * Presentation by Kevin Johnson, InGuardians |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| + | * Round table Discussion of Portugal Summit |
| + | * Open discussion |
| | | |
− | <ul type=disc>
| + | Kevin Johnson is a Senior Security Analyst with InGuardians. Kevin came to security from a development and system administration background. He has many years of experience performing security services for fortune 100 companies, and contributes to a large number of open source security projects. Kevin founded and leads the development on B.A.S.E., Samurai, SecTools and Yokoso! projects. |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt: | |
− | auto;mso-list:l1 level1 lfo18;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Discussed web application
| |
− | "firewalls". No one in the group indicated they were using any
| |
− | of these products.<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | Kevin is an instructor for SANS, authoring and teaching Security 542, Web Application Pen-Testing In-Depth and teaching other SANS classes such as the Incident Handling and Hacker Techniques class. He has presented to many organizations, including InfraGard, ISACA, ISSA and the University of Florida. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | You can RSVP to the event on Upcoming.org: |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level1 lfo18;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>DISA has a checklist for
| |
− | application security (called the Application Security Checklist) at: <a
| |
− | href="http://csrc.nist.gov/pcig/cig.html">http://csrc.nist.gov/pcig/cig.html</a>,
| |
− | and NIST is working on the FISMA guidelines, but until there’s a
| |
− | federal regulation on secure development it will be hard to convince them
| |
− | to (pay to) do it<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | http://upcoming.yahoo.com/event/1334575 |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | '''October 15th 6:30pm OWASP Meeting, Washington DC''' |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level1 lfo18;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Discussed the conundrum of
| |
− | developers having no motivation to think security; mentioned putting
| |
− | security requirements in the business/software requirements; mentioned the
| |
− | OWASP secure software contract annex (<a
| |
− | href="http://www.owasp.org/docroot/owasp/misc/contract.doc">http://www.owasp.org/docroot/owasp/misc/contract.doc</a>)<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| + | This month we will be holding our meeting at the DC offices of [http://www.deloitte.com/ Deloitte & Touche] ([http://maps.google.com/maps?f=q&hl=en&geocode=&q=1001+G+ST+NW+washington+dc 1001 G St NW Washington DC 20001]). |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | The meeting will start at 1830. Upon arriving, please go to the 9th floor and sign in, someone will escort you to the meeting location, Rm. 8S026. If you are late and can not get in, please call 202.270.8715. |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level1 lfo18;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Discussed the new application
| |
− | code scanning tools, Ounce Lab's Prexis, Fortfy, and Klocwork were all
| |
− | mentioned. Some members had received briefings on them but no significant
| |
− | use was discussed.<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | This month's agenda is as follows: |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level2 lfo18;tab-stops:list 1.0in;background:whitesmoke'><b><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Since the meeting, some
| |
− | articles about these tools have been identified and are included here for
| |
− | reference:</span></b><span style='font-size:8.5pt;font-family:Tahoma'><o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <ul type=disc>
| + | * Adam Vincent, Hacking and Hardening Web Services |
− | <ul type=circle>
| + | * Doug Wilson, Report on AppSec NYC 2008 |
− | <ul type=square>
| + | * Open discussion |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level3 lfo18;tab-stops:list 1.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Here's a recent (Jan 2005)
| |
− | article about Fortify: <a
| |
− | href="http://www.infoworld.com/article/05/01/14/03TCfortify_1.html">http://www.infoworld.com/article/05/01/14/03TCfortify_1.html</a><o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.5in;background:whitesmoke'><span
| + | Adam Vincent will be presenting on Hacking and Hardening Web Services. He has presented this to other OWASP chapters, including NoVa, and we are pleased to have him be able to bring it to our DC audience. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | Doug Wilson will also be reporting back from the OWASP AppSec NYC 2008 conference. He will cover some of the themes that emerged from that, and talk about some of the directions that OWASP is looking to take in the coming year. |
− | <ul type=circle>
| |
− | <ul type=square>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level3 lfo18;tab-stops:list 1.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Here's an older (Jul 2004)
| |
− | article about a previous release of Ounce's Prexis: <a
| |
− | href="http://www.sdtimes.com/news/106/story12.htm">http://www.sdtimes.com/news/106/story12.htm</a><o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.5in;background:whitesmoke'><span
| + | = History = |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | The original DC Chapter was founded in June 2004 by [mailto:jeff.williams(at)owasp.org Jeff Williams] and has had members from Virginia to Delaware. |
− | <ul type=circle>
| |
− | <ul type=square>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level3 lfo18;tab-stops:list 1.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>A summary of mostly open
| |
− | source application security code analysis tools is available here: <a
| |
− | href="http://sardonix.org/Auditing_Resources.html">http://sardonix.org/Auditing_Resources.html</a><o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.5in;background:whitesmoke'><span
| + | In April 2005 a new chapter, DC-Virginia, was formed and the DC Chapter was renamed to DC-Maryland. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | In 2008, the DC-Maryland chapter was given over to the stewardship of co-chairs Rex Booth, Mark Bristow, and Doug Wilson, and charged by the OWASP board to create a chapter focused on the needs of Washington DC in specific. The new chapter has tried to reach out to government and academic environments found in DC as well as the private sector. |
− | <ul type=circle>
| |
− | <ul type=square>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level3 lfo18;tab-stops:list 1.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>A general article about the
| |
− | emerging web app security capabilities: "Emerging web app security
| |
− | services and products bring source code vulnerabilities to light" <a
| |
− | href="http://infosecuritymag.techtarget.com/ss/0,295796,sid6_iss467_art975,00.html">http://infosecuritymag.techtarget.com/ss/0,295796,sid6_iss467_art975,00.html</a><o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.5in;background:whitesmoke'><span
| + | The DC chapter will be hosting OWASP AppSec DC in November of 2009, the national OWASP conference for the year. |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| |
− | <ul type=circle>
| |
− | <ul type=square>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level3 lfo18;tab-stops:list 1.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>And in the same Information
| |
− | Security mag article is a summary chart of various product and service
| |
− | vendors in the space: <a
| |
− | href="http://infosecuritymag.techtarget.com/ss/0,295796,sid6_iss467_art978,00.html">http://infosecuritymag.techtarget.com/ss/0,295796,sid6_iss467_art978,00.html</a><o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:1.5in;background:whitesmoke'><span | + | <headertabs /> |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc> | + | <br> |
− | <ul type=circle>
| |
− | <ul type=square>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l1 level3 lfo18;tab-stops:list 1.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>The Vendors' pages for these
| |
− | products are at:<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <ul type=disc> | + | <br> |
− | <ul type=circle>
| |
− | <ul type=square>
| |
− | <ul type=square>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;
| |
− | mso-margin-bottom-alt:auto;mso-list:l1 level4 lfo18;tab-stops:list 2.0in;
| |
− | background:whitesmoke'><span style='font-size:8.5pt;font-family:Tahoma'><a
| |
− | href="http://www.ouncelabs.com/prexis_engine.html">http://www.ouncelabs.com/prexis_engine.html</a><o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:2.0in;background:whitesmoke'><span | + | <br> |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc> | + | <paypal>Washington DC</paypal> |
− | <ul type=circle>
| |
− | <ul type=square>
| |
− | <ul type=square>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;
| |
− | mso-margin-bottom-alt:auto;mso-list:l1 level4 lfo18;tab-stops:list 2.0in;
| |
− | background:whitesmoke'><span style='font-size:8.5pt;font-family:Tahoma'><a
| |
− | href="http://www.fortifysoftware.com/products/suite/">http://www.fortifysoftware.com/products/suite/</a><o:p></o:p></span></li>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;
| |
− | mso-margin-bottom-alt:auto;mso-list:l1 level4 lfo18;tab-stops:list 2.0in;
| |
− | background:whitesmoke'><span style='font-size:8.5pt;font-family:Tahoma'><a
| |
− | href="http://www.klocwork.com/products/inspect.asp">http://www.klocwork.com/products/inspect.asp</a><o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul>
| |
− | </ul> | |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><b><span style='font-size:
| |
− | 8.5pt;font-family:Tahoma;color:#333333'>Note: OWASP is not endorsing these
| |
− | products in any way. This information is simply provided for the interest of
| |
− | the members of the DC Chapter.</span></b><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><br>
| |
− | <br>
| |
| <br> | | <br> |
− | This meeting was held at:<o:p></o:p></span></p>
| |
− |
| |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.aspectsecurity.com/contact.html">Aspect Security</a><br>
| |
− | 9175 Guilford Rd<br>
| |
− | Columbia, MD<o:p></o:p></span></p>
| |
| | | |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| |
− | margin-bottom:3.75pt'>
| |
− |
| |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
− |
| |
− | </div>
| |
− |
| |
− | </div>
| |
− |
| |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
− |
| |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1051"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 12/28/04</a> <o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Tue Jun 21 12:43:49
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>No
| |
− | meeting this month due to the holidays. Happy holidays!<o:p></o:p></span></p>
| |
− |
| |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| |
− | margin-bottom:3.75pt'>
| |
− |
| |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
− |
| |
− | </div>
| |
− |
| |
− | </div>
| |
− |
| |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
− |
| |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1052"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 11/23/04</a> <o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Tue Jun 21 12:51:15
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>This
| |
− | month's meeting was again held in the first floor conference room at <a
| |
− | href="http://www.aspectsecurity.com/">Aspect Security</a>, the chapter's
| |
− | sponsor. A couple "regulars" couldn't make it due to the holiday but
| |
− | it was still well-attended.<br>
| |
− | <br>
| |
− | IMPORTANT: Future meetings will continue to be on the fourth Tuesday of the
| |
− | month--so the next meeting will be on December 28, again at 6pm. As long as
| |
− | Aspect can reserve the conference room for us, we'll continue meeting there.<br>
| |
| <br> | | <br> |
− | Minutes: A slightly smaller group allowed us to keep discussion on topic more
| |
− | easily this month.<o:p></o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l19 level1 lfo19;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>GEMS Demo: Demonstration of the
| |
− | insecurity of Diebold's General Election Management System (GEMS). See <a
| |
− | href="http://www.equalccw.com/dieboldtestnotes.html">http://www.equalccw.com/dieboldtestnotes.html</a>
| |
− | for more details.<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l19 level1 lfo19;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>DropMyRights: Discussed use of <i>dropmyrights.exe
| |
− | </i>when you're running as administrator but want to run your email and
| |
− | browser with lower privileges. Just create a shortcut that contains
| |
− | "C:\Program Files\dropmyrights\DropMyRights.exe"
| |
− | "C:\Program Files\Internet Explorer\iexplore.exe" and use that
| |
− | instead of directly invoking the browser. See <br>
| |
− | <a
| |
− | href="http://msdn.microsoft.com/security/securecode/columns/default.aspx?pull=/library/en-us/dncode/html/secure11152004.asp">http://msdn.microsoft.com/security/securecode/columns/default.aspx?pull=/library/en-us/dncode/html/secure11152004.asp</a>
| |
− | for the tool and a short article.<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l19 level1 lfo19;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>OWASP Secure Software Contract
| |
− | Annex: Jeff Williams prepared a draft of this document as a starting point
| |
− | for helping people write software development contracts that include
| |
− | security. We discussed how this contract emphasizes the lifecycle steps,
| |
− | whereas the Ounce Labs version emphasizes specific vulnerabilities. We
| |
− | also discussed the fact that the contract includes "requirements for
| |
− | the requirements" instead of trying to cover everything. The document
| |
− | needs more work on the "teeth," i.e. how to ensure that each
| |
− | element is specific enough to audit. Also, it needs some more work on including
| |
− | risk-related activities before the requirements. The plan is to
| |
− | incorporate a few comments, get approval from the OWASP-Leaders, send it
| |
− | out to <a href="http://www.securityfocus.com/archive/107">WebAppSec</a>
| |
− | and stand up an OWASP project to maintain the document.<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l19 level2 lfo19;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>The OWASP Mission: The
| |
− | contract discussion led into questions about OWASP's constituency and how
| |
− | we are serving them. One view is that OWASP serves developers and the
| |
− | contract effort is not exactly on target. The other view we discussed is
| |
− | that OWASP is focused on the problem of insecure software, and it should
| |
− | do whatever is necessary to raise awareness of the issue. We also
| |
− | discussed OWASP's role as a platform for the application security
| |
− | community. Is OWASP an "if you build it, they will come" model?<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l19 level2 lfo19;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Open Letter and Requirements
| |
− | Project: We discussed the Open Letter and how it looks like the various
| |
− | product vendors will be working with OWASP to produce a strong list of
| |
− | requirements for all of web application security.<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l19 level1 lfo19;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Reference Architectures: We
| |
− | discussed the concept for this project again, and examined Microsoft's <i>Improving
| |
− | Web Application Security </i><br>
| |
− | (<a
| |
− | href="http://msdn.microsoft.com/security/default.aspx?pull=/library/en-us/dnnetsec/html/threatcounter.asp">http://msdn.microsoft.com/security/default.aspx?pull=/library/en-us/dnnetsec/html/threatcounter.asp</a>).
| |
− | While an impressive effort, it seems like there is a need for platform
| |
− | independent documentation that covers the threat, requirements, and
| |
− | architecture levels, but doesn't go into the source code level.<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l19 level1 lfo19;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>J2EE Filters: Jeff gave a bit
| |
− | of background on how J2EE Filters works. Anil pointed out that this is
| |
− | very similar to how HTTP Handlers work in the .NET environment. We then
| |
− | discussed the types of things that J2EE Filters can do. Jeff showed how to
| |
− | write filters that implement a request rate throttle, an input sanitizer,
| |
− | a certificate validator, an SSL-only verifier, and several other
| |
− | functions. Some ideas raised by the group included a logging filter and a
| |
− | filter to verify that responses with set-cookie headers should only be <br>
| |
− | sent over SSL.<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'>This meeting was held at:<o:p></o:p></span></p>
| |
− |
| |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.aspectsecurity.com/contact.html">Aspect Security</a><br>
| |
− | 9175 Guilford Rd<br>
| |
− | Columbia, MD<o:p></o:p></span></p>
| |
− |
| |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| |
− | margin-bottom:3.75pt'>
| |
− |
| |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
− |
| |
− | </div>
| |
− |
| |
− | </div>
| |
− |
| |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
− |
| |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1053"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 10/28/04</a> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | September Meeting:<br> |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Tue Jun 21 12:43:28
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>This
| |
− | month we decided to meet in a conference room at <a
| |
− | href="http://www.aspectsecurity.com/">Aspect Security</a>, the chapter's
| |
− | sponsor. Aspect was generous enough to provide sodas, chips, and the most
| |
− | delicious brownies anyone ever tasted. Thanks!<br>
| |
− | <br>
| |
− | IMPORTANT: Future meetings will be on the fourth Tuesday of the month--so the
| |
− | next meeting will be on November 23, again at 6pm. As long as Aspect can
| |
− | reserve the conference room for us, we'll meet there again.<br>
| |
| <br> | | <br> |
− | Minutes: We tried to keep the discussion on three main topics: whitepaper
| |
− | topics, a concept for a "webappsec dashboard," and J2EE filters.<o:p></o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l0 level1 lfo20;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Whitepaper topics: Jeff has a
| |
− | list of subjects he'd really like to read whitepapers about, but doesn't
| |
− | have time to write about himself. If anyone would like to volunteer to
| |
− | write a whitepaper to be posted on the OWASP site, <a
| |
− | | |
− | that sparked a lot of discussion and interest were:<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <ul type=disc>
| |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l0 level2 lfo20;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>The asymmetric/broken market
| |
− | for security: Consumers can't determine if software is secure so they
| |
− | won't pay more for the claim of security; producers can't charge more for
| |
− | more secure software so they don't make it more secure. How do we get
| |
− | vendors to write secure code? How about for libraries--are the
| |
− | circumstances different? A related but possibly separate topic is, who
| |
− | has the burden of proof--the developer to prove software's secure, or the
| |
− | consumer to prove it's insecure?<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
| |
− | margin-left:1.0in;background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l0 level2 lfo20;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Secure web app architectures:
| |
− | How do you draw security or secure web app architectures? We're not so
| |
− | good at telling customers <i>where </i>to do security things in the data
| |
− | flow and n-tier diagrams. Can we do this with UML? Data flow diagrams?
| |
− | How about a "reference architecture" for authentication as an
| |
− | example? This may turn out to be a Chapter project.<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
| |
− | margin-left:1.0in;background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l0 level2 lfo20;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>How to decide what to fix
| |
− | first: Is there a quick and easy way for a company with a large number of
| |
− | web apps to determine where they should begin with assessments? If they
| |
− | don't know about any vulnerabilities in any sites, which do they look at
| |
− | first? Maybe we can come up with a short questionnaire for each web app
| |
− | to risk rank them relatively, in the style of <a
| |
− | href="http://www.joelonsoftware.com/articles/fog0000000043.html">The Joel
| |
− | Test</a>. This may also become a Chapter project.<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
| |
− | margin-left:1.0in;background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l0 level2 lfo20;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Mechanisms, vulnerabilities,
| |
− | and threat models: How do people threat-model attacks? Do they even do
| |
− | it? Could we create a standard suite of threat models for any generic web
| |
− | app?<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
| |
− | margin-left:1.0in;background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <ul type=circle>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l0 level2 lfo20;tab-stops:list 1.0in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Webappsec requirements: Are
| |
− | people putting security requirements into their business requirements for
| |
− | projects involving web apps? Can we create a standard list of security
| |
− | requirements people can paste in to their project docs?<o:p></o:p></span></li>
| |
− | </ul>
| |
− | </ul>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l0 level1 lfo20;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Webappsec dashboard: The
| |
− | concern is that CISOs have no way to get their arms around the state of
| |
− | web app security in their environment. They need a sort of dashboard where
| |
− | they can see metrics and statistics about all their web apps all in one
| |
− | place. Something like this may have to be a tool/software, and OWASP
| |
− | really isn't in the business of writing tools/software.<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l0 level1 lfo20;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>J2EE filters: We didn't have
| |
− | time to discuss this but attendees were interested so it will be on the
| |
− | agenda for the next meeting. Jeff quickly demonstrated a tool to analyze
| |
− | JAR files and show what calls they make.<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− |
| |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l0 level1 lfo20;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>General discussion: More and
| |
− | more Local Chapters are springing up--what kinds of things can chapters
| |
− | contribute? What should they be expected to contribute?<o:p></o:p></span></li>
| |
− | </ul>
| |
− |
| |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'>This meeting was held at:<o:p></o:p></span></p>
| |
− |
| |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.aspectsecurity.com/contact.html">Aspect Security</a><br>
| |
− | 9175 Guilford Rd<br>
| |
− | Columbia, MD<o:p></o:p></span></p>
| |
− |
| |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| |
− | margin-bottom:3.75pt'>
| |
− |
| |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
− |
| |
− | </div>
| |
− |
| |
− | </div>
| |
− |
| |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
− |
| |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1054"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 9/30/04</a> <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| + | Facility Sponsor: [http://www.uberoffices.com UberOffices] Refreshment Sponsor: Still Open!<!-- {{MemberLinks|link=http://www.securicon.com|logo=Securicon.gif}} --> |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Tue Jun 21 12:42:45
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
| | | |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>A
| |
− | good time was had by all.<br>
| |
− | <br>
| |
− | IMPORTANT: Future meetings will be on the last Thursday of the month--so the
| |
− | next meeting will be on October 28, again at 6pm. If anyone has a good
| |
− | suggestion about where to meet, please send it to the <a
| |
− | href="http://lists.sourceforge.net/lists/listinfo/owasp-washington/">list</a>.<br>
| |
− | <br>
| |
− | Minutes: None recorded.<br>
| |
| <br> | | <br> |
− | This meeting was held at:<o:p></o:p></span></p>
| |
− |
| |
− | <blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'>
| |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.rockyrun.com/locations.htm">Rocky Run Tap & Grill</a><br>
| |
− | 6480 Dobbin Center Way<br>
| |
− | Columbia, MD<o:p></o:p></span></p>
| |
− |
| |
− | </blockquote>
| |
− |
| |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| |
− | margin-bottom:3.75pt'>
| |
− |
| |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
− |
| |
− | </div>
| |
− |
| |
− | </div>
| |
− |
| |
− | <div style='border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC .75pt;
| |
− | padding:0in 0in 0in 0in;margin-top:7.5pt;margin-right:153.75pt;margin-bottom:
| |
− | 7.5pt'>
| |
− |
| |
− | <p class=MsoNormal style='margin:.75pt;mso-outline-level:2;background:#E9E9E9'><b><span
| |
− | style='font-size:10.5pt;font-family:Tahoma;color:#333333;mso-font-kerning:18.0pt'><img
| |
− | border=0 width=16 height=16 id="_x0000_i1055"
| |
− | src="../../../../../Desktop/washington_files/document.gif" class=postIcon><a
| |
− | href="http://www.owasp.org/local/washington.html">Meeting Notes - 8/25/04</a> <o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin-top:.75pt;margin-right:3.0pt;margin-bottom:
| |
− | 3.0pt;margin-left:0in;mso-outline-level:3;background:whitesmoke'><b><span
| |
− | style='font-size:10.0pt;font-family:Tahoma;color:#CCCCCC'>Tue Jun 21 12:42:00
| |
− | EDT 2005 <o:p></o:p></span></b></p>
| |
− |
| |
− | <p class=MsoNormal style='margin:3.75pt;line-height:150%;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;line-height:150%;font-family:Tahoma;color:#333333'>Thanks
| |
− | to everyone who showed up last night to the first OWASP Washington Local
| |
− | Chapter meeting. It was great to finally put some faces to names, meet some
| |
− | local application security folks, and the Guinness was nice too!<br>
| |
− | <br>
| |
− | IMPORTANT: Meetings will be on the last Wednesday of the month--so the next
| |
− | meeting will be on September 29, again at 6pm. This time we're going to meet in
| |
− | Columbia, MD at a place to be determined soon. If anyone has a good suggestion
| |
− | about where to meet, please send it to the list.<br>
| |
| <br> | | <br> |
− | Minutes: We had some wide-ranging discussions that touched on scanning,
| |
− | brute-force attacks, validation, web app firewalls, and new projects for OWASP.<o:p></o:p></span></p>
| |
| | | |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l3 level1 lfo21;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Brute force attacks: We
| |
− | discussed some schemes for handling brute force attacks on websites, some
| |
− | techniques for making a site hard to scan (and why some scanners don't
| |
− | care), and we discussed the combinatorics of generating productive
| |
− | password lists. We also got a demo of Matt Fisher's password generation
| |
− | utility.<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | [[Category:OWASP Chapter]] |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l3 level1 lfo21;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>OWASP and awareness: We had a
| |
− | long discussion about things that OWASP can do to help raise awareness
| |
− | about web application security. Some promising approaches included making
| |
− | some webinars and offering them on the website, and providing more <i>practical</i>
| |
− | stuff (tools, libraries, templates) and not focusing on the academic.<o:p></o:p></span></li>
| |
− | </ul>
| |
− | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− | | |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l3 level1 lfo21;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>OWASP image: We discussed some
| |
− | ways that OWASP could build on the "platform" provided by the
| |
− | new portal. We could move the webappsec list to OWASP from sourceforge,
| |
− | maybe create some different lists (newbie, advanced, SQL injection, etc.).
| |
− | We could create some discussion forums.<o:p></o:p></span></li>
| |
− | </ul>
| |
− | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
− | | |
− | <ul type=disc>
| |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l3 level1 lfo21;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Metrics: We talked about the
| |
− | new metrics project and what kinds of metrics would be the most useful to
| |
− | the appsec community.<o:p></o:p></span></li>
| |
− | </ul>
| |
− | | |
− | <p class=MsoNormal style='margin-left:.5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><o:p> </o:p></span></p>
| |
| | | |
− | <ul type=disc>
| + | [[Category:Washington, DC]] |
− | <li class=MsoNormal style='color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:
| |
− | auto;mso-list:l3 level1 lfo21;tab-stops:list .5in;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma'>Promoting adoption: There were
| |
− | some interesting ideas about things OWASP could do to advance the adoption
| |
− | of good appsec practices. One was to get some buy-in from the FBI (a la
| |
− | SANS) or another high-power agency. Matt Chalmers and Chris Burton are
| |
− | going to pursue a few leads to see if there's interest.<o:p></o:p></span></li>
| |
− | </ul>
| |
| | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| + | [[Category:Maryland]] |
− | font-family:Tahoma;color:#333333'>This meeting was held at:<o:p></o:p></span></p>
| |
− | | |
− | <p class=MsoNormal style='background:whitesmoke'><span style='font-size:8.5pt;
| |
− | font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.mayorgaimports.com/html/retail-silverspring.php">Mayorga Cafe</a><br>
| |
− | 8040 Georgia Av<br>
| |
− | Silver Spring, MD<o:p></o:p></span></p>
| |
− | | |
− | <div style='margin-left:3.75pt;margin-top:3.75pt;margin-right:3.75pt;
| |
− | margin-bottom:3.75pt'>
| |
− | | |
− | <p class=MsoNormal align=right style='text-align:right;background:whitesmoke'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'><a
| |
− | href="http://www.owasp.org/local/washington.html">Read</a><o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | <div style='border:none;border-top:dotted #CCCCCC 1.0pt;mso-border-top-alt:
| |
− | dotted #CCCCCC .75pt;padding:0in 0in 0in 0in;margin-top:7.5pt' id=footer>
| |
− | | |
− | <p class=MsoNormal align=center style='text-align:center'><span
| |
− | style='font-size:8.5pt;font-family:Tahoma;color:#333333'>© 2005 <a
| |
− | href="http://www.owasp.org/index.html">The OWASP Foundation</a> | Contact the <a
| |
− | | |
− | concerning this site.<o:p></o:p></span></p>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | </div>
| |
− | | |
− | </body>
| |
− | | |
− | </html>
| |
− | | |
− | | |
− | [[Category:OWASP Chapter]] | |
Everyone is welcome to join us at our chapter meetings.