This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Summit 2011 Working Sessions/Session009"
From OWASP
Sarah Baso (talk | contribs) (Created page with '{{Template:<includeonly>{{{1}}}</includeonly><noinclude>Summit 2011 Working Sessions tab</noinclude> |- | summit_session_name = | summit_session_url = |- | summit_session_objec…') |
|||
(32 intermediate revisions by 10 users not shown) | |||
Line 1: | Line 1: | ||
− | {{Template:<includeonly>{{{1}}}</includeonly><noinclude>Summit 2011 Working Sessions tab</noinclude> | + | {{Template:<includeonly>{{{1}}}</includeonly><noinclude>Summit 2011 Working Sessions test tab</noinclude> |
|- | |- | ||
− | + | ||
− | | | + | | summit_session_attendee_name1 = Chris Eng |
− | | | + | | summit_session_attendee_email1 = [email protected] |
− | + | | summit_session_attendee_username1 = | |
− | + | | summit_session_attendee_company1= | |
− | + | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1= | |
− | + | ||
− | + | | summit_session_attendee_name2 = Abraham Kang | |
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | | | ||
− | | | ||
− | |||
− | | | ||
− | |||
− | | summit_session_attendee_name2 = | ||
| summit_session_attendee_email2 = | | summit_session_attendee_email2 = | ||
− | | | + | | summit_session_attendee_username2 = |
− | | summit_session_attendee_name3 = | + | | summit_session_attendee_company2= |
− | | summit_session_attendee_email3 = | + | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2= |
− | | | + | |
− | | summit_session_attendee_name4 = | + | | summit_session_attendee_name3 = Tony UcedaVelez |
− | | summit_session_attendee_email4 = | + | | summit_session_attendee_email3 = [email protected] |
− | | | + | | summit_session_attendee_username3 = Tony UcedaVelez |
− | | summit_session_attendee_name5 = | + | | summit_session_attendee_company3= VerSprite |
− | | summit_session_attendee_email5 = | + | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3= |
− | | | + | |
+ | | summit_session_attendee_name4 = Fred Donovan | ||
+ | | summit_session_attendee_email4 = [email protected] | ||
+ | | summit_session_attendee_username4 = Fred.Donovan | ||
+ | | summit_session_attendee_company4= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4= | ||
+ | |||
+ | | summit_session_attendee_name5 = Juan Jose Rider | ||
+ | | summit_session_attendee_email5 = [email protected] | ||
+ | | summit_session_attendee_username5 = Juan_Jose_Rider_Jimenez | ||
+ | | summit_session_attendee_company5= WUL4 | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5= | ||
+ | |||
| summit_session_attendee_name6 = | | summit_session_attendee_name6 = | ||
| summit_session_attendee_email6 = | | summit_session_attendee_email6 = | ||
− | | | + | | summit_session_attendee_username6 = |
+ | | summit_session_attendee_company6= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6= | ||
+ | |||
| summit_session_attendee_name7 = | | summit_session_attendee_name7 = | ||
| summit_session_attendee_email7 = | | summit_session_attendee_email7 = | ||
− | | | + | | summit_session_attendee_username7 = |
+ | | summit_session_attendee_company7= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7= | ||
+ | |||
| summit_session_attendee_name8 = | | summit_session_attendee_name8 = | ||
| summit_session_attendee_email8 = | | summit_session_attendee_email8 = | ||
− | | | + | | summit_session_attendee_username8 = |
+ | | summit_session_attendee_company8= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8= | ||
+ | |||
| summit_session_attendee_name9 = | | summit_session_attendee_name9 = | ||
| summit_session_attendee_email9 = | | summit_session_attendee_email9 = | ||
− | | | + | | summit_session_attendee_username9 = |
+ | | summit_session_attendee_company9= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9= | ||
+ | |||
| summit_session_attendee_name10 = | | summit_session_attendee_name10 = | ||
| summit_session_attendee_email10 = | | summit_session_attendee_email10 = | ||
− | | | + | | summit_session_attendee_username10 = |
+ | | summit_session_attendee_company10= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10= | ||
+ | |||
| summit_session_attendee_name11 = | | summit_session_attendee_name11 = | ||
| summit_session_attendee_email11 = | | summit_session_attendee_email11 = | ||
− | | | + | | summit_session_attendee_username11 = |
+ | | summit_session_attendee_company11= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11= | ||
+ | |||
| summit_session_attendee_name12 = | | summit_session_attendee_name12 = | ||
| summit_session_attendee_email12 = | | summit_session_attendee_email12 = | ||
− | | | + | | summit_session_attendee_username12 = |
+ | | summit_session_attendee_company12= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12= | ||
+ | |||
| summit_session_attendee_name13 = | | summit_session_attendee_name13 = | ||
| summit_session_attendee_email13 = | | summit_session_attendee_email13 = | ||
− | | | + | | summit_session_attendee_username13 = |
+ | | summit_session_attendee_company13= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13= | ||
+ | |||
| summit_session_attendee_name14 = | | summit_session_attendee_name14 = | ||
| summit_session_attendee_email14 = | | summit_session_attendee_email14 = | ||
− | | | + | | summit_session_attendee_username14 = |
+ | | summit_session_attendee_company14= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14= | ||
+ | |||
| summit_session_attendee_name15 = | | summit_session_attendee_name15 = | ||
| summit_session_attendee_email15 = | | summit_session_attendee_email15 = | ||
− | | | + | | summit_session_attendee_username15 = |
+ | | summit_session_attendee_company15= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15= | ||
+ | |||
| summit_session_attendee_name16 = | | summit_session_attendee_name16 = | ||
| summit_session_attendee_email16 = | | summit_session_attendee_email16 = | ||
− | | | + | | summit_session_attendee_username16 = |
+ | | summit_session_attendee_company16= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16= | ||
+ | |||
| summit_session_attendee_name17 = | | summit_session_attendee_name17 = | ||
| summit_session_attendee_email17 = | | summit_session_attendee_email17 = | ||
− | | | + | | summit_session_attendee_username17 = |
+ | | summit_session_attendee_company17= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17= | ||
+ | |||
| summit_session_attendee_name18 = | | summit_session_attendee_name18 = | ||
| summit_session_attendee_email18 = | | summit_session_attendee_email18 = | ||
− | | | + | | summit_session_attendee_username18 = |
+ | | summit_session_attendee_company18= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18= | ||
+ | |||
| summit_session_attendee_name19 = | | summit_session_attendee_name19 = | ||
| summit_session_attendee_email19 = | | summit_session_attendee_email19 = | ||
− | | | + | | summit_session_attendee_username19 = |
+ | | summit_session_attendee_company19= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19= | ||
+ | |||
| summit_session_attendee_name20 = | | summit_session_attendee_name20 = | ||
| summit_session_attendee_email20 = | | summit_session_attendee_email20 = | ||
− | | | + | | summit_session_attendee_username20 = |
+ | | summit_session_attendee_company20= | ||
+ | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20= | ||
+ | |||
+ | |||
+ | |- | ||
+ | | summit_track_logo = [[Image:T._cross_site.jpg]] | ||
+ | | summit_ws_logo = [[Image:WS._cross_site.jpg]] | ||
+ | | summit_session_name = XSS and the Frameworks | ||
+ | | summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session009 | ||
+ | | mailing_list = | ||
+ | |||
+ | |- | ||
+ | |||
+ | | short_working_session_description= Can we work with the common web frameworks to prevent XSS at the framework level? If the framework a developer uses handles the most common cases of XSS occurring, the overall prevalence of XSS will be reduced significantly. | ||
+ | |||
+ | |||
+ | |- | ||
+ | |||
+ | | related_project_name1 = ESAPI | ||
+ | | related_project_url_1 = http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API | ||
+ | |||
+ | | related_project_name2 = | ||
+ | | related_project_url_2 = | ||
+ | |||
+ | | related_project_name3 = | ||
+ | | related_project_url_3 = | ||
+ | |||
+ | | related_project_name4 = | ||
+ | | related_project_url_4 = | ||
+ | |||
+ | | related_project_name5 = | ||
+ | | related_project_url_5 = | ||
+ | |||
+ | |- | ||
+ | |||
+ | | summit_session_objective_name1= Work on how OWASP can engage with the major web frameworks to move towards a "secure by default" stance | ||
+ | |||
+ | | summit_session_objective_name2 = Work on OWASP resources to provide patches/design approaches in conjunction with the frameworks | ||
+ | |||
+ | | summit_session_objective_name3 = | ||
+ | |||
+ | | summit_session_objective_name4 = | ||
+ | |||
+ | | summit_session_objective_name5 = | ||
+ | |||
+ | |- | ||
+ | |||
+ | | working_session_date_and_time = | ||
+ | |||
+ | |- | ||
+ | |||
+ | | discussion_model = participants and attendees | ||
+ | |||
+ | |- | ||
+ | |||
+ | | operational_resources = Projector, whiteboards, markers, Internet connectivity, power | ||
+ | |||
+ | |- | ||
+ | |||
+ | | working_session_additional_details = *'''Related resources:''' [[OWASP Working Session - Browser Security Letters]] <br> *'''Frameworks to invite:''' .NET, Struts, Spring, Ruby on Rails | ||
+ | |- | ||
+ | |||
+ | |summit_session_deliverable_name1 = OWASP statement/Press release to publicly ask the frameworks to build security in | ||
+ | |||
+ | |summit_session_deliverable_name2 = Engagement plan on how we'd work with (if at all) a framework to get ESAPI or similar functionality integrated | ||
+ | |||
+ | |summit_session_deliverable_name3 = White paper or standard for what we want the web frameworks to provide in terms of XSS defenses. Turning the XSS Prevention Cheat Sheet into a standard/metric for frameworks would be great. | ||
+ | |||
+ | |summit_session_deliverable_name4 = OWASP Standard defining an appraisal methodology for a framework’s XSS prevention capability based on the other deliverable. | ||
+ | |||
+ | |summit_session_deliverable_name5 = | ||
+ | |||
+ | |summit_session_deliverable_name6 = | ||
+ | |||
+ | |summit_session_deliverable_name7 = | ||
+ | |||
+ | |summit_session_deliverable_name8 = | ||
+ | |||
+ | |- | ||
+ | |||
+ | | summit_session_leader_name1 = Justin Clarke | ||
+ | | summit_session_leader_email1 = [email protected] | ||
+ | | summit_session_leader_username1 = Justin42 | ||
+ | |||
+ | | summit_session_leader_name2 = | ||
+ | | summit_session_leader_email2 = | ||
+ | | summit_session_leader_username2 = | ||
+ | |||
+ | | summit_session_leader_name3 = | ||
+ | | summit_session_leader_email3 = | ||
+ | | summit_session_leader_username3 = | ||
+ | |||
+ | |- | ||
+ | |||
+ | | operational_leader_name1 = | ||
+ | | operational_leader_email1 = | ||
+ | | operational_leader_username1 = | ||
+ | |||
+ | |- | ||
+ | |||
+ | | meeting_notes = | ||
+ | |||
|- | |- | ||
| session_name_mask = <!--Please replace DO NOT EDIT this string --> Session009 | | session_name_mask = <!--Please replace DO NOT EDIT this string --> Session009 | ||
| session_home_page = <!--Please replace DO NOT EDIT this string --> Summit_2011_Working_Sessions/Session009 | | session_home_page = <!--Please replace DO NOT EDIT this string --> Summit_2011_Working_Sessions/Session009 | ||
}} | }} |
Latest revision as of 15:58, 7 February 2011
Global Summit 2011 Home Page
Global Summit 2011 Tracks
XSS and the Frameworks | ||||||
---|---|---|---|---|---|---|
Please see/use the 'discussion' page for more details about this Working Session | ||||||
Working Sessions Operational Rules - Please see here the general frame of rules. |
WORKING SESSION IDENTIFICATION | ||||||
---|---|---|---|---|---|---|
Short Work Session Description | Can we work with the common web frameworks to prevent XSS at the framework level? If the framework a developer uses handles the most common cases of XSS occurring, the overall prevalence of XSS will be reduced significantly. | |||||
Related Projects (if any) |
| |||||
Email Contacts & Roles | Chair Justin Clarke @ |
Operational Manager |
Mailing list Subscription Page |
WORKING SESSION SPECIFICS | ||||||
---|---|---|---|---|---|---|
Objectives |
| |||||
Venue/Date&Time/Model | Venue/Room OWASP Global Summit Portugal 2011 |
Date & Time
|
Discussion Model participants and attendees |
|
---|
WORKING SESSION OPERATIONAL RESOURCES | ||||||
---|---|---|---|---|---|---|
Projector, whiteboards, markers, Internet connectivity, power |
|
---|
WORKING SESSION ADDITIONAL DETAILS | ||||||
---|---|---|---|---|---|---|
*Related resources: OWASP Working Session - Browser Security Letters *Frameworks to invite: .NET, Struts, Spring, Ruby on Rails |
WORKING SESSION OUTCOMES / DELIVERABLES | ||
---|---|---|
Proposed by Working Group | Approved by OWASP Board | |
OWASP statement/Press release to publicly ask the frameworks to build security in |
After the Board Meeting - fill in here. | |
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. |
Working Session Participants
(Add you name by clicking "edit" on the tab on the upper left side of this page)
WORKING SESSION PARTICIPANTS | ||||||
---|---|---|---|---|---|---|
Name | Company | Notes & reason for participating, issues to be discussed/addressed | ||||
Chris Eng @ |
|
| ||||
Abraham Kang |
| |||||
Tony UcedaVelez @ |
VerSprite |
| ||||
Fred Donovan @ |
| |||||
Juan Jose Rider @ |
WUL4 |
| ||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
|