This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Summit 2011 Working Sessions/Session003"
Sarah Baso (talk | contribs) |
Sarah Baso (talk | contribs) |
||
| Line 2: | Line 2: | ||
|- | |- | ||
| − | | summit_session_attendee_name1 = | + | | summit_session_attendee_name1 = John Wilander |
| summit_session_attendee_email1 = [email protected] | | summit_session_attendee_email1 = [email protected] | ||
| summit_session_attendee_company1= | | summit_session_attendee_company1= | ||
| Line 132: | Line 132: | ||
| summit_session_objective_name1= '''Fix the problems with Object.defineProperty() and property unsealing / [https://bugzilla.mozilla.org/show_bug.cgi?id=588138 double-freezing]'''.<noinclude> Implement it if not yet done.</noinclude> | | summit_session_objective_name1= '''Fix the problems with Object.defineProperty() and property unsealing / [https://bugzilla.mozilla.org/show_bug.cgi?id=588138 double-freezing]'''.<noinclude> Implement it if not yet done.</noinclude> | ||
| − | | summit_session_objective_name2 = <noinclude>'''Goal I''': </noinclude> Raise awareness for the power or object freezing in a security context. <noinclude>ES5 can really make a change here.<noinclude> | + | | summit_session_objective_name2 = <noinclude>'''Goal I''': </noinclude>Raise awareness for the power or object freezing in a security context. <noinclude>ES5 can really make a change here.</noinclude> |
| summit_session_objective_name3 = <noinclude>'''Goal II''':</noinclude> Raise awareness in seeing the DOM as the place where XSS attacks actually take place - and where they should be prevented. <noinclude> CSP is a great yet still immature start - but worth discussing and extending. Discuss specification drafts for a secure DOM and easy to configure capability profiles with reasonable and quantitative proofs of concept.</noinclude> | | summit_session_objective_name3 = <noinclude>'''Goal II''':</noinclude> Raise awareness in seeing the DOM as the place where XSS attacks actually take place - and where they should be prevented. <noinclude> CSP is a great yet still immature start - but worth discussing and extending. Discuss specification drafts for a secure DOM and easy to configure capability profiles with reasonable and quantitative proofs of concept.</noinclude> | ||
| − | | summit_session_objective_name4 = | + | | summit_session_objective_name4 = '''Long Term Goal''': Discuss the possibility of vendor supported client side security mechanisms. <noinclude>Client side IDS/IPS based on ES5 can be possible - yet have to be designed and specified. </noinclude> |
| summit_session_objective_name5 = | | summit_session_objective_name5 = | ||
Revision as of 02:38, 25 January 2011
Global Summit 2011 Home Page
Global Summit 2011 Tracks
| Please see/use the 'discussion' page for more details about this Working Session | ||||||
|---|---|---|---|---|---|---|
| Working Sessions Operational Rules - Please see here the general frame of rules. |
| WORKING SESSION IDENTIFICATION | ||||||
|---|---|---|---|---|---|---|
| Short Work Session Description | | |||||
| Related Projects (if any) |
| |||||
| Email Contacts & Roles | Chair Mario Heiderich TBC |
Operational Manager John Wilander @ |
Mailing list https://groups.google.com/group/owasp-summit-browsersec | |||
| WORKING SESSION SPECIFICS | ||||||
|---|---|---|---|---|---|---|
| Objectives |
| |||||
| Venue/Date&Time/Model | Venue/Room OWASP Global Summit Portugal 2011 |
Date & Time Tuesday, 09 February Time: TBA
|
Discussion Model The working form will most probably be short presentations to frame the topic and then round table discussions. Depending on number of attendees we'll break into groups. | |||
| |
|---|
| WORKING SESSION OPERATIONAL RESOURCES | ||||||
|---|---|---|---|---|---|---|
| Projector, whiteboards, markers, Internet connectivity, power | ||||||
| |
|---|
| WORKING SESSION ADDITIONAL DETAILS | ||||||
|---|---|---|---|---|---|---|
Co-chair Mario HeiderichMario Heiderich works as a researcher for the Ruhr-University in Bochum, Germany and currently focuses on HTML5, SVG security and security implications of the ES5 specification draft. Mario invoked the HTML5 security cheat-sheet and maintains the PHPIDS filter rules. In his spare time he delivers trainings and security consultancy for larger German and international companies. He is also one of the co-authors of Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-' – a book on how an attacker would bypass different types of security controls including IDS/IPS. Co-chair 2To be confirmed. | ||||||
| WORKING SESSION OUTCOMES / DELIVERABLES | ||
|---|---|---|
| Proposed by Working Group | Approved by OWASP Board | |
| After the Board Meeting - fill in here. | ||
| After the Board Meeting - fill in here. | ||
| After the Board Meeting - fill in here. | ||
| After the Board Meeting - fill in here. | ||
| After the Board Meeting - fill in here. | ||
| After the Board Meeting - fill in here. | ||
| After the Board Meeting - fill in here. | ||
| After the Board Meeting - fill in here. | ||
Working Session Participants
(Add you name by clicking "edit" on the tab on the upper left side of this page)
| WORKING SESSION PARTICIPANTS | ||||||
|---|---|---|---|---|---|---|
| Name | Company | Notes & reason for participating, issues to be discussed/addressed | ||||
| John Wilander @ |
|
| ||||
| Michael Coates |
| |||||
| Colin Watson |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
| |
| |||||
</includeonly>