This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Summit 2011 Working Sessions/Session043"

From OWASP
Jump to: navigation, search
Line 105: Line 105:
 
| summit_track_logo = [[Image:T._cross_site.jpg]]
 
| summit_track_logo = [[Image:T._cross_site.jpg]]
 
| summit_ws_logo = [[Image:WS._cross_site.jpg]]
 
| summit_ws_logo = [[Image:WS._cross_site.jpg]]
| summit_session_name = ModSecurity (WAF)
+
| summit_session_name = WAF Mitigations for XSS
 
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session043
 
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session043
  
 
|-
 
|-
  
| short_working_session_description=
+
| short_working_session_description= To discuss if/when/how web application firewalls can help to prevent XSS attacks
  
 
|-
 
|-
Line 131: Line 131:
 
|-
 
|-
  
| summit_session_objective_name1=  
+
| summit_session_objective_name1= Improve XSS Attack Payload Detection Techniques
  
| summit_session_objective_name2 =  
+
| summit_session_objective_name2 = Identifying Improper Output Handling Flaws in Web Apps
  
| summit_session_objective_name3 =  
+
| summit_session_objective_name3 = Feasibility of Profile Page Scripts/Iframes
  
| summit_session_objective_name4 =  
+
| summit_session_objective_name4 = Testing Injection of JS Sandbox Code in Responses
  
 
| summit_session_objective_name5 =   
 
| summit_session_objective_name5 =   

Revision as of 16:49, 12 January 2011

Global Summit 2011 Home Page
Global Summit 2011 Tracks

WS. cross site.jpg WAF Mitigations for XSS
Please see/use the 'discussion' page for more details about this Working Session
Working Sessions Operational Rules - Please see here the general frame of rules.
WORKING SESSION IDENTIFICATION
Short Work Session Description To discuss if/when/how web application firewalls can help to prevent XSS attacks
Related Projects (if any)


Email Contacts & Roles Chair
Ryan Barnett @

Operational Manager
Mailing list
{{{mailing_list}}}
WORKING SESSION SPECIFICS
Objectives
  1. Improve XSS Attack Payload Detection Techniques
  2. Identifying Improper Output Handling Flaws in Web Apps
  3. Feasibility of Profile Page Scripts/Iframes
  4. Testing Injection of JS Sandbox Code in Responses

Venue/Date&Time/Model Venue/Room
OWASP Global Summit Portugal 2011
Date & Time


Discussion Model
participants and attendees

WORKING SESSION OPERATIONAL RESOURCES
Projector, whiteboards, markers, Internet connectivity, power

WORKING SESSION ADDITIONAL DETAILS
WORKING SESSION OUTCOMES / DELIVERABLES
Proposed by Working Group Approved by OWASP Board

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

{{{summit_session_deliverable_name6}}}

After the Board Meeting - fill in here.

{{{summit_session_deliverable_name7}}}

After the Board Meeting - fill in here.

{{{summit_session_deliverable_name8}}}

After the Board Meeting - fill in here.

Working Session Participants

(Add you name by clicking "edit" on the tab on the upper left side of this page)

WORKING SESSION PARTICIPANTS
Name Company Notes & reason for participating, issues to be discussed/addressed