This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Summit 2011 Working Sessions/Session002"
Sarah Baso (talk | contribs) (Undo revision 100729 by Sarah Baso (Talk)) |
Sarah Baso (talk | contribs) |
||
Line 1: | Line 1: | ||
− | + | {{Template:<includeonly>{{{1}}}</includeonly><noinclude>Summit 2011 Working Sessions test tab</noinclude> | |
− | <includeonly> | ||
|- | |- | ||
− | | summit_session_attendee_name1 = | + | | summit_session_attendee_name1 = Email John Wilander if you are unable to edit the Wiki and would like to sign up! |
− | | summit_session_attendee_email1 = | + | | summit_session_attendee_email1 = [email protected] |
| summit_session_attendee_company1= | | summit_session_attendee_company1= | ||
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1= | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1= | ||
− | | summit_session_attendee_name2 = | + | | summit_session_attendee_name2 = Michael Coates |
| summit_session_attendee_email2 = | | summit_session_attendee_email2 = | ||
| summit_session_attendee_company2= | | summit_session_attendee_company2= | ||
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2= | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2= | ||
− | | summit_session_attendee_name3 = | + | | summit_session_attendee_name3 = Colin Watson |
| summit_session_attendee_email3 = | | summit_session_attendee_email3 = | ||
| summit_session_attendee_company3= | | summit_session_attendee_company3= | ||
Line 104: | Line 103: | ||
|- | |- | ||
− | | summit_session_name = | + | | summit_track_logo = [[Image:T._browser_security.jpg]] |
+ | | summit_ws_logo = [[Image:WS._browser_security.jpg]] | ||
+ | | summit_session_name = HTML5 Security | ||
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session002 | | summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session002 | ||
− | | mailing_list = | + | | mailing_list = https://groups.google.com/group/owasp-summit-browsersec |
|- | |- | ||
− | | short_working_session_description= | + | | short_working_session_description= |
− | |||
|- | |- | ||
− | | related_project_name1 = | + | | related_project_name1 = Browser Security Track - main page |
− | | related_project_url_1 = | + | | related_project_url_1 = http://www.owasp.org/index.php/Category:Summit_2011_Browser_Security_Track |
− | | related_project_name2 = | + | | related_project_name2 = Google Group for the Browser Security Track |
− | | related_project_url_2 = | + | | related_project_url_2 = https://groups.google.com/group/owasp-summit-browsersec |
| related_project_name3 = | | related_project_name3 = | ||
Line 130: | Line 130: | ||
|- | |- | ||
− | | summit_session_objective_name1= | + | | summit_session_objective_name1= '''Handle autofocus in a unified and secure way'''.<noinclude> Make sure SOP applies for autofocus usage in frame/iframe'd websites. Re-discuss necessity for (future) attributes like this.</noinclude> |
− | |||
− | |||
− | | | + | | summit_session_objective_name2 = '''Discuss necessity and capability for the HTML5 form controls'''.<noinclude> Do we need a non-SOP formaction attribute and why? </noinclude> |
− | | | + | | summit_session_objective_name3 = <noinclude>'''Goal I''':</noinclude>Initiate and create documentation and references for developers that address security issues. <noinclude>Html5sec.org is a start but impossible to continue or extend large scale without vendor help</noinclude> |
− | | | + | | summit_session_objective_name4 = <noinclude>'''Goal II''':</noinclude>Discuss and heavily restrict SVG capabilities - especially when deployed in CSS backgrounds and <img> tags. <noinclude>Mainly Opera and Mozilla are addressed here.</noinclude> |
+ | | summit_session_objective_name5 = '''Long Term Goal(s)''': Provide a working and easy to use as well as vendor supported HTML5 compliant filter software such as HTMLPurifier. <noinclude>Browser vendors should participate in creating security software and filters - not undermine them as we could experience in the last decade.</noinclude> | ||
|- | |- | ||
− | | working_session_date_and_time = | + | | working_session_date_and_time = Tuesday, 09 February <br> Time: TBA |
|- | |- | ||
− | | discussion_model = | + | | discussion_model = The working form will most probably be short presentations to frame the topic and then round table discussions. Depending on number of attendees we'll break into groups. |
|- | |- | ||
Line 154: | Line 153: | ||
|- | |- | ||
− | | working_session_additional_details = | + | | working_session_additional_details = <br> |
+ | |||
+ | [[Image:Html5_mario_hackvertor.jpg]] | ||
+ | |||
+ | ===Co-chair Mario Heiderich=== | ||
+ | Mario Heiderich works as a researcher for the Ruhr-University in Bochum, Germany and currently focuses on HTML5, SVG security and security implications of the ES5 specification draft. Mario invoked the [http://html5sec.org/ HTML5 security cheat-sheet] and maintains the [http://php-ids.org/ PHPIDS filter rules]. In his spare time he delivers trainings and security consultancy for larger German and international companies. He is also one of the co-authors of [http://www.amazon.com/Web-Application-Obfuscation-WAFs-Evasion-Filters-alert/dp/1597496049 Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-'] – a book on how an attacker would bypass different types of security controls including IDS/IPS. | ||
+ | |||
+ | ===Co-chair Gareth Heyes=== | ||
+ | Gareth "Gaz" Heyes calls himself Chief Conspiracy theorist and is affiliated with Microsoft. He is the designer and developer behind [http://www.owasp.org/index.php/OWASP_JavaScript_Sandboxes#tab=JSReg JSReg] – a Javascript sandbox which converts code using regular expressions; [http://www.owasp.org/index.php/OWASP_JavaScript_Sandboxes#tab=HTMLReg HTMLReg] & [http://www.owasp.org/index.php/OWASP_JavaScript_Sandboxes#tab=CSSReg CSSReg] – converters of malicious HTML/CSS into a safe form of HTML. He is also one of the co-authors of [http://www.amazon.com/Web-Application-Obfuscation-WAFs-Evasion-Filters-alert/dp/1597496049 Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-'] – a book on how an attacker would bypass different types of security controls including IDS/IPS. | ||
|- | |- | ||
− | |summit_session_deliverable_name1 = | + | |summit_session_deliverable_name1 = Browser Security Report |
|summit_session_deliverable_url_1 = | |summit_session_deliverable_url_1 = | ||
− | |summit_session_deliverable_name2 = | + | |summit_session_deliverable_name2 = Browser Security Priority List |
|summit_session_deliverable_url_2 = | |summit_session_deliverable_url_2 = | ||
Line 175: | Line 182: | ||
|- | |- | ||
− | | summit_session_leader_name1 = | + | | summit_session_leader_name1 = Mario Heiderich |
| summit_session_leader_email1 = | | summit_session_leader_email1 = | ||
− | | summit_session_leader_name2 = | + | | summit_session_leader_name2 = Gareth Heyes |
| summit_session_leader_email2 = | | summit_session_leader_email2 = | ||
− | | summit_session_leader_name3 = | + | | summit_session_leader_name3 = |
| summit_session_leader_email3 = | | summit_session_leader_email3 = | ||
|- | |- | ||
− | | operational_leader_name1 = | + | | operational_leader_name1 = John Wilander |
− | | operational_leader_email1 = | + | | operational_leader_email1 = [email protected] |
− | |||
|- | |- | ||
− | |||
| meeting_notes = | | meeting_notes = | ||
− | |||
|- | |- | ||
| session_name_mask = <!--Please replace DO NOT EDIT this string --> Session002 | | session_name_mask = <!--Please replace DO NOT EDIT this string --> Session002 | ||
− | | session_home_page = <!--Please replace DO NOT EDIT this string --> Summit_2011_Working_Sessions/Session002 | + | | session_home_page = <!--Please replace DO NOT EDIT this string --> Summit_2011_Working_Sessions/Session002 |
}} | }} | ||
+ | </includeonly> |
Revision as of 01:19, 25 January 2011
Global Summit 2011 Home Page
Global Summit 2011 Tracks
HTML5 Security | ||||||
---|---|---|---|---|---|---|
Please see/use the 'discussion' page for more details about this Working Session | ||||||
Working Sessions Operational Rules - Please see here the general frame of rules. |
WORKING SESSION IDENTIFICATION | ||||||
---|---|---|---|---|---|---|
Short Work Session Description | | |||||
Related Projects (if any) |
| |||||
Email Contacts & Roles | Chair Mario Heiderich Gareth Heyes |
Operational Manager John Wilander @ |
Mailing list https://groups.google.com/group/owasp-summit-browsersec |
WORKING SESSION SPECIFICS | ||||||
---|---|---|---|---|---|---|
Objectives |
| |||||
Venue/Date&Time/Model | Venue/Room OWASP Global Summit Portugal 2011 |
Date & Time Tuesday, 09 February Time: TBA
|
Discussion Model The working form will most probably be short presentations to frame the topic and then round table discussions. Depending on number of attendees we'll break into groups. |
|
---|
WORKING SESSION OPERATIONAL RESOURCES | ||||||
---|---|---|---|---|---|---|
Projector, whiteboards, markers, Internet connectivity, power |
|
---|
WORKING SESSION ADDITIONAL DETAILS | ||||||
---|---|---|---|---|---|---|
Co-chair Mario HeiderichMario Heiderich works as a researcher for the Ruhr-University in Bochum, Germany and currently focuses on HTML5, SVG security and security implications of the ES5 specification draft. Mario invoked the HTML5 security cheat-sheet and maintains the PHPIDS filter rules. In his spare time he delivers trainings and security consultancy for larger German and international companies. He is also one of the co-authors of Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-' – a book on how an attacker would bypass different types of security controls including IDS/IPS. Co-chair Gareth HeyesGareth "Gaz" Heyes calls himself Chief Conspiracy theorist and is affiliated with Microsoft. He is the designer and developer behind JSReg – a Javascript sandbox which converts code using regular expressions; HTMLReg & CSSReg – converters of malicious HTML/CSS into a safe form of HTML. He is also one of the co-authors of Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-' – a book on how an attacker would bypass different types of security controls including IDS/IPS. |
WORKING SESSION OUTCOMES / DELIVERABLES | ||
---|---|---|
Proposed by Working Group | Approved by OWASP Board | |
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. |
Working Session Participants
(Add you name by clicking "edit" on the tab on the upper left side of this page)
WORKING SESSION PARTICIPANTS | ||||||
---|---|---|---|---|---|---|
Name | Company | Notes & reason for participating, issues to be discussed/addressed | ||||
Email John Wilander if you are unable to edit the Wiki and would like to sign up! @ |
|
| ||||
Michael Coates |
| |||||
Colin Watson |
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
|
</includeonly>