This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Summit 2011/OWASP Secure Coding Workshop"

From OWASP
Jump to: navigation, search
Line 13: Line 13:
 
|-
 
|-
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Work Session Name'''  
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Work Session Name'''  
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | <font color="black"><span style="font-weight: bold;">Browser Working Group</span></font>
+
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | <font color="black"><span style="font-weight: bold;">No Fluff, Just Stuff</span></font>
 
|-
 
|-
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Short Work Session Description'''  
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Short Work Session Description'''  
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | One of the great challenges of application security is browser security. The browser is becoming our de facto runtime platform for applications and it comprises a whole ecosystem of plug-ins and web technologies. Therefore we will spend a full day working together with the leading browser vendors to penetrate current problems, new ideas, and how security fits in alongside other requirements from developers and end-users. Do not miss this chance to influence what's important in browser security in the coming years. <br>
+
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | <br>
 
|-
 
|-
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Related Projects (if any)'''  
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Related Projects (if any)'''  
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | [http://www.owasp.org/index.php/Working_Sessions_Browser_Working_Group_Sandboxing Sandboxing], [http://www.owasp.org/index.php/Working_Sessions_Browser_Working_Group_Securing_Plugins Securing Plugins], [http://www.owasp.org/index.php/Working_Sessions_Browser_Working_Group_Enduser_Warnings Enduser Warnings], [http://www.owasp.org/index.php/Working_Sessions_Browser_Working_Group_Blacklisting Blacklisting], [http://www.owasp.org/index.php/Working_Sessions_Browser_Working_Group_OS_Integration OS Integration], [http://www.owasp.org/index.php/Working_Sessions_Browser_Working_Group_JavaScript JavaScript], [http://www.owasp.org/index.php/Working_Sessions_Browser_Working_Group_New_HTTP_Headers New HTTP Headers]
+
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
 
|-
 
|-
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Email Contacts &amp; Roles'''  
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Email Contacts &amp; Roles'''  
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | '''Chair'''<br>[mailto:john.wilander@owasp.org '''John Wilander''']  
+
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | '''Chair'''<br>[mailto:John.Steven@owasp.org '''John Steven''']  
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | '''Secretary'''<br>  
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | '''Secretary'''<br>  
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | '''Mailing list'''<br>[http://www.owasp.org/index.php/Summit_2011#tab=How_Do_I_Join.3F_.2F_Mailing_list '''Subscription Page''']
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | '''Mailing list'''<br>[http://www.owasp.org/index.php/Summit_2011#tab=How_Do_I_Join.3F_.2F_Mailing_list '''Subscription Page''']
Line 32: Line 32:
 
|-
 
|-
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Objectives'''  
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Objectives'''  
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | <font color="black"></font><font color="black"></font><font color="black">
+
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | <font color="black"></font><font color="black"></font><font color="black"> </font>  
#Work on and discuss how to enhance enduser security in web applications,
 
#Work on and discuss browser-based countermeasures against XSS, CSRF, man-in-the-middle, man-in-the-browser and full remote access exploits.</font>  
 
  
 
|-
 
|-
Line 67: Line 65:
 
|-
 
|-
 
| align="left" style="width: 100%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
 
| align="left" style="width: 100%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
*'''Related resources:''' [[OWASP Working Session - Browser Security Letters]]
 
*'''Browser vendors invited: '''Apple, Google, Microsoft, Mozilla, Opera
 
 
 
|}
 
|}
  
Line 81: Line 76:
 
|-
 
|-
 
| align="center" style="width: 7%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | <br>
 
| align="center" style="width: 7%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | <br>
| align="center" style="width: 46%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | Enhanced cooperation between browser vendors.
+
| align="center" style="width: 46%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" |  
 
| align="center" style="width: 47%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | After the Board Meeting - fill in here.
 
| align="center" style="width: 47%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | After the Board Meeting - fill in here.
 
|-
 
|-
 
| align="center" style="width: 7%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | <br>
 
| align="center" style="width: 7%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | <br>
| align="center" style="width: 46%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | A new role for OWASP in this area.
+
| align="center" style="width: 46%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" |  
 
| align="center" style="width: 47%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | After the Board Meeting - fill in here.
 
| align="center" style="width: 47%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | After the Board Meeting - fill in here.
 
|}
 
|}

Revision as of 21:56, 13 December 2010

Global Summit 2011 Home Page
Global Summit 2011 Schedule
Global Summit 2011 Working Sessions

Working Sessions Operational Rules - Please see here the general frame of rules.
WORKING SESSION IDENTIFICATION
Work Session Name No Fluff, Just Stuff
Short Work Session Description
Related Projects (if any)
Email Contacts & Roles Chair
John Steven
Secretary
Mailing list
Subscription Page
WORKING SESSION SPECIFICS
Objectives
Venue/Date&Time/Model Venue
OWASP Global Summit Portugal 2011

Date&Time

Discussion Model
Open Space, demo-driven discussion, round-table discussions (i e not a PowerPoint race ;)

WORKING SESSION OPERATIONAL RESOURCES
Projector, whiteboards, markers, Internet connectivity, post-it notes, power

WORKING SESSION ADDITIONAL DETAILS
WORKING SESSION OUTCOMES
Statements, Initiatives or Decisions Proposed by Working Group Approved by OWASP Board

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

Working Session Participants

Working Session Participants

Name Company Notes & reason for participating, issues to be discussed/addressed
view edit Sample Only! Go to Summit_2011_Attendee to enter your info.
view edit Sample Only! Go to Summit_2011_Attendee to enter your info.