This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Working Sessions XSS Eradication"

From OWASP
Jump to: navigation, search
(Created page with '[http://www.owasp.org/index.php/Summit_2011 ''' Global Summit 2011 Home Page''']<br> [http://www.owasp.org/index.php/Summit_2011_Schedule ''' Global Summit 2011 Schedule''']<br> …')
 
Line 2: Line 2:
 
[http://www.owasp.org/index.php/Summit_2011_Schedule ''' Global Summit 2011 Schedule''']<br>
 
[http://www.owasp.org/index.php/Summit_2011_Schedule ''' Global Summit 2011 Schedule''']<br>
 
[http://www.owasp.org/index.php/Summit_2011_Working_Sessions ''' Global Summit 2011 Working Sessions''']
 
[http://www.owasp.org/index.php/Summit_2011_Working_Sessions ''' Global Summit 2011 Working Sessions''']
 +
  
 
{| border="0" align="center" style="width: 100%;"
 
{| border="0" align="center" style="width: 100%;"
 
|-
 
|-
! align="center" style="background: none repeat scroll 0% 0% rgb(179, 179, 179); color: white;" colspan="7" | <font color="black">'''Working Sessions Operational Rules''' - [[:Working Sessions Methodology|'''Please see here the general frame of rules''']].</font>
+
! align="center" colspan="7" style="background: none repeat scroll 0% 0% rgb(179, 179, 179); color: white;" | <font color="black">'''Working Sessions Operational Rules''' - [[:Working Sessions Methodology|'''Please see here the general frame of rules''']].</font>
 
|}
 
|}
  
 
{| border="0" align="center" style="width: 100%;"
 
{| border="0" align="center" style="width: 100%;"
 
|-
 
|-
! align="center" style="background: none repeat scroll 0% 0% rgb(64, 88, 160); color: white;" colspan="7" | <font color="white">'''WORKING SESSION IDENTIFICATION'''</font>
+
! align="center" colspan="7" style="background: none repeat scroll 0% 0% rgb(64, 88, 160); color: white;" | <font color="white">'''WORKING SESSION IDENTIFICATION'''</font>
 
|-
 
|-
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Work Session Name'''  
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Work Session Name'''  
| align="left" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" colspan="6" | <font color="black"><span style="font-weight: bold;"> Cross-Site Scripting Eradication</span></font><br>
+
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | <font color="black"><span style="font-weight: bold;">Cross-Site Scripting Eradication</span></font>
 
|-
 
|-
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Short Work Session Description'''  
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Short Work Session Description'''  
| align="left" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" colspan="6" | Let's make 2011 the OWASP year of XSS... eradication. As part of that effort, we need to get the word out as we never have before. To achieve this we are going to have to spread the word and knowledge through more than just OWASP - who can we partner with (commercial and non-commercial)? What freely available resources can we reference? How can we reach developers and get them what they need in order to be more effective with regards to XSS?<br>
+
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | Let's make 2011 the OWASP year of XSS... eradication. As part of that effort, we need to get the word out as we never have before. To achieve this we are going to have to spread the word and knowledge through more than just OWASP - who can we partner with (commercial and non-commercial)? What freely available resources can we reference? How can we reach developers and get them what they need in order to be more effective with regards to XSS?<br>
 +
 
 
|-
 
|-
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Related Projects (if any)'''  
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Related Projects (if any)'''  
| align="left" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" colspan="6" | [http://www.owasp.org/index.php/Working_Sessions_XSS_Frameworks XSS and the Frameworks]
+
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | <br>
|-
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Email Contacts &amp; Roles'''
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | '''Chair'''<br>[mailto:[email protected] '''Justin Clarke''']
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | '''Secretary'''<br>
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | '''Mailing list'''<br>[http://www.owasp.org/index.php/Summit_2011#tab=How_Do_I_Join.3F_.2F_Mailing_list '''Subscription Page''']
 
 
|}
 
|}
 
+
<br>
 
{| border="0" align="center" style="width: 100%;"
 
{| border="0" align="center" style="width: 100%;"
 
|-
 
|-
! align="center" style="background: none repeat scroll 0% 0% rgb(64, 88, 160); color: white;" colspan="7" | <font color="white">'''WORKING SESSION SPECIFICS'''</font>
+
! align="center" colspan="7" style="background: none repeat scroll 0% 0% rgb(64, 88, 160); color: white;" | <font color="white">'''WORKING SESSION SPECIFICS'''</font>
 
|-
 
|-
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Objectives'''  
 
| align="center" style="width: 15%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Objectives'''  
| align="left" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" colspan="6" | <font color="black"></font><font color="black"></font><font color="black"></font><font color="black"></font><font color="black"></font><font color="black"></font><font color="black"></font><font color="black"></font>
+
| align="left" colspan="6" style="width: 85%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | <font color="black"></font><font color="black"></font><font color="black"></font>  
# Work on what partners we can reach, and what resources they can provide us access to
+
 
# Work on who we can work with to reach a maximum amount of developers writing web applications
 
# Plan engagement with identified organizations
 
# Plan a call to action for OWASP chapters for identified XSS resources
 
 
|-
 
|-
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Venue/Date&amp;Time/Model'''  
 
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Venue/Date&amp;Time/Model'''  
Line 47: Line 41:
 
|}
 
|}
  
{| border="0" align="center" style="width: 100%;"
+
<br>
|-
 
! align="center" style="background: none repeat scroll 0% 0% white; color: white;" colspan="7" | <font color="black"></font> <br>
 
|}
 
  
 
{| border="0" align="center" style="width: 100%;"
 
{| border="0" align="center" style="width: 100%;"
 
|-
 
|-
! align="center" style="background: none repeat scroll 0% 0% rgb(64, 88, 160); color: white;" colspan="7" | <font color="white">'''WORKING SESSION OPERATIONAL RESOURCES'''</font>
+
! align="center" colspan="4" style="background: none repeat scroll 0% 0% rgb(64, 88, 160); color: white;" | <font color="white">'''WORKING SESSION ADDITIONAL DETAILS'''</font>
 
|-
 
|-
| align="center" style="width: 100%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | Projector, whiteboards, markers, Internet connectivity, power
+
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Working Session Pages''' <br>
|}
+
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Chair'''<br>
 
+
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | '''Secretary'''<br>
{| border="0" align="center" style="width: 100%;"
+
| align="center" style="width: 25%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" |
 
|-
 
|-
! align="center" style="background: none repeat scroll 0% 0% white; color: white;" colspan="7" | <font color="black"></font> <br>
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | [[:Working Sessions XSS Frameworks|'''Cross-Site Scripting: Frameworks''']]
|}
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | [mailto:[email protected] '''Justin Clarke''']
 
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
{| border="0" align="center" style="width: 100%;"
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
 
|-
 
|-
! align="center" style="background: none repeat scroll 0% 0% rgb(64, 88, 160); color: white;" colspan="7" | <font color="white">'''WORKING SESSION ADDITIONAL DETAILS'''</font>
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | [[:Working Sessions XSS AwarnessResourcesPartnerships|'''Cross-Site Scripting: Awarenes, Resources, and Partnerships''']]
 +
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" | [mailto:[email protected] '''Justin Clarke''']
 +
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
 +
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
 
|-
 
|-
| align="left" style="width: 100%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
*'''Related resources:''' [[OWASP Working Session - Browser Security Letters]]
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
*'''Partners to invite:''' HP, Veracode, IBM (others?)  
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
 
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
|}
 
 
 
{| border="0" align="center" style="width: 100%;"
 
 
|-
 
|-
! align="center" style="background: none repeat scroll 0% 0% rgb(64, 88, 160); color: white;" colspan="3" | '''WORKING SESSION OUTCOMES'''
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
 +
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
 +
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
 +
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
 
|-
 
|-
| align="center" style="width: 7%; background: none repeat scroll 0% 0% rgb(108, 130, 181);" | Statements, Initiatives or Decisions
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
| align="center" style="width: 46%; background: none repeat scroll 0% 0% rgb(179, 179, 179);" | '''Proposed by Working Group'''
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
| align="center" style="width: 47%; background: none repeat scroll 0% 0% rgb(179, 179, 179);" | '''Approved by OWASP Board'''
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
 +
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
 
|-
 
|-
| align="center" style="width: 7%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | <br>
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
| align="center" style="width: 46%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" |  
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
| align="center" style="width: 47%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | After the Board Meeting - fill in here.
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
 +
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
 
|-
 
|-
| align="center" style="width: 7%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | <br>
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
| align="center" style="width: 46%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" |
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
| align="center" style="width: 47%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | After the Board Meeting - fill in here.
+
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |
 +
| align="left" style="width: 25%; background: none repeat scroll 0% 0% rgb(204, 204, 204);" |  
 
|}
 
|}
  
== Working Session Participants  ==
 
  
{{:Template:Summit 2011 Working Sessions Attendee/Columns}}
+
[[Category:OWASP_Working_Session]]
{{:Summit_2011_Attendee/Attendee008 | Summit 2011 Working Sessions Attendee/Rows_Browser_Security}}
+
[[Category:Summit_2011]]
{{:Summit_2011_Attendee/Attendee052 | Summit 2011 Working Sessions Attendee/Rows_Browser_Security}}
 
 
 
|}
 
<br>
 
[[Category:OWASP_Working_Session]] [[Category:Summit_2011]]
 

Revision as of 02:35, 14 December 2010

Global Summit 2011 Home Page
Global Summit 2011 Schedule
Global Summit 2011 Working Sessions


Working Sessions Operational Rules - Please see here the general frame of rules.
WORKING SESSION IDENTIFICATION
Work Session Name Cross-Site Scripting Eradication
Short Work Session Description Let's make 2011 the OWASP year of XSS... eradication. As part of that effort, we need to get the word out as we never have before. To achieve this we are going to have to spread the word and knowledge through more than just OWASP - who can we partner with (commercial and non-commercial)? What freely available resources can we reference? How can we reach developers and get them what they need in order to be more effective with regards to XSS?
Related Projects (if any)


WORKING SESSION SPECIFICS
Objectives
Venue/Date&Time/Model Venue
OWASP Global Summit Portugal 2011

Date&Time


Discussion Model
"Participants + Attendees"


WORKING SESSION ADDITIONAL DETAILS
Working Session Pages
Chair
Secretary
Cross-Site Scripting: Frameworks Justin Clarke
Cross-Site Scripting: Awarenes, Resources, and Partnerships Justin Clarke