<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: owasp]]></title>
    <link>http://securityratty.com/tag/owasp</link>
    <description></description>
    <pubDate>Mon, 29 Sep 2008 06:06:04 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Team Foundation Server (TFS) and the Open Web Application Security Project (OWASP) Top Ten]]></title>
      <link>http://securityratty.com/article/cfc1b01afc96e6d273324073e35586f8</link>
      <guid>http://securityratty.com/article/cfc1b01afc96e6d273324073e35586f8</guid>
      <description><![CDATA[Nice article over on MSDN...]]></description>
      <content:encoded><![CDATA[Nice article over on MSDN here.
&#160;&#160;&#160;&#160;&#160;&#160;     ]]></content:encoded>
      <pubDate>Fri, 21 Nov 2008 09:25:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nice article">nice article</category>
      <category domain="http://securityratty.com/tag/msdn">msdn</category>
      <source url="http://securitybuddha.com/2008/11/21/team-foundation-server-tfs-and-the-open-web-application-security-project-owasp-top-ten/">Team Foundation Server (TFS) and the Open Web Application Security Project (OWASP) Top Ten</source>
    </item>
    <item>
      <title><![CDATA[OWASP CISO Panel]]></title>
      <link>http://securityratty.com/article/02381b4b5ab244f9ac7b901745eff569</link>
      <guid>http://securityratty.com/article/02381b4b5ab244f9ac7b901745eff569</guid>
      <description><![CDATA[I didnt go to OWASP NYC (put off by the vulnerability circus to be brutally honest) but I just watched the CISO panel and its just fantastic to see a panel of CISOs discussing really important...]]></description>
      <content:encoded><![CDATA[I didn&#8217;t go to OWASP NYC (put off by the vulnerability circus to be brutally honest) but I just watched the CISO panel and it&#8217;s just fantastic to see a panel of CISO&#8217;s discussing really important application security topics.
Jim Routh



&#8216;&#8230;..view application security as a supply chain management problem&#8217;. Very wise!

&#8216;Static analysis tools are most effective [...]]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 08:43:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/panel">panel</category>
      <category domain="http://securityratty.com/tag/ciso panel">ciso panel</category>
      <category domain="http://securityratty.com/tag/view application security">view application security</category>
      <category domain="http://securityratty.com/tag/static analysis tools">static analysis tools</category>
      <category domain="http://securityratty.com/tag/supply chain management">supply chain management</category>
      <category domain="http://securityratty.com/tag/application security topics">application security topics</category>
      <category domain="http://securityratty.com/tag/vulnerability circus">vulnerability circus</category>
      <category domain="http://securityratty.com/tag/owasp nyc">owasp nyc</category>
      <category domain="http://securityratty.com/tag/jim routh">jim routh</category>
      <source url="http://securitybuddha.com/2008/10/20/owasp-ciso-panel/">OWASP CISO Panel</source>
    </item>
    <item>
      <title><![CDATA[OWASP Twin Cities Mini-Conference]]></title>
      <link>http://securityratty.com/article/e0f944dc07d50df7bce30caa0440c715</link>
      <guid>http://securityratty.com/article/e0f944dc07d50df7bce30caa0440c715</guid>
      <description><![CDATA[Next week, there will be an OWASP Mini-Conference right here in the Twin Cities.I am sorry that I will have to miss it, but the lineup is great - Brian Chess , Jeff WIlliams , RIchard Stallman and a...]]></description>
      <content:encoded><![CDATA[<p>Next week, there will be an <a href="https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference">OWASP Mini-Conference</a> right here in the Twin Cities.&#0160;I am sorry that I will have to miss it, but the lineup is great - <a href="http://extra.fortifysoftware.com/blog/">Brian Chess</a>, <a href="http://www.aspectsecurity.com/">Jeff WIlliams</a>, RIchard Stallman and a number of others. Brian and Jeff are both very engaging presenters. I am curious to hear what Stallman says, I am not sure I have heard of him being associated with OWASP or security work in general before, and I have read any number of his comments that seem to directly oppose security mechanisms. In any case it promises to be worth the price of admission.</p><br /><div>I have spoken at a number of local OWASP conferences, and you can always see that the good ones are the result of a lot of hard work by a small group of people. Bob Sullivan really brought the Minnesota chapter through its adolescence very nicely, building a good base, and now Kuai Hinojosa is doing some phenomenal work growing the chapter. Kuai has serious networking skills, I would love to see Kuai, <a href="http://duckdown.blogspot.com/">James McGovern</a> and other successful OWASP leaders put together a Top 10 list for how grow a chapter. These are things I don&#39;t know the first thing how to do, but you can sure see the results. I am pretty sure a lot of other OWASP leaders could benefit from these guys&#39; insights.</div>]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 15:58:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/owasp">owasp</category>
      <category domain="http://securityratty.com/tag/successful owasp leaders">successful owasp leaders</category>
      <category domain="http://securityratty.com/tag/owasp leaders">owasp leaders</category>
      <category domain="http://securityratty.com/tag/owasp mini-conference">owasp mini-conference</category>
      <category domain="http://securityratty.com/tag/kuai">kuai</category>
      <category domain="http://securityratty.com/tag/chapter">chapter</category>
      <category domain="http://securityratty.com/tag/kuai hinojosa">kuai hinojosa</category>
      <category domain="http://securityratty.com/tag/local owasp conferences">local owasp conferences</category>
      <category domain="http://securityratty.com/tag/minnesota chapter">minnesota chapter</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/owasp-twin-cities-mini-conference.html">OWASP Twin Cities Mini-Conference</source>
    </item>
    <item>
      <title><![CDATA[OWASP European Summit - Portugal]]></title>
      <link>http://securityratty.com/article/ea11601c79d7b13866fce47288b63fbd</link>
      <guid>http://securityratty.com/article/ea11601c79d7b13866fce47288b63fbd</guid>
      <description><![CDATA[Portugal/Algarve - 4th - 7th November 2008
Setting the Web Application Security Agenda for 2009: OWASP Invites You to Join Our Summit in Portugal
http://www.owasp.org/index.php/OWASP EU Summit 2008...]]></description>
      <content:encoded><![CDATA[<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;"><em><span style="font-size: small;">Portugal/Algarve - 4th - 7th November 2008</span></em></p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;"><span style="font-weight: bold;">Setting the Web Application Security Agenda for 2009: OWASP Invites You to Join Our Summit in Portugal</span></p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;"><a style="text-decoration: none; color: #3366bb;" title="http://www.owasp.org/index.php/OWASP_EU_Summit_2008" rel="nofollow" href="http://www.owasp.org/index.php/OWASP_EU_Summit_2008" target="_blank"><span style="font-weight: bold;">http://www.owasp.org/index.php/OWASP_EU_Summit_2008</span></a></p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">With the theme <span style="font-style: italic;">&#8216;Setting the AppSec agenda for 2009&#8242;</span>, the OWASP Summit will be a worldwide gathering of OWASP leaders and key industry players to present and discuss the latest OWASP tools, documentation projects, and web application security trends. Join us in Portugal in just a few short weeks! This venue hosts a diverse selection of training courses along with technical and business tracks, making it THE place to learn about web application security and the resources OWASP has available for use today.</p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">OWASP is a not-for-profit organization with the purpose of supporting the Web Application Security community around the world, and has granted $250,000 USD for web application security research. In addition to over 40 presentations from the OWASP Leaders and grant recipients, the OWASP Summit will host multiple Working Sessions designed to improve collaboration, achieve specific objectives and identify roadmaps for OWASP projects, chapters, and the OWASP community itself.</p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">To facilitate this event, OWASP is investing $150,000 USD which will be used to cover air travel and accommodation expenses for OWASP leaders, active contributors, and select key industry leaders. With their confirmed presence, the OWASP Summit will provide a relaxed but professional environment to meet, discuss, influence and contribute to OWASP projects.</p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">There are still funds available! If you are interested in attending and you meet the profile of the current OWASP supported attendees (see list here: <a style="text-decoration: none; color: #3366bb;" title="http://spreadsheets.google.com/pub?key=pAX6n7m2zaTVLrPtR07riBA" rel="nofollow" href="http://spreadsheets.google.com/pub?key=pAX6n7m2zaTVLrPtR07riBA" target="_blank">http://spreadsheets.google.com/pub?key=pAX6n7m2zaTVLrPtR07riBA</a>) contact Paulo Coimbra (<a href="mailto:paulo.coimbra@owasp.org" target="_blank">paulo.coimbra@owasp.org</a>). Please note that you should do so only if you meet the paid attendance criteria (see here<a style="text-decoration: none; color: #3366bb;" title="https://www.owasp.org/index.php/OWASP_EU_Summit_2008_paid_participation_rules" rel="nofollow" href="https://www.owasp.org/index.php/OWASP_EU_Summit_2008_paid_participation_rules" target="_blank">https://www.owasp.org/index.php/OWASP_EU_Summit_2008_paid_participation_rules</a>) and are unable to get corporate support to attend this event (for other corporate sponsorship opportunities see <a style="text-decoration: none; color: #3366bb;" title="http://www.owasp.org/index.php/OWASP_EU_Summit_2008_Sponsors" rel="nofollow" href="http://www.owasp.org/index.php/OWASP_EU_Summit_2008_Sponsors" target="_blank">http://www.owasp.org/index.php/OWASP_EU_Summit_2008_Sponsors</a>).</p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">The OWASP Summit will also host a large and diverse selection of training courses, covering multiple OWASP specific and Web Application Security Topics.</p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">The remarkable impact of OWASP is made possible only by the collaboration of many dedicated people and organizations worldwide. In that spirit of cooperation, OWASP invites all its members (who have 20% discount + 1 VIP Ticket) and interested individuals and companies to attend this thrilling event. Please join us and help to set the Web Application Security Agenda for 2009!</p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">Please see below for additional details about the OWASP Summit or visit the OWASP Summit website: <a style="text-decoration: none; color: #3366bb;" title="http://www.owasp.org/index.php/OWASP_EU_Summit_2008" rel="nofollow" href="http://www.owasp.org/index.php/OWASP_EU_Summit_2008" target="_blank">http://www.owasp.org/index.php/OWASP_EU_Summit_2008</a>.</p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;"><strong>Projects</strong></p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">OWASP projects selected for Summit presentation include new documentation and innovative tools to help developers, architects, and security specialists ensure that applications are secure:</p>
<ul style="margin: 0.3em 0px 0px 1.5em; padding: 0px; line-height: 1.5em; list-style-type: square;">
<li style="margin-bottom: 0.1em;">Application Security Verification Standard,</li>
<li style="margin-bottom: 0.1em;">Code review guide, V1.1,</li>
<li style="margin-bottom: 0.1em;">Ruby on Rails Security Guide v2,</li>
<li style="margin-bottom: 0.1em;"> Securing WebGoat using ModSecurity,</li>
<li style="margin-bottom: 0.1em;">Testing Guide v3,</li>
<li style="margin-bottom: 0.1em;">GTK+ GUI for w3af project,</li>
<li style="margin-bottom: 0.1em;">Access Control Rules Tester,</li>
<li style="margin-bottom: 0.1em;">AntiSamy .NET,</li>
<li style="margin-bottom: 0.1em;">Live CD &amp; DVD Project,</li>
<li style="margin-bottom: 0.1em;">OpenPGP Extensions for HTTP,</li>
<li style="margin-bottom: 0.1em;"> Orizon Project,</li>
<li style="margin-bottom: 0.1em;">Python Static Analysis,</li>
<li style="margin-bottom: 0.1em;">WebScarab-NG,</li>
<li style="margin-bottom: 0.1em;">And many, many others.</li>
</ul>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;"><strong>Working Sessions</strong></p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">Expecting the presence of the application security industry key players, the Working Sessions will cover a wide range of issues such as:</p>
<ul style="margin: 0.3em 0px 0px 1.5em; padding: 0px; line-height: 1.5em; list-style-type: square;">
<li style="margin-bottom: 0.1em;">OWASP Top 10 2009,</li>
<li style="margin-bottom: 0.1em;">Browser Security,</li>
<li style="margin-bottom: 0.1em;">Web Application Framework Security,</li>
<li style="margin-bottom: 0.1em;"> Enterprise Security API Project,</li>
<li style="margin-bottom: 0.1em;">Best Practices for OWASP Chapter Leaders,</li>
<li style="margin-bottom: 0.1em;">OWASP Documentation Projects,</li>
<li style="margin-bottom: 0.1em;"> OWASP Tools Projects,</li>
<li style="margin-bottom: 0.1em;">OWASP Education Project,</li>
<li style="margin-bottom: 0.1em;">OWASP Strategic Planning for 2009,</li>
<li style="margin-bottom: 0.1em;">OWASP Certification,</li>
<li style="margin-bottom: 0.1em;">OWASP Winter of Code 2009</li>
<li style="margin-bottom: 0.1em;">Two-way Internationalization of OWASP Content</li>
<li style="margin-bottom: 0.1em;">And many more.</li>
</ul>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;"><strong>Training</strong></p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">These 2-day, 1-day or 1/2-day training courses cover a wide range of OWASP specific and Web Application Security Topics:</p>
<ul style="margin: 0.3em 0px 0px 1.5em; padding: 0px; line-height: 1.5em; list-style-type: square;">
<li style="margin-bottom: 0.1em;">OWASP Top 10 - What Developers Should Know on Web Application Security</li>
<li style="margin-bottom: 0.1em;">Uncovering WebScarab&#8217;s Secret Treasures</li>
<li style="margin-bottom: 0.1em;"> Securing WebGoat with ModSecurity</li>
<li style="margin-bottom: 0.1em;">Secure Programming with Java</li>
<li style="margin-bottom: 0.1em;">Advanced Web Application Security Testing</li>
<li style="margin-bottom: 0.1em;"> Building Secure Web 2.0 Applications</li>
<li style="margin-bottom: 0.1em;">Building Secure Web Services</li>
<li style="margin-bottom: 0.1em;">Building Secure Web Applications with OWASP&#8217;s Enterprise Security API (ESAPI)</li>
<li style="margin-bottom: 0.1em;">Classic ASP Security using OWASP tools</li>
<li style="margin-bottom: 0.1em;">Web Application Assessments</li>
<li style="margin-bottom: 0.1em;">Hacking Owasp Orizon Project v1.0</li>
<li style="margin-bottom: 0.1em;"> Ajax Security</li>
<li style="margin-bottom: 0.1em;">Practical Penetration Testing: Think Like an Attacker to Stop Attacks</li>
<li style="margin-bottom: 0.1em;">Linux Software Exploitation</li>
<li style="margin-bottom: 0.1em;"> Web server/services hardening using SELinux</li>
</ul>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">
Main Contact:</p>
<p style="margin: 0.4em 0px 0.5em; line-height: 1.5em;">Kate Hartmann<br />
OWASP Operations Director<br />
9175 Guilford Road, Suite 300<br />
Columbia, MD 21046, USA<br />
Phone: +1-301-575-0189<br />
Facsimile: +1-301-604-8033<br />
Email: <a href="mailto:kate.hartmann@owasp.org" target="_blank">kate.hartmann@owasp.org</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 14:27:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/summit">summit</category>
      <category domain="http://securityratty.com/tag/documentation">documentation</category>
      <category domain="http://securityratty.com/tag/owasp documentation projects">owasp documentation projects</category>
      <category domain="http://securityratty.com/tag/projects">projects</category>
      <category domain="http://securityratty.com/tag/owasp">owasp</category>
      <category domain="http://securityratty.com/tag/owasp tools projects">owasp tools projects</category>
      <category domain="http://securityratty.com/tag/owasp tools">owasp tools</category>
      <category domain="http://securityratty.com/tag/owasp summit website">owasp summit website</category>
      <category domain="http://securityratty.com/tag/owasp projects">owasp projects</category>
      <source url="http://www.thecepblog.com/2008/10/15/owasp-european-summit-portugal/">OWASP European Summit - Portugal</source>
    </item>
    <item>
      <title><![CDATA[OWASP AppSec Asia 2008 - Taiwan]]></title>
      <link>http://securityratty.com/article/e79fc46b6ee63dd9ff5215cefbd04d13</link>
      <guid>http://securityratty.com/article/e79fc46b6ee63dd9ff5215cefbd04d13</guid>
      <description><![CDATA[Here is the latest on OWASP AppSec Asia 2008 - Taiwan . I will be giving a talk on Oct 27th about Proxy Caches and Web Application Securityusing the recent Google Docs 0-day as an example
Some of the...]]></description>
      <content:encoded><![CDATA[<p>Here is the latest on <a href="http://www.owasp.org/index.php/OWASP_AppSec_Asia_2008" target="_blank">OWASP AppSec Asia 2008 - Taiwan</a>.  I will be giving a talk on <span class="mw-headline">Oct 27th about </span><a href="http://www.owasp.org/index.php/Proxy_Caches_and_Web_Application_Security--using_the_recent_Google_Docs_0-day_as_an_example" target="_blank">Proxy Caches and Web Application Security&#8211;using the recent Google Docs 0-day as an example.</a></p>
<p>Some of the background for this presentation are <a href="http://blog.isc2.org/isc2_blog/2008/09/proxy-caches-ar.html">Proxy Caches are a Challenging Threat to Internet Security</a> and <a href="http://blog.isc2.org/isc2_blog/2008/09/serious-securit.html">A New Security Breach in Google Docs Revealed.</a></p>
]]></content:encoded>
      <pubDate>Tue, 14 Oct 2008 10:48:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/owasp appsec asia">owasp appsec asia</category>
      <category domain="http://securityratty.com/tag/proxy caches">proxy caches</category>
      <category domain="http://securityratty.com/tag/google docs">google docs</category>
      <category domain="http://securityratty.com/tag/taiwan">taiwan</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/oct 27th">oct 27th</category>
      <category domain="http://securityratty.com/tag/internet security">internet security</category>
      <category domain="http://securityratty.com/tag/web application">web application</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <source url="http://www.thecepblog.com/2008/10/14/owasp-appsec-asia-2008-taiwan/">OWASP AppSec Asia 2008 - Taiwan</source>
    </item>
    <item>
      <title><![CDATA[Web services talk at OWASP]]></title>
      <link>http://securityratty.com/article/6137f8e4cc033bf825ba725790030679</link>
      <guid>http://securityratty.com/article/6137f8e4cc033bf825ba725790030679</guid>
      <description><![CDATA[The video from my OWASP AppSec Conference talk on OWASP Top Ten for Web services is online here

OWASP is consistently the most interesting and practical security conference, its probably the closest...]]></description>
      <content:encoded><![CDATA[<p>The video from my OWASP AppSec Conference talk on OWASP Top Ten for &#0160;Web services &#0160;is online <a href="http://video.google.com/videoplay?docid=-7008552133222293089&amp;ei=WNPzSPLIAon0-wH7iujiDg&amp;q=owasp.tv">here</a>.</p><br /><div>OWASP is consistently the most interesting and practical security conference, its probably the closest thing we have to a true software security conference. Sure, we could use a few more <a href="http://1raindrop.typepad.com/1_raindrop/2008/09/mark-curphey-on-builders-and-breakers.html">builders</a>, but I still think its the best we have right now.</div>]]></content:encoded>
      <pubDate>Mon, 13 Oct 2008 14:14:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/owasp">owasp</category>
      <category domain="http://securityratty.com/tag/web services">web services</category>
      <category domain="http://securityratty.com/tag/practical security conference">practical security conference</category>
      <category domain="http://securityratty.com/tag/owasp top">owasp top</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/builders">builders</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/consistently">consistently</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/web-services-talk-at-owasp.html">Web services talk at OWASP</source>
    </item>
    <item>
      <title><![CDATA[Microsoft Joins OWASP]]></title>
      <link>http://securityratty.com/article/8aa9d1dec1271075a0dce98272870935</link>
      <guid>http://securityratty.com/article/8aa9d1dec1271075a0dce98272870935</guid>
      <description><![CDATA[If you navigate over to the OWASP members page you will see a new logo Its an interesting full circle for me having started OWASP back in 2001 and now having had a hand in one of the biggest...]]></description>
      <content:encoded><![CDATA[If you navigate over to the OWASP members page you will see a new logo
 
It&#8217;s an interesting full circle for me having started OWASP back in 2001 and now having had a hand in one of the biggest technology companies in the world (my current employer) joining. Someone sent me a mail on Friday [...]]]></content:encoded>
      <pubDate>Sun, 12 Oct 2008 04:30:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/owasp">owasp</category>
      <category domain="http://securityratty.com/tag/technology companies">technology companies</category>
      <category domain="http://securityratty.com/tag/current employer">current employer</category>
      <category domain="http://securityratty.com/tag/page">page</category>
      <category domain="http://securityratty.com/tag/friday">friday</category>
      <category domain="http://securityratty.com/tag/circle">circle</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/logo">logo</category>
      <category domain="http://securityratty.com/tag/hand">hand</category>
      <source url="http://securitybuddha.com/2008/10/12/microsoft-joins-owasp/">Microsoft Joins OWASP</source>
    </item>
    <item>
      <title><![CDATA[OWASP AppSec Asia 2008: Proxy Caches and Web Application Security]]></title>
      <link>http://securityratty.com/article/6d5703cf99293c1caf631a9f5bc73906</link>
      <guid>http://securityratty.com/article/6d5703cf99293c1caf631a9f5bc73906</guid>
      <description><![CDATA[Back to travelling a bit, I have accepted an invitation from Wayne Huang, Chapter Leader, OWASP Taiwan , to give the following presentation at OWASP AppSec Asia 2008, October 27 - 28, 2008, in Taipei...]]></description>
      <content:encoded><![CDATA[<p>Back to travelling a bit, I have accepted an invitation from Wayne Huang, Chapter Leader, <a href="http://www.owasp.org/index.php/Taiwan" target="_blank">OWASP Taiwan</a>,  to give the following presentation at <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference" target="_blank">OWASP AppSec</a> Asia 2008, October 27 - 28, 2008, in Taipei:</p>
<p><strong>Proxy Caches and Web Application Security</strong></p>
<blockquote><p>Abstract:  <em>Proxy caches, combined with poorly written session management code, can easily lead to serious Internet security breaches. Web application developers cannot know whether their content is consumed directly or via a proxy cache. Developers cannot assume that the HTTP responses will be delivered to the intended browser. Moreover, developers cannot be sure that the intended browser even receives the intented content. Consequently, proxy caches are a serious theat to web application security.  In the presentation, we will discuss the recent <a href="http://www.thecepblog.com/2008/09/15/a-new-security-breach-in-google-docs-revealed/" target="_blank">security breach Tim found in Google Docs </a>and review <a href="http://blog.isc2.org/isc2_blog/2008/09/proxy-caches-ar.html" target="_blank">web application security and session management topics related to proxy caching.</a></em></p></blockquote>
]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 07:05:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/proxy caches">proxy caches</category>
      <category domain="http://securityratty.com/tag/proxy">proxy</category>
      <category domain="http://securityratty.com/tag/web application security">web application security</category>
      <category domain="http://securityratty.com/tag/owasp appsec asia">owasp appsec asia</category>
      <category domain="http://securityratty.com/tag/web application developers">web application developers</category>
      <category domain="http://securityratty.com/tag/developers">developers</category>
      <category domain="http://securityratty.com/tag/session management topics">session management topics</category>
      <category domain="http://securityratty.com/tag/session management code">session management code</category>
      <category domain="http://securityratty.com/tag/internet security breaches">internet security breaches</category>
      <source url="http://www.thecepblog.com/2008/10/03/owasp-appsec-asia-2008-proxy-caches-and-web-application-security/">OWASP AppSec Asia 2008: Proxy Caches and Web Application Security</source>
    </item>
    <item>
      <title><![CDATA[(ISC)2s Newest Cash Cow: The CSSLP Certification]]></title>
      <link>http://securityratty.com/article/4d2aae6d17ac0d88114660137a62c55f</link>
      <guid>http://securityratty.com/article/4d2aae6d17ac0d88114660137a62c55f</guid>
      <description><![CDATA[Earlier this week, during the OWASP AppSec 2008 Conference , the people behind the ubiquitous CISSP certification announced their latest creation the Certified Software Security Lifecycle Professional...]]></description>
      <content:encoded><![CDATA[<p>Earlier this week, during the <a href="http://www.owasp.org/index.php?title=OWASP_NYC_AppSec_2008_Conference">OWASP AppSec 2008 Conference</a>, the people behind the ubiquitous CISSP certification announced their latest creation &#8212; the <a href="http://isc2.org/csslp">Certified Software Security Lifecycle Professional</a> (CSSLP).  In front of a captive audience waiting for a 42&#8243; plasma TV to be raffled, the <a href="http://blog.isc2.org/isc2_blog/tipton/index.html">Executive Director of (ISC)2</a> outlined this new certification designed to appeal to application security professionals.  To his credit, Mr. Tipton stated very clearly that the CSSLP is not intended to measure one&#8217;s technical skillset.  Unfortunately, it&#8217;s inevitable that employers will treat it as such.</p>
<p>You can read all the details on their website (except for the part about the certification not being a measure of practical skills).  From what I can tell, the CSSLP is just the CISSP with different CBKs, or Common Bodies of Knowledge.  As with the CISSP, they are going for broad knowledge, not depth.  Starting in June 2009, you can get certified by taking a paper exam, likely a multiple choice test similar to the CISSP.  Why June?  Because the test isn&#8217;t even written yet &#8212; I&#8217;ve heard from several sources that they are actively soliciting their existing pool of CISSPs to help write test questions.</p>
<p>Ah, but what if you can&#8217;t wait that long and want to get certified <i>right away</i>?  You&#8217;re in luck. If you act before March 31, 2009, you can get grandfathered in without even having to take the exam!  That&#8217;s right, they call it the <a href="https://www.isc2.org/cgi-bin/content.cgi?category=1691">CSSLP Experience Assessment</a>, and here are the requirements:</p>
<div style="float:right; margin-left: 15px"><a href="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money.jpg"><img src="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money-191x300.jpg" alt="" title="101-hand_with_money" width="191" height="300" class="alignright size-medium wp-image-372 photoborder" /></a></div>
<ul>
<li>Upload a resume showing three years of experience related to software security, or four years if you don&#8217;t have a college degree</li>
<li>Write short essays (500 words maximum) discussing four CBKs of your choice</li>
<li>Get a CISSP to vouch for you</li>
<li>Pay $650</li>
<p>
</ul>
<p>Let&#8217;s examine these requirements one at a time.</p>
<p><b>Three years of experience</b>.  (ISC)2 doesn&#8217;t provide any requirements on depth of experience, other than citing the broadly-defined CBKs.  Considering they are targeting everyone from software developers to security assessors to business analysts (yes, really), chances are they are going to accept any experience that is even tangential to the SDLC or software security.</p>
<p><b>Short essays on four of the CBKs</b>.  I asked the (ISC)2 exhibitors specifically what they are looking for to satisfy this requirement, and they said the essays should be a general discussion of the CBK topic, <i>optionally</i> citing your personal experience in that area if you have any.  This messaging is not quite aligned with the website guidance, which states that the essays should be &#8220;Accomplishment Records&#8221; which are self-reported descriptions of experience.  Either way, with a maximum essay length of 500 words, it&#8217;s pretty obvious that substance is not (ISC)2&#8217;s first priority.  Here&#8217;s one data point for you: I spoke to someone who has already submitted the CSSLP Experience Assessment, and he said it took about an hour to write the essays.</p>
<p><b>Get a CISSP to vouch for you</b>.  Actually this can be any (ISC)2 certified person, not just CISSPs.  Contrary to what you&#8217;d expect, though, the person isn&#8217;t vouching for your skillset so much as they are confirming that the attestations on your resume are accurate.</p>
<p><b>Pay $650</b>.  You knew it was coming.  After all, there is money to be made.  How is it that qualifying for the CSSLP through professional experience should cost $650?  If you&#8217;re taking the written exam, fair enough, (ISC)2 does incur the cost of administering and grading that exam (even though the <a href="http://www.scantron.com/datacollection/scanners.aspx">Scantron machine</a> is probably paid off by now).  But $650 for the submitted-online Experience Assessment?  If we assume that the person reading these essay submissions makes a rather generous $100k per year, then $650 accounts for roughly a day and a half.  Will it really take that long to read a <i>maximum</i> of 2,000 words and pass judgment?  Of course not.  (ISC)2 wants to get as many people as possible to qualify based on &#8220;experience&#8221;, seeding the initial pool of CSSLPs and netting them $650 per head for doing next to nothing.</p>
<p>As <a href="http://www.ljkushner.com/about_mstr.html">Lee Kushner</a> stated during his OWASP AppSec presentation (<i>7 Habits of Highly Effective Career Managers</i>), &#8220;the more people who own a cert, the less relevant it becomes.&#8221;  Irrelevant &#8212; that&#8217;s exactly what the CISSP has become, and it&#8217;s exactly where the CSSLP is headed.  Meanwhile, (ISC)2 will sit back and watch while you and your employers continue to fill their coffers.</p>
<p>In closing, let me acknowledge that this blog entry probably comes across as judgmental.  I accept that.  I&#8217;m not ranting against the idea of certifications, though admittedly <a href="http://www.veracode.com/blog/2008/04/not-a-cissp/">I&#8217;m not a fan of them either</a>.  I am disappointed that (ISC)2, an organization with tremendous influence, could have created something more meaningful but chose not to. Why bother when people will just fork over the cash anyway?</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 11:08:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/csslp">csslp</category>
      <category domain="http://securityratty.com/tag/csslp experience assessment">csslp experience assessment</category>
      <category domain="http://securityratty.com/tag/experience assessment">experience assessment</category>
      <category domain="http://securityratty.com/tag/certification">certification</category>
      <category domain="http://securityratty.com/tag/experience">experience</category>
      <category domain="http://securityratty.com/tag/isc">isc</category>
      <category domain="http://securityratty.com/tag/personal experience">personal experience</category>
      <category domain="http://securityratty.com/tag/ubiquitous cissp certification">ubiquitous cissp certification</category>
      <category domain="http://securityratty.com/tag/cissp">cissp</category>
      <source url="http://www.veracode.com/blog/2008/09/isc2s-newest-cash-cow-csslp/">(ISC)2s Newest Cash Cow: The CSSLP Certification</source>
    </item>
    <item>
      <title><![CDATA[The 10 Top Cybersecurity Threats for 2008, AMCHAM & OWASP Thailand]]></title>
      <link>http://securityratty.com/article/82f0bbf4754462f71a9f9c3ac66ff1bf</link>
      <guid>http://securityratty.com/article/82f0bbf4754462f71a9f9c3ac66ff1bf</guid>
      <description><![CDATA[Last year, in collaboration with IT security experts from (ISC)2 and the LinkedIn professional network, I published The Top Ten Cybersecurity Threats for 2008 . In a joint meeting with interested...]]></description>
      <content:encoded><![CDATA[<p>Last year, in collaboration with IT security experts from (ISC)2 and the LinkedIn professional network, I published <a href="http://www.thecepblog.com/2008/01/05/the-top-ten-cybersecurity-threats-for-2008/" target="_blank">The Top Ten Cybersecurity Threats for 2008</a>.  In a joint meeting with interested <a href="http://www.amchamthailand.com" target="_blank">AMCHAM Thailand</a> guests from the Open Web Application Security Project (<a href="http://www.owasp.org" target="_blank">OWASP</a>), Thailand, Chapter, we will review the 2008 top 10 cybersecurity threats and facilitate an open discussion on these threats, including how these cybersecurity threats could impact AMCHAM members.  The presentation will be at the J. W. Marriott on October 21, 2008 (details to follow).</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 06:06:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/threats">threats</category>
      <category domain="http://securityratty.com/tag/cybersecurity threats">cybersecurity threats</category>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/amcham thailand guests">amcham thailand guests</category>
      <category domain="http://securityratty.com/tag/linkedin professional network">linkedin professional network</category>
      <category domain="http://securityratty.com/tag/impact amcham">impact amcham</category>
      <category domain="http://securityratty.com/tag/security experts">security experts</category>
      <category domain="http://securityratty.com/tag/owasp">owasp</category>
      <source url="http://www.thecepblog.com/2008/09/29/the-10-top-cybersecurity-threats-for-2008-amcham-owasp-thailand/">The 10 Top Cybersecurity Threats for 2008, AMCHAM &amp; OWASP Thailand</source>
    </item>
  </channel>
</rss>
