<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>owasp &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/owasp/</link>
	<description>Feed of posts on WordPress.com tagged "owasp"</description>
	<pubDate>Sat, 28 Nov 2009 13:59:23 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[IBWAS09 be there!]]></title>
<link>http://cyberinsec.wordpress.com/2009/11/26/ibwas09-be-there/</link>
<pubDate>Thu, 26 Nov 2009 09:36:22 +0000</pubDate>
<dc:creator>SRF</dc:creator>
<guid>http://cyberinsec.wordpress.com/2009/11/26/ibwas09-be-there/</guid>
<description><![CDATA[ESP: Si estáis por Madrid durante los días 10 y 11 de Diciembre no os podéis perder IBWAS09, organiz]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong>ESP:</strong> Si estáis por Madrid durante los días 10 y 11 de Diciembre no os podéis perder <a title="IBWAS09" href="http://www.ibwas.com/" target="_blank">IBWAS09</a>, organizado por <a title="OWASP" href="http://www.owasp.org" target="_blank">OWASP</a> (Capítulos <a title="Irlanda" href="http://www.owasp.org/index.php/Ireland" target="_blank">Irlanda</a>, <a title="Portugal" href="http://www.owasp.org/index.php/Portuguese" target="_blank">Portugal</a> y <a title="España" href="http://www.owasp.org/index.php/Spain" target="_blank">España</a>) con una selección de ponentes de lujo! Nosotros estaremos <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ¿y tú?</p>
<p><strong>US:</strong> If you are in Madrid on 10 and 11 December don’t miss <a title="IBWAS09" href="http://www.ibwas.com/" target="_blank">IBWAS09</a>, organized by <a title="OWASP" href="http://www.owasp.org" target="_blank">OWASP</a> (chapters <a title="Ireland" href="http://www.owasp.org/index.php/Ireland" target="_blank">Ireland</a>, <a title="Portugal" href="http://www.owasp.org/index.php/Portuguese" target="_blank">Portugal</a> and <a title="Spain" href="http://www.owasp.org/index.php/Spain" target="_blank">Spain</a>) with an awesome speaker list! We will be there <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ¿and you?</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP Top 10 Release Candidate 2010— OWASP Podcast Interview ]]></title>
<link>http://artofdefence.wordpress.com/2009/11/25/owasp-top-10-release-candidate-2010%e2%80%94-owasp-podcast-interview/</link>
<pubDate>Wed, 25 Nov 2009 18:06:05 +0000</pubDate>
<dc:creator>hyperguard</dc:creator>
<guid>http://artofdefence.wordpress.com/2009/11/25/owasp-top-10-release-candidate-2010%e2%80%94-owasp-podcast-interview/</guid>
<description><![CDATA[On episode 54 of the OWASP podcast, OWASP chapter head for Germany, Georg Hess and CEO and co-founde]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>On <a href="http://www.owasp.org/download/jmanico/owasp_podcast_54.mp3" target="_blank">episode 54</a> of the OWASP podcast, OWASP chapter head for Germany, <a href="http://de.linkedin.com/pub/georg-he%C3%9F/17/159/b09">Georg Hess</a> and CEO and co-founder of <a href="http://aws.artofdefence.com/home/">art of defence</a> speaks with <a href="http://www.linkedin.com/in/matttesauro">Matt Tesauro</a> at the <a href="http://appsecdc.org/">OWASP’s AppSecDC show</a> on the <a href="../../../../../files/2009/11/owasp-top-10-rcl-2010.pdf">top 10 release candidate 2010</a> and the impacts it will have on the industry.</p>
<p><a href="http://www.owasp.org/download/jmanico/owasp_podcast_54.mp3" target="_blank">Listen here</a> for OWASP insight on the release candidate.</p>
<p><a href="http://artofdefence.wordpress.com/files/2009/11/new-top-ten-table.jpg"><img class="aligncenter size-full wp-image-148" title="New Top Ten Table" src="http://artofdefence.wordpress.com/files/2009/11/new-top-ten-table.jpg" alt="" width="467" height="250" /></a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP Top 10 - 2010 RC1]]></title>
<link>http://mithandir.wordpress.com/2009/11/23/owasp-top-10-2010-rc1/</link>
<pubDate>Mon, 23 Nov 2009 20:12:32 +0000</pubDate>
<dc:creator>mithandir</dc:creator>
<guid>http://mithandir.wordpress.com/2009/11/23/owasp-top-10-2010-rc1/</guid>
<description><![CDATA[A first release candidate for the OWASP Top 10 2010 was released a while ago. In my view the best en]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>A first release candidate for the <a href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project">OWASP Top 10 2010</a> was released a while ago. In my view the best enhancement is the new design of document.</p>
<p>As I worked on some short executive summaries for my company, I always struggled how to get a lot of information in the shortest form possible. The new OWASP Top10 PDF design is kind of perfect for this matter.</p>
<p><strong>Document</strong> (<a title="OWASP Top 10 2010 RC1 PDF Download" href="http://www.owasp.org/images/0/0f/OWASP_T10_-_2010_rc1.pdf">Download</a> as PDF):</p>
<p><strong><span style="font-weight:normal;"><!-- SlideShare error: doc is missing or has illegal characters /[^-_a-zA-Z0-9]/ --></span></strong></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Owasp Top Ten versiunea 2010]]></title>
<link>http://securityaspects.wordpress.com/2009/11/19/owasp-top-ten-versiunea-2010/</link>
<pubDate>Thu, 19 Nov 2009 09:35:33 +0000</pubDate>
<dc:creator>Cezar</dc:creator>
<guid>http://securityaspects.wordpress.com/2009/11/19/owasp-top-ten-versiunea-2010/</guid>
<description><![CDATA[Saptamina  asta a fost facuta publica, la conferinta OWASP AppSec DC, versiunea release candidate nr]]></description>
<content:encoded><![CDATA[Saptamina  asta a fost facuta publica, la conferinta OWASP AppSec DC, versiunea release candidate nr]]></content:encoded>
</item>
<item>
<title><![CDATA[O2: A brief introduction and why you should care]]></title>
<link>http://owasptesting.wordpress.com/2009/11/17/o2-a-brief-introduction-and-why-you-should-care/</link>
<pubDate>Tue, 17 Nov 2009 08:12:42 +0000</pubDate>
<dc:creator>owasptesting</dc:creator>
<guid>http://owasptesting.wordpress.com/2009/11/17/o2-a-brief-introduction-and-why-you-should-care/</guid>
<description><![CDATA[If you consider yourself a well-educated follower of all things info security related, then the Owas]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>If you consider yourself a well-educated follower of all things info security related, then the <a href="http://www.owasp.org/index.php/O2">Owasp O2 Platform</a> project shouldn&#8217;t come as a surprise. If that&#8217;s not the case, here is a quick breakdown:</p>
<p>What: A series of Open Source modules that allow you, the tester, to better understand an applications security profile.</p>
<p>Why: It&#8217;s a known fact that black-box assessments won&#8217;t result in all the possible vulnerabilities being discovered. A hybrid approach is needed, when applicable source code and access is available.This is where O2 comes into the picture. A more detailed explanation can be found <a href="http://www.o2-ounceopen.com/files-binaries-source-and-demo/old-documents-and-presentations/OWASP_O2_Platform_-_AppSec_Ireland_Sep_2009.pdf">here</a>.</p>
<p>Dinis, being the bundle of infosec energy we all know and love, has written a series of blog posts discussing the future of O2, namely:</p>
<ul>
<li><a href="http://diniscruz.blogspot.com/2009/11/part-i-ibm-application-security-related.html">Part  I &#8211; IBM Application Security related tools &#38; &#8220;AppScan 2011&#8243;</a></li>
<li><a href="http://diniscruz.blogspot.com/2009/11/part-ii-why-ibm-will-solve-problem.html">Part II &#8211; Why IBM will ‘solve the problem’</a></li>
<li><a href="http://diniscruz.blogspot.com/2009/11/part-iii-why-i-said-no-to-ibm-for-now.html">Part III &#8211; Why I said NO to IBM &#8230; for now</a></li>
<li><a href="http://diniscruz.blogspot.com/2009/11/part-iv-o2-needs-to-be-commercially.html">Part IV &#8211; O2 needs to be Commercially Supported</a></li>
</ul>
<p>All good points, albeit it with some fundamental flaws. In Part 1, he talks about a fictional company called AppSEC, which is primarily an IBM shop. The problem here is that whilst IBM is a big company, anyone who&#8217;s worked with IBM tools in the past know they often don&#8217;t really do the job well. All I need to mutter are the fabled words of &#8216;Lotus Notes&#8217; to know what a total abortion some of their tools are like. AppSEC, like many new consultancies who cannot afford more senior staff, rely on automated tools like AppScan.</p>
<p>AppScan is ok for catching low-hanging fruit, but it does not replace the experience and knowledge obtained from testing hundreds of applications. I&#8217;d query any companies approach to security that relies on any given tool to achieve a full-spread of testing. The rest of the post goes on to mention how the test would flow, including some pretty nifty ideas, albeit it rather impractical ones.</p>
<p>Maybe in 2011 security assessments will look like this, but in 10 years of doing this, i&#8217;ve yet to see one that does.</p>
<p>In Part II, he thinks that IBM will solve the problem, which again is something I find rather impossible. Having worked with IBM and some of their more talented employees, this is a distant dream and one I doubt will come true. IBM, like any other large company, has invested in Application Security by purchasing big name products and stamping the IBM badge on them. The basis of their approach is building &#8217;smarter&#8217; technologies. So if that&#8217;s the case, why have we been inundated with dump technologies to date?</p>
<p>SQL injection is still a major hassle to anyone on the Internet, as is Cross-Site Scripting. Are we saying that up to now, all developments have been dumb and now all of a sudden IBM have the ability to go smart? What changed?</p>
<p>The final post is about the commercial support of O2, one I do agree with. However, as with any tool that&#8217;s developed by a security professional, a massive amount of common sense is missing. The framework is hard to use, the documentation is lacking and the overall support just isn&#8217;t there. For any chance of having a company support O2, some drastic work has to be done to make it appealing to people in the industry, and right now it&#8217;s not.</p>
<p>Dinis is looking for a company or department which provides the following services:</p>
<ul>
<li><strong>Support: </strong>9 to 5 (or 24h), Level 1 and Level 2 support (via email, phone, tweet, online forums and mailing lists)</li>
<li><strong>Training</strong>: provide online and classroom based training to both new and advanced users</li>
<li><strong>QA</strong>: Test new releases of O2</li>
<li><strong>Documentation</strong></li>
<li><strong>Security Review of O2 itself</strong></li>
<li><strong>Build Certified versions of O2</strong> (just like ReddHat)</li>
<li>Manage source control and user-submitted content</li>
<li><strong>On Demand customization of O2 Modules</strong></li>
<li><strong>Professional Services</strong></li>
<li><strong>Integration Services</strong>: building new parsers / plug-ins for consuming &#38; instrument other tools. Adding support to new languages and technologies (ABAP SmallTalk, SQL, COBOL, etc&#8230;)</li>
<li><strong>Bug Fixing of existing O2 Modules</strong></li>
<li><strong>Development of new O2 Features</strong></li>
</ul>
<p>All good and great, but something that will require vast am0unts of investment from said company and right now the world&#8217;s economy is still reeling from a nasty meltdown and investment isn&#8217;t forthcoming.</p>
<p>The problem with this industry is that we love to make things complicated. It&#8217;s often like a special badge that shows we can do it, but just because we can doesn&#8217;t mean we should. The basic idea behind O2 is brilliant, the execution isn&#8217;t. It&#8217;s confusing and lacking in so many different areas that i&#8217;d hedge a bet and say it&#8217;s not attractive to any potential investor as they cannot see what they&#8217;d get out of it.</p>
<p>If you want to attract support, here is what I think would help:</p>
<ol>
<li>Tidy up the house. Explain what the tool does in an easy to understand language. Show examples, with diagrams and make sure everyone who has a basic level of IT knowledge understands it.</li>
<li>Train a group of core people up who can be evangelists of the project. Having one or two people isn&#8217;t enough, it&#8217;s just another Open Source project that has a limited future</li>
<li>Ease of use. I cannot stress this enough, a tool that is hard to use <strong>ISN&#8217;T</strong> used!</li>
</ol>
<p>I do see a future for O2 but not until some basic changes have been made to make it more attractive to investors.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Catch Up - Blandat]]></title>
<link>http://berinder.wordpress.com/2009/11/14/catch-up-blandat/</link>
<pubDate>Fri, 13 Nov 2009 22:56:38 +0000</pubDate>
<dc:creator>berinder</dc:creator>
<guid>http://berinder.wordpress.com/2009/11/14/catch-up-blandat/</guid>
<description><![CDATA[Det här är en samling blandade inlägg som jag tyckt varit intressanta och som jag ska använda någon ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Det här är en samling blandade inlägg som jag tyckt varit intressanta och som jag ska använda någon gång. </p>
<ul>
<li>
<strong><a href="http://www.smashingmagazine.com/2009/10/05/mastering-css-coding-getting-started/">Mastering CSS Coding: Getting Started</a></strong></p>
<blockquote><p>En av dom bästa sakerna med internet är alla howtos, saker skrivna av människor som har stor koll vad dom håller på med för att hjälpa dig och mig som inte har en aning. Den här CSS-guiden har för första gången gett mig koll på vad som är vad, bra illustrerad!</p></blockquote>
</li>
<li>
<strong><a href="http://www.seriouseats.com/2009/10/the-food-lab-science-of-how-to-cook-perfect-boiled-eggs.html?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed:+seriouseatsfeaturesvideos+(Serious+Eats)&#38;utm_content=Google+Reader">The Food Lab: Perfect Boiled Eggs</a></strong></p>
<blockquote><p>Som en stor fantast av howtos och av kokta ägg måste jag dela med mig av den här utförliga vetenskapliga undersökningen av hur man kokar ägg!</p></blockquote>
</li>
<li>
<strong><a href="http://lifehacker.com/5388610/doitim-is-a-cross+platform-gtd-task-management-app">Doit.im Is a Cross-Platform GTD Task Management App</a></strong></p>
<blockquote><p>Jag letar fortfarande efter en taskmanager som har allt jag önskar. När den här kommer till Android och jag har skaffat mig en android-tvåa ska jag helt klart prova den!</p></blockquote>
</li>
<li>
<strong><a href="http://owaspsweden.blogspot.com/2009/10/sakerhet-och-unicode.html">Säkerhet och Unicode</a></strong></p>
<blockquote><p>OWASP har alltid bra inlägg om säkerhet. Här frågar dom sig om du kan skilja på punkter i domännamn?</p></blockquote>
</li>
<li>
<strong><a href="http://www.techcrunch.com/2009/10/28/google-should-make-apple-beg-for-maps-navigation/?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed:+Techcrunch+(TechCrunch)&#38;utm_content=Google+Reader">Google Should Make Apple Beg For Maps Navigation</a></strong></p>
<blockquote><p>Google släpper sina bästa applikationer till iPhone och till Android. Med navigation släpper dom för första gången nånting till Android först, ska Apple få tilllgång till det?</p></blockquote>
</li>
<li>
<strong><a href="http://klamberg.blogspot.com/2009/11/forsvarsunderrattelsedomstolen-tar-form.html">Försvarsunderrättelsedomstolen tar form</a></strong></p>
<blockquote><p>Inte mer än tre ledamöter åt gången varav en har underrättelsebakgrund. Det blir färre att pressa för att få igenom allt. Nu kommer det inte behövas så många beslut för att avlyssna hela svenska folket heller, bara hitta nån misstänkt per län typ. Vem delar du &#8220;trafikstråk&#8221; med?</p></blockquote>
</li>
<li>
<strong><a href="http://blog.mmn-o.se/2009/11/01/one-million-giraffes-go/">One million giraffes, GO!</a></strong></p>
<blockquote><p>Hur ser din giraff ut?</p></blockquote>
</li>
<li>
<strong><a href="http://www.boingboing.net/2009/11/06/corporate-law-firm-t.html?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed:+boingboing/iBag+(Boing+Boing)&#38;utm_content=Google+Reader">Corporate law firm targets whistle-blowers and anonymous commenters</a></strong></p>
<blockquote><p>An advokatfirma som inriktar sig på att hitta dom som försöker vara anonyma på nätet. Sensmoralen är väl att du ska vara väldigt försiktig innan du säger nånting, överhuvudtaget. Med datalagringsdirektiv och FRA-kablar så finns det ju fler ställen som kan råka läcka som dom kommer rikta in sig på!</p></blockquote>
</li>
<li>
<strong><a href="http://copyriot.se/2009/11/07/trolltyg-del-6-trollmi/">Trolltyg, del 6: Trollmi!</a></strong></p>
<blockquote><p>Rasmus skriver alltid så djävla bra. Det finns inte ord för hur mycket jag beundrar det som kommer från den mannens tangentbord. Nätkärlek!</p></blockquote>
</li>
<li>
<strong><a href="http://www.boingboing.net/2009/11/09/star-trek-chandelier.html?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed:+boingboing/iBag+(Boing+Boing)&#38;utm_content=Google+Reader">&#8220;Star Ship&#8221; Chandelier Boldly Lights Where No Lamp Has Lit Before</a></strong></p>
<blockquote><p>Nånting att hänga ovanför vardagsrumsbordet kanske! Tyckte den var snygg och nördpoängen är hög.</p></blockquote>
</li>
<li>
<strong><a href="http://blogg.tianmi.info/2009/11/09/inkorsporten/">Inkörsporten</a></strong></p>
<blockquote><p>Det räcker egentligen med att citera en mening ur det här inlägget för att man ska tänka efter: <em>&#8220;Nej, anledningen till att illegala droger är en inkörsport är just att de är illegala.&#8221;</em></p></blockquote>
</li>
<li>
<strong><a href="http://owaspsweden.blogspot.com/2009/11/esapi-python-edition.html">ESAPI Python Edition</a></strong></p>
<blockquote><p>Indatavalidering är sexigt. Python är sexigt. Sånt här gör mig upphetsad&#8230; typ.</p></blockquote>
</li>
<li>
<strong><a href="http://minamoderatakarameller.blogspot.com/2009/11/inga-utlandska-frimarken-pa-e-posten.html">Inga utländska frimärken på e-posten&#8230;</a></strong></p>
<blockquote><p>Kanske inte så konstigt att man inte tycker FRA är ett problem när man låter myndigheters mail gå genom främmande makts kablar. Okrypterat. Sånt här gör mig mörkrädd, har svenska myndigheter inga som helst säkerhetsansvariga. Dom borde få sparken om detta är sant.</p></blockquote>
</li>
<li>
<strong><a href="http://henrikalexandersson.blogspot.com/2009/11/nytt-lage.html">Nytt läge</a></strong></p>
<blockquote><p>HAX skriver lite om sina tankar nere i Bryssel. Inte så mycket om någon enskild politisk fråga just här, men det är den här känslan han har som gör att jag vill bli riksdagskandidat för Piratpartiet. Jag vill känna att jag kan påverka!</p></blockquote>
</li>
<li>
<strong><a href="http://arstechnica.com/microsoft/news/2009/11/microsoft-pulls-windows-7-tool-after-gpl-violation-claims.ars?utm_source=rss&#38;utm_medium=rss&#38;utm_campaign=rss">Microsoft pulls Windows 7 tool after GPL violation claims</a></strong></p>
<blockquote><p>Microsoft har programmerare som också tycker att det finns bra saker i GPL-ad kod. Så bra att dom kopierade in det i Windows-verktyg. Aja baja, inte utan att GPLa verktyget!</p></blockquote>
</li>
<li>
<strong><a href="http://ledomainedanais.blogspot.com/2009/11/den-franska-hogern-prioriterar.html">Den franska högern prioriterar</a></strong></p>
<blockquote><p>Anais beskriver vilka besparingar som den franska högern vill göra. Mänskliga rättigheter, individers rättigheter och frihet verkar vara saker som ska kosta mindre framöver!</p></blockquote>
</li>
<li>
<strong><a href="http://blogg.tianmi.info/2009/11/11/den-skanska-bynazismen/">Den skånska bynazismen</a></strong></p>
<blockquote><p>Diskussionen kring Vellinge i media känns vid tillfällen onyanserad, men jag kommer ihåg när jag bodde i Skåne. Varje gång jag åkte buss, i princip, så höll jag på att bli rent ut sagt förbannd för det satt alltid nått rasistsvin bakom mig och diskuterade negrer och apor. Det finns ett reellt problem med främlingsfientlighet i Skåne och det är inte bara Vellinge som lider av problemet.</p></blockquote>
</li>
<li>
<strong><a href="http://www.boingboing.net/2009/11/11/eff-lawyers-grin-lik.html?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed:+boingboing/iBag+(Boing+Boing)&#38;utm_content=Google+Reader">EFF lawyers grin like holy fools, surrounded by a fan of formerly secret government documents</a></strong></p>
<blockquote><p>Varje gång ett dokument som tidigare varit hemligstämplat blir släppt till allmänheten är det en vinst för demokratin. Nuff said.</p></blockquote>
</li>
<li>
<strong><a href="http://www.mackanandersson.se/2009/11/12/komiker-hor-upp/#utm_source=rss&#38;utm_medium=rss&#38;utm_campaign=komiker-hor-upp">Komiker &#8211; hör upp!</a></strong></p>
<blockquote><p>Youtube är inget problem, det är gratis marknadsföring. Jag kommer dock inte kolla ett Betnér-klipp på youtube fram tills den 18 Mars då jag ser han på nordanåteatern. Vill inte ha sett nått av det materialet innan.</p></blockquote>
</li>
<li>
<strong><a href="http://scabernestor.blogg.se/2009/november/no-shit-sherlock-arets-doh.html">No shit sherlock&#8230;.. Årets DOH! &#8230;.</a></strong></p>
<blockquote><p>Om man tror att jorden inte kan vara mer än sex-sju-tusen år kan man kanske inte ha så stor tillit till vetenskap&#8230;</p></blockquote>
</li>
</ul>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Industry Round-up: Week of November 9th  ]]></title>
<link>http://artofdefence.wordpress.com/2009/11/13/weekly-industry-round-up-week-of-november-9th/</link>
<pubDate>Fri, 13 Nov 2009 19:54:17 +0000</pubDate>
<dc:creator>hyperguard</dc:creator>
<guid>http://artofdefence.wordpress.com/2009/11/13/weekly-industry-round-up-week-of-november-9th/</guid>
<description><![CDATA[Around the Blogosphere… This week we’ve been on the ground at the OWASP AppSecDC Conference, where t]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Around the Blogosphere…<br />
This week we’ve been on the ground at the <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference">OWASP</a> <a href="http://appsecdc.org/">AppSecDC Conference</a>, where the Top 10 Most Critical Web Application Security Risks have been made available as a release candidate.  The new top 10 is about risks, not just vulnerabilities.  Our friend, <a href="http://twitter.com/jeremiahg">Jeremiah Grossman</a> shared the <a href="http://www.slideshare.net/jeremiahgrossman/owasp-top-10-2010-release-candidate-1">OWASP document</a> and <a href="http://jeremiahgrossman.blogspot.com/2009/11/owasp-top-10-2010-release-candidate-1.html">posted comments</a> live from the show.  It will be interesting to see how these new risks will impact the industry—such as <a href="../../../../../pcidss-resources/">PCI compliance</a> and the <a href="../../../../../cloud-security-alliance/">Cloud Security Alliance</a>.  Check out <a href="http://twitter.com/#search?q=%23OWASP">#OWASP</a> for real time commentary.</p>
<p>Dark Reading…<br />
<a href="http://www.darkreading.com/securityservices/security/government/showArticle.jhtml?articleID=221600333">New Security Certification On The Horizon For Cloud Services</a><br />
Writer, Kelly Jackson Higgins speaks with Jim Reavis, co-founder and executive director of the Cloud Security Alliance about the need for security certification for cloud security service providers.  Some are currently using <a href="http://en.wikipedia.org/wiki/Statement_on_Auditing_Standards_No._70:_Service_Organizations">SAS 70</a> and <a href="http://en.wikipedia.org/wiki/ISO/IEC_27001">ISO 27001</a>, but experts say neither is sufficient for providing potential cloud customers with assurances that the provider has deployed proper security or that their data is sufficiently locked down.  According to Reavis we should expect the industry to move forward with this certificate around the first quarter of 2010.</p>
<p>SearchSecurity.com&#8230;<br />
<a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1374218,00.html">Web Application Vulnerability Assessment Shows Patching Progress</a><br />
In this article, Robert Westervelt discusses how companies are making progress in Web application security. According to the latest research by WhiteHat Inc., they found a 61% vulnerability resolution rate, which is a slight increase. There is still much work that needs to be done since 64% of websites contain at least one serious vulnerability. WhiteHat is now focusing on figuring out what works for companies that are resolving the most serious vulnerabilities quickly.</p>
<p>Dark Reading…<br />
<a href="http://www.darkreading.com/securityservices/security/perimeter/showArticle.jhtml?articleID=220600860">Cost, Strength Of Security Drive Users Toward SaaS Offerings</a><br />
Using an excerpt from <em>Dark Reading’s</em> report, <em>&#8220;</em><a href="http://www.darkreading.com/securityservices/login.jhtml?_requestid=593027" target="new">Security Software as a Service: Navigating The New MSSP Landscape</a>”, Charlotte Dunlap investigates the pros and cons of security SaaS and provides tips on choosing the right provider.  She also cites an interesting study conducted by <a href="http://www.infonetics.com/">Infonetics Research</a>— 81 percent of respondents said improving the strength of the enterprise&#8217;s security is the No. 1 reason for moving to the SaaS model.  Other top reasons cited: cost, time to deploy, and centralized management.   One key point: 82 percent of those surveyed plan to use SaaS offerings to augment, not replace, their existing security deployments.  This is a great overview of businesses’ perceptions of SaaS and their intent to move to the cloud.  For more information on this topic, download <em>Dark Reading’s </em>report <a href="https://login.techweb.com/cas/login?service=http%3A//www.darkreading.com/GLOBAL/btg/iwbtn/checkUser.jhtml%3F_requestid%3D232582">here</a>.</p>
<p>SC Magazine&#8230;<br />
<a href="http://www.scmagazineus.com/Vulnerability-assessment-integration-with-web-application-firewalls/article/157371/">Vulnerability Assessment Integration with Web Application Firewalls</a><br />
This article by <a href="http://jeremiahgrossman.blogspot.com/">Jeremiah Grossman</a> discusses how even for proactive organizations, finding and fixing flaws in website code is a complex, time and resource intensive task. He provides a must-have checklist for organizations that includes production-safe scanning, accuracy, a precise reporting format, assessment repeatability, WAF/IDS SSL support and flexible and actionable rules. It would be ideal if a 100 percent secure code was developed, but until then Jeremiah says the integration of website vulnerability assessment and Web application firewalls allow IT security professionals to have control over website security. Having the right solution can noticeably improve how an organization handles and overcomes web vulnerability.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Beginning of an End]]></title>
<link>http://neontapir.wordpress.com/2009/11/12/the-beginning-of-an-end/</link>
<pubDate>Thu, 12 Nov 2009 06:21:43 +0000</pubDate>
<dc:creator>neontapir</dc:creator>
<guid>http://neontapir.wordpress.com/2009/11/12/the-beginning-of-an-end/</guid>
<description><![CDATA[It&#8217;s been some time since I&#8217;ve written. I&#8217;m in the middle of some pretty large lif]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>It&#8217;s been some time since I&#8217;ve written. I&#8217;m in the middle of some pretty large life changes. I&#8217;m in the middle of divorce proceedings. On top of that, I&#8217;m changing jobs.</p>
<p>My employer had been an independent software shop. It was bought by a big financial giant right before I was hired on. Recently, a lot of the old guard management left, leaving the big giant management to fill the void. There has been a large culture shift for our little agile company doing distributed systems work going into a mainframe, brick and mortar style world.</p>
<p>My last project as an employee for them is to produce an internal presentation on PCI compliance and the OWASP Top 10 vulnerabilities and how they apply to our application. There is a wealth of information on security vulnerabilities, that&#8217;s for certain! While researching the presentation, I was surprised to learn about the number and quality of the tools that exist for probing applications.</p>
<p>Monday, I&#8217;m dipping my toes into the consulting waters for the first time. I&#8217;ve taken a gig with a consulting firm I&#8217;ve worked with before. I&#8217;ll be filling a position at a large network bandwidth provider, writing software to integrate their systems. In theory, it&#8217;s a step up, though it can be hard to tell with the different styles of compensation. I&#8217;m looking forward to reporting about it in future posts.</p>
<p>What&#8217;s up in your world?</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Security Podcast Episode 78, Nov 09 2009]]></title>
<link>http://datasecurityblog.wordpress.com/2009/11/08/data-security-podcast-episode-78-nov-09-2009/</link>
<pubDate>Mon, 09 Nov 2009 05:40:21 +0000</pubDate>
<dc:creator>datasecurityblog</dc:creator>
<guid>http://datasecurityblog.wordpress.com/2009/11/08/data-security-podcast-episode-78-nov-09-2009/</guid>
<description><![CDATA[30 minutes every week on data security, privacy, and the law…..(plus or minus ten) On this week’s pr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><strong>30 minutes every week on data security, privacy, and the law…..(plus or minus ten)</strong></h3>
<p>On this week’s program:</p>
<p>* Why are web drive-by downloads proliferating like cockroaches?<strong><br />
</strong></p>
<p>* Sixty Minutes just covered a data security story. We rate the coverage.</p>
<p>* Our take on this week’s news.</p>
<p>–&#62; Stream This Week’s Show with our Built-In Flash Player:</p>
<p><span style='text-align:left;display:block;'><p><object type='application/x-shockwave-flash' data='http://wordpress.com/wp-content/plugins/audio-player/player.swf' width='290' height='24' id='audioplayer1'><param name='movie' value='http://wordpress.com/wp-content/plugins/audio-player/player.swf' /><param name='FlashVars' value='&amp;bg=0xf8f8f8&amp;leftbg=0xeeeeee&amp;lefticon=0x666666&amp;rightbg=0xcccccc&amp;rightbghover=0x999999&amp;righticon=0x666666&amp;righticonhover=0xffffff&amp;text=0x666666&amp;slider=0x666666&amp;track=0xFFFFFF&amp;border=0x666666&amp;loader=0x9FFFB8&amp;soundFile=http%3A%2F%2Fsecurity.talkworkshop.com%2Fdatasecpodcast_78.mp3' /><param name='quality' value='high' /><param name='menu' value='false' /><param name='bgcolor' value='#FFFFFF' /></object></p></span></p>
<p>–&#62; Scroll down to see links and show notes for this week’s show</p>
<p>–&#62; <a title="Data Security Podcast" href="http://feeds.feedburner.com/datasecuritypodcast" target="_blank">Stream, subscribe or download Episode 78</a> – Listen or subscribe to the feed to automatically get the latest episode sent to you to your Google, Yahoo, iTunes, or other popular sites.</p>
<p>–&#62;<a title="iTunes" href="http://itunes.datasecuritypodcast.com/">Tune into the show directly on iTunes,</a> you can also subscribe to the program on iTunes.</p>
<p>–&#62;  A simple way to listen to the show from with stricter firewalls:  <a title="odeo" href="http://odeo.com/channels/2120516-Data-Security-Podcast/episodes" target="_blank">Listen from Odeo</a>. This site works better if you are behind a more restrictive enterprise firewall.</p>
<p>Please visit our sponsors, and be sure to let them know you heard about them on The Data Security Podcast:</p>
<ul>
<li> Vipre Anti-Virus, the complete Antimalware solution by Sunbelt Software. If you TRY the enterprise version, you get the home version for FREE! Go to: <a title="Test Drive Vipre" href="http://www.testdrivevipre.com/" target="_blank">http://www.testdrivevipre.com</a> .</li>
</ul>
<ul>
<li>GamaSec Web App Scans: Spots cyber-hazards on your web site, and has advanced zero-day protection. <a title="GamaSec Free Web App Scan" href="https://www.gamasec.com/gsf/FreeTrial.aspx" target="_blank">GET YOUR FREE BASIC WEB APP SCAN</a>, plus a special offer just for listeners to The Data Security Podcast. Go here to sign up, and add the offer code: <strong>Podcast</strong>.</li>
</ul>
<ul>
<li>SonicWall;  Get the super fast UTM firewall that’s rated Five Stars (the Best rating) by <a title="SC Magazine" href="http://www.scmagazineus.com/SonicWALL-TZ-210-Wireless-N/Review/2799/" target="_blank">Secure Computing Magazine</a>.  <a title="SonicWalls" href="http://dataclonelabs.com/index.php?option=com_content&#38;task=view&#38;id=101&#38;Itemid=158" target="_blank">Data Clone Labs</a> is the premier SonicWall Medallion Partner for all your security needs.</li>
</ul>
<ul>
<li> <a title="DeviceLock" href="http://www.devicelock.com/" target="_blank">DeviceLock</a>; Software that controls, manages and helps encrypt USB drives and other removable media. Get a free trial on their site, and be sure to let them know you heard about them on The Data Security Podcast.</li>
</ul>
<p><strong>Show Notes for Episode 78 of the Data Security Podcast</strong></p>
<p>* Conversation:  Ira talks with Georg Hess, CEO and Co-Founder, <a title="Art of Defence" href="http://www.artofdefence.com/en" target="_blank">Art of D<span style="font-size:small;">efence</span></a>, about network scans versus web application scans. <a title="OWASP AppSec DC 2009" href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009" target="_blank">OWASP AppSec DC 2009</a> takes place this week,  November 10-13th, in Washington, DC. The Open Web Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of application software. Their mission is to make application security visible,  so that people and organizations can make informed decisions about true application security risks.</p>
<p style="text-align:center;"><a href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009"><img class=" aligncenter" title="OWASP Conf 2009 Wash DC" src="http://www.owasp.org/images/9/92/Dc09.png" alt="OWASP Conf 2009 Wash DC" width="468" height="60" /></a></p>
<p>* Tales From The Dark Web:  Our take on the 60 Minutes segment Sabotaging The System:  Could hackers get into the computer systems that run crucial elements of the world&#8217;s infrastructure, such as the power grids, water works or even a nation&#8217;s military arsenal?  Be sure to <a title="60 Minutes" href="http://www.cbsnews.com/video/watch/?id=5578986n&#38;tag=api" target="_blank">watch this video segment</a> with the highest level non-technical boss in your organization. Also, make sure you, and your non-technical boss watch the &#8220;Web Extras&#8221; from this segment.  One of the stunning parts of the segment was the claim that private companies are more vulnerable because the companies only care about profit. Unlike government networks, which are more secure (uh?).  If that was the case, how can that be squared against the portion of the segment that revealed that the Feds lost 12TB of data from the DOD, DOE, DOC and possible NASA, in 2007? Where was the profit motive that stopped good security in those organizations? Security expert Robert Graham explores this, and other issues, in this posting: <a title="Brazil Grid Attacks?" href="http://erratasec.blogspot.com/2009/11/brazil-outage-not-caused-by-hackers.html" target="_blank">Brazil outage NOT caused by hackers</a>.</p>
<p>* From Our Take on The News:  New open-source voting technology – the developer is looking for jurisdictions to try it for free.  <a title="http://www.wired.com/threatlevel/2009/11/scantegrity" href="http://www.wired.com/threatlevel/2009/11/scantegrity" target="_blank">Read the Wired account</a>.</p>
<p>* From Our Take on The News:  A technical overview of the <a title="SSL flaw report" href="http://www.leviathansecurity.com/pdf/Renegotiating_TLS.pdf" target="_blank">newly discovered SSL vulnerabilities</a> and possible mitigation. Ben Laurie has excellent, technical <a title="SSL flaw blogs" href="http://www.links.org/?p=789" target="_blank">blog postings</a> about the SSL protocol flaw.</p>
<p>* From Our Take on The News:  Voters hate traffic surveillance cameras &#8212; proven in three U. S. cities in last week’s elections. (<a title="Washington Post" href="http://www.washingtonpost.com/wp-dyn/content/article/2009/11/04/AR2009110404747.html" target="_blank">As if we still need proof</a>.) Great coverage of <a title="StopBigBrotherMD.org" href="http://www.stopbigbrothermd.org" target="_blank">traffic surveillance and related matters</a> in Maryland. (But the topic is universal).</p>
<p>* From The Wrap:  First iPhone worm found, <a title="iPhone Worm in the wild" href="http://www.f-secure.com/weblog/archives/00001814.html" target="_blank">details at F-Secure</a>.  A <a title="iPhone Worm in the wild" href="http://www.f-secure.com/weblog/archives/cydia.htm" target="_blank">how-to for changing the SSH default password</a> in your jailbroken iPhone; one uses a computer connected to your iPhone to change the SSH settings.  Note: If you are not using a jailbroken iPhone, you don&#8217;t need to make changes to be protected from this particular attack.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Industry Round-up: Week of November 2nd ]]></title>
<link>http://artofdefence.wordpress.com/2009/11/06/industry-update-116/</link>
<pubDate>Fri, 06 Nov 2009 22:19:12 +0000</pubDate>
<dc:creator>hyperguard</dc:creator>
<guid>http://artofdefence.wordpress.com/2009/11/06/industry-update-116/</guid>
<description><![CDATA[Online Security Authority… Building Security Into Your Organizations Web Applications to Begin With ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Online Security Authority…<br />
<a href="http://blog.onlinesecurityauthority.net/online-security/building-security-into-your-organizations-web-applications-to-begin-with/">Building Security Into Your Organizations Web Applications to Begin With</a><br />
This post discusses the importance of Web application protection being the chief component in the Web application development process and having it integrated from the ground up. It suggests the essential trick is a modification of attitude and awareness among the company software developers. Security imperfections should be viewed as only another category of application defect. During the entire process of software development, the focus must be on addressing the ever-changing potential for deficiencies, and the perception of new vulnerabilities and exploitation strategies.</p>
<p>CIO…<br />
<a href="http://www.cio.com/article/506865/Six_Steps_to_Pull_App_Security_Back_to_the_Future?page=1&#38;taxonomyId=1419">Six Steps to Pull App Security Back to the Future</a><br />
Bill Brenner speaks with fellow OWASP member Matt Fisher about some of the key problems with app security today and together they drive in to six different ways to change these. Bill wrote this article in conjunction with the upcoming <a href="http://artofdefence.wordpress.com/owasp/">OWASP</a> show, <a href="http://appsecdc.org/">AppSecDC</a>.  This is a great read; provides helpful background information and links to other app security articles.</p>
<p>Dark Reading…<br />
<a href="http://www.darkreading.com/vulnerability_management/security/app-security/showArticle.jhtml?articleID=220900412&#38;subSection=Application+Security">Tech Insight: Managing Vulnerability In The Cloud</a><br />
Writer, Curt Franklin explores the common issue, how do you manage vulnerabilities in your IT infrastructures when it is in the cloud?  Although this is in your provider’s hand, Curt provides readers with some best practices and tips for controlling it.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Keeping XSS at Bay, Ninja-Style]]></title>
<link>http://supplychaintechnology.wordpress.com/2009/11/02/security-ninjas-output-validation-post/</link>
<pubDate>Mon, 02 Nov 2009 09:02:48 +0000</pubDate>
<dc:creator>Jim</dc:creator>
<guid>http://supplychaintechnology.wordpress.com/2009/11/02/security-ninjas-output-validation-post/</guid>
<description><![CDATA[Perhaps the most commonly discussed web application security issue is Cross-Site Scripting, or XSS. ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Perhaps the most commonly discussed web application security issue is Cross-Site Scripting, or XSS.  (While the &#8216;X&#8217; makes it sound cool, it&#8217;s also there to prevent confusion over Cascading Style Sheets, the original CSS.)</p>
<p>The Security Ninja site is doing an overview of various aspects of the OWASP ESAPI toolkit, and the latest post is on output validation &#8212; the area of validation and encoding that pertains to preventing XSS attacks.</p>
<p>They take a simple, easy to follow walkthrough approach to common issues in application security while illuminating features of the ESAPI library.</p>
<p>Links:</p>
<p>Security Ninja Post: <a href="http://www.securityninja.co.uk/output-validation-using-the-owasp-esapi" target="_blank">http://www.securityninja.co.uk/output-validation-using-the-owasp-esapi</a></p>
<p>OWASP Enterprise Security API (ESAPI): <a href="http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API" target="_blank">http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AppSec 2009 - Transmissão das Palestras]]></title>
<link>http://joaorodolfo.wordpress.com/2009/10/26/appsec2009-tramissao-das-palestras-ao-vivo/</link>
<pubDate>Mon, 26 Oct 2009 21:00:10 +0000</pubDate>
<dc:creator>João Rodolfo</dc:creator>
<guid>http://joaorodolfo.wordpress.com/2009/10/26/appsec2009-tramissao-das-palestras-ao-vivo/</guid>
<description><![CDATA[Para quem não conseguiu uma &#8220;cadeira&#8221; na AppSec 2009 e pensou que perderia a conferência]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="aligncenter size-full wp-image-312" title="cadeiras" src="http://joaorodolfo.wordpress.com/files/2009/10/cadeira.jpg" alt="cadeiras" width="460" height="307" /></p>
<p>Para quem não conseguiu uma &#8220;cadeira&#8221; na <a title="Conferência Internacional de Segurança de Aplicaçõe" href="http://www.owasp.org/index.php/AppSec_Brasil_2009_%28pt-br%29" target="_blank">AppSec 2009</a> e pensou que perderia a conferência se enganou, a conferência terá suas palestras transmitidas pela internet no dia do evento.</p>
<p>Acesse a url e confira: <a href="http://www.camara.gov.br/webcamara" target="_blank">www.camara.gov.br/webcamara</a></p>
<p>Mais informações: <a href="http://www.owasp.org/index.php/AppSec_Brasil_2009_%28pt-br%29" target="_blank">http://www.owasp.org/index.php/AppSec_Brasil_2009_%28pt-br%29</a></p>
<p><span style="color:#888888;">fonte: cisspBR@yahoogroups.com<br />
imagem: http://www.imagebank.com</span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP AppSecDC]]></title>
<link>http://artofdefence.wordpress.com/2009/10/16/owasp-appsecdc/</link>
<pubDate>Fri, 16 Oct 2009 13:28:31 +0000</pubDate>
<dc:creator>hyperguard</dc:creator>
<guid>http://artofdefence.wordpress.com/2009/10/16/owasp-appsecdc/</guid>
<description><![CDATA[It’s getting closer to OWASP’s AppSecDC show, Nov 10-13, and this year’s show will feature the annou]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>It’s getting closer to <a href="http://appsecdc.org/">OWASP’s AppSecDC show</a>, Nov 10-13, and <a href="http://owasp.blogspot.com/">this year’s show</a> will feature the announcement of an updated Top 10 web vulnerabilities list for the first time since 2007. This list impacts the entire WebAppSec industry and there are a number of interesting effects anticipated here.</p>
<p>How will these updates impact PCI-DSS which is currently <a href="../../../../../2009/09/25/a-virtual-certainty-for-pci/">in the process of redefining requirements</a> for a virtualized market? The OWASP Top 10 forms an important part of PCI so any updates are sure to have an impact.</p>
<p>What impact will this have on the <a href="http://www.cloudsecurityalliance.org/csaguide.pdf">Cloud Security Alliance’s</a> (CSA) <a href="http://www.cloudsecurityalliance.org/csaguide.pdf">guidelines</a> for the industry? Again, they factored the Top 10 in predominantly. The CSA is preparing an update of these guidelines before the end of the year. Our <a href="http://www.cloudbook.net/alex-meisel">Alex Meisel</a> is contributing heavily this time around to the WAF section.</p>
<p>If you’re going and would like to meet up with <span style="text-decoration:underline;"><a title="http://www.artofdefence.com/" href="http://www.artofdefence.com/">Art of Defence’s</a></span> <a title="http://www.owasp.org/index.php/Germany" href="http://www.owasp.org/index.php/Germany">Georg Hess</a>, leave a comment and we’ll get you on his calendar.</p>
<p>Hope to see you in DC!</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Give1Get2 Developer's Guide English]]></title>
<link>http://wikifr.wordpress.com/2009/10/09/give1get2-developers-guide-english/</link>
<pubDate>Fri, 09 Oct 2009 13:37:29 +0000</pubDate>
<dc:creator>Yann Geffrotin</dc:creator>
<guid>http://wikifr.wordpress.com/2009/10/09/give1get2-developers-guide-english/</guid>
<description><![CDATA[Give 1 Get 2 &#8211; Give One Get Two / MOCHA &#8211; Moneybookers Exchange (v. Beryl) slide : http:]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div style="text-align:center;font-family:Times New Roman;"><span style="font-size:small;"><!-- SlideShare error: doc is missing or has illegal characters /[^-_a-zA-Z0-9]/ --></span></div>
<div style="text-align:center;font-family:Times New Roman;"><span style="font-size:small;"><strong>Give 1 Get 2 &#8211; Give One Get Two / MOCHA &#8211; Moneybookers Exchange</strong></span></div>
<div style="text-align:center;font-family:Times New Roman;"><span style="font-size:small;"><strong> (v. </strong></span><span style="font-size:small;"><strong>Beryl</strong></span><span style="font-size:small;"><strong>) </strong><br />
</span></div>
<p><span style="font-size:small;">slide : <a href="http://give1get2.sourceforge.net/give1get2/support/docs/Give1Get2_Slides_EN.pdf">http://give1get2.sourceforge.net/give1get2/support/docs/Give1Get2_Slides_EN.pdf</a></span></p>
<p><span style="font-size:small;">pdf : <a href="http://give1get2.sourceforge.net/give1get2/support/docs/Give1Get2_Guide_Dev_EN.pdf">http://give1get2.sourceforge.net/give1get2/support/docs/Give1Get2_Guide_Dev_EN.pdf</a></span></p>
<p><span style="font-size:small;"><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;">The French version is the primary source for all translations.</span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>Problems &#38; Vision: </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Creating a world without poverty to enable education, reducing disease and reducing mortality. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>The paradigm shift </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The existing paradigm solves some problems, so it was accepted in the past. However, at this moment, it does not meet the demand of everyone. So there was a challenge and a demand for change. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> I studied the market for existing solutions. Not being satisfied (because if I was happy the issue was already resolved), so I decided to create this software. Because, in my opinion, we must phase out barriers to trade. (ref Treaty establishing the European Community, 1957)</span><br style="font-family:Times New Roman;" /><br />
</span><span style="font-size:small;"><span style="font-family:Times New Roman;">The software </span></span><span style="font-size:small;"><span style="font-family:Times New Roman;">&#8220;Give1Get2&#8243; </span></span><span style="font-size:small;"><span style="font-family:Times New Roman;">is designed to build an alternative trading market to existing financial markets. The software specialised in online fund raising. It facilitates free trade in the international economy. </span></span><span style="font-size:small;"><span style="font-family:Times New Roman;">This software was created to meet the financing needs of economic agents in Europe and globally in order to finance, among other things, research, education and innovation. </span><br style="font-family:Times New Roman;" /> </span><br style="font-family:Times New Roman;" /><span style="font-size:small;"> <strong>Principles &#38; Qualities:</strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; Freedom, Citizenship, Responsibility, Equality, Solidarity, </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; Open, rule based, predictable, nondiscriminatory </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>Objective: </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Make a pilot project (functional, no set-up fees, free to use, legal, available (7/7j, 24/24h) and based on a win-win strategy) for an international trading platform from a PSP payment API (Moneybookers) and the FreePay Trading System (FTS) to help raise account balance of </span><span style="font-family:Times New Roman;">participants. (+1 Euro each time)</span><br style="font-family:Times New Roman;" /> </span><br />
<strong>Directed:</strong> The main objective has been achieved.</p>
<p>The software has been tested in real conditions with personal accounts for the 3 possible cases of purchase (less, equal and higher) and in each case, it worked perfectly.</p>
<p>Simple example: when 1 Euro was sent, are received 2 Euros (factor 2: 1 * 2 = 2). The motto &#8220;Give 1. Get 2.&#8221; was chosen in this way. The starting amount is chosen by the user and may use the system as often as he wants. Example: 1234 Euros sent -&#62; 2468 Euros received.</p>
<p><strong>Target: </strong></p>
<p>Target User: This software is being implemented, primarily targeting users of the PSP used speaking French or English and have minimal skills in finance (Moneybookers saves 9 million customers, according to Moneybookers). The goal is not to limit it to this category but can reach the largest number of users.</p>
<p>Target Developer: Those targeted for downloading and installing the software are programmers (preferably web developer) and / or companies wishing to establish a trading platform.<br />
<span style="font-size:small;"><br />
</span><span style="font-size:small;"><span style="font-family:Times New Roman;">The platform does not take a percentage of the funds it raises. In this sense, an organization that would use it could be a non-profitable organization. </span></span><br style="font-family:Times New Roman;" /><span style="font-size:small;"> <strong><br />
</strong></span></p>
<div id="p-et" dir="ltr"><strong>The strategy for doing business </strong></p>
<p>There are 3 possible strategies for 2 people: lose, no deal or win. (representing 9 combinations in total)</p>
<p>Case study: I do not want to lose money (destruction of money) I do not want to lose money for someone wins. (theft of money) I want to change. I do not make money for someone to lose. (theft of money) I do not want to make money alone. (counterfeit) I want to make money and someone else wins, too.</p>
<p>The only solution that seems feasible is: the win-win strategy.</p>
</div>
<div id="xunf" dir="ltr"><strong>Business Model of an online trading platform with a Win-Win Strategy:</strong></div>
<p><span style="font-size:small;"> </span></p>
<div id="cdq8" dir="ltr">5 parts: Provider, Consumer, Competitor, Partner and Self.</p>
<p>Provider:<br />
- Payment Services Providers (PSP) have a business model that works by commissions (fixed and variable) on the transactions of their customers (about 2%). To increase their profits, they want to increase their volume of transactions and that customers send the most money.<br />
- Their main partners are the merchants and trading platform that allows them to increase their volume of transactions and amounts over the users who use them. This is done by increasing the number of customers that is proportional to the access of their information systems: the API (Application Programming Interface) that allows anyone to automate payments.<br />
- Their suppliers are one or more banks. The financial messages are handled electronically by the bank. The PSP received confirmation via an API.</p>
<p>Consumer:<br />
- The internet users want to meet their needs. The needs of humanity are recurrent (must be met every day). This need is either a product or service, or money. The products are among the online marketplaces (e-commerce). The easy money is on the trading platform.<br />
- To send money, the user needs a PSP. PSP and asked to have a bank account to fulfill its electronic wallet. Compared to the PSP, the user earns more per transaction if the gain is at its default value (maximum).</p>
<p>Competitor, Partner and Self:<br />
- The business model of the trading platform is either the same as the PSP (for transactions), or an entrance fee or monthly fee or premium sponsorships (link id) or is free. (The money is earned in the same way as users.)<br />
- Providers of trading platforms are the PSP with their API. (the logo is highlighted)<br />
- The users use a service that allows them to move money. The strategy of moving money is defined either by the trading platform or by users themselves. (depends on the internal politics of the trading platform)<br />
- The trading platform is a software layer above the PSP. The design and evolution of the computer product can be partially outsourced to one or more persons caring for an open source trading platform that would reduce costs and development time.</p>
</div>
<p><span style="font-size:small;"><strong>Revenues </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The link to the sponsorship program is here: </span><a id="m035" style="font-family:Times New Roman;" title="http://www.moneybookers.com/app/referral.pl" href="http://www.moneybookers.com/app/referral.pl">http://www.moneybookers.com/app/referral.pl</a><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> There are over 9 million customers who use Moneybookers (Moneybookers depending). The target population is mainly covered that already included. The affiliate can not take commissions on those already listed. (he did not himself sponsored, implied) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> For people who are not registered yet, they can apply directly to the url </span><a id="yihz" style="font-family:Times New Roman;" title="http://moneybookers.com/" href="http://moneybookers.com/">http://moneybookers.com/</a><span style="font-family:Times New Roman;">: in this case, the partner does not take commission. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> </span>Either option, register with the affiliate link (the URL provided in a footnote on the script) in this case, the affiliate will receive commissions on what wins the PSP (up to 30 % and limited to 100 Euros maximum) This is not an additional cost (30-70 division). It is therefore completely transparent to the user.<span style="font-size:small;"><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> This incentive, I have put in place to increase the number of my partners on this project. I thought it was legitimate in order to pay the fixed costs (domain name) and variable operating costs (bandwidth, database) of each partner sites. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> In addition, each user also has the ability to sponsor others in making requests for payments. I think it&#8217;s a fairness.</span></span></p>
<p><strong>Interoperability: How do I know if the API electronic purse of a financial institution is compatible with FSX to FreePay?</strong><span style="font-size:small;"><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> </span>Financial Institution:</p>
<p>1. It must be able to create an account.</p>
<p>2. Supply: The user can supply his account with different means of payment (check, credit card, bank transfer etc.) and remove.</p>
<p>3. It must have a minimum of funds in its account (balance at least 1 euro). (must also take into account the costs of financial institution)</p>
<p>Optional (but strongly recommended): Approval Financial: The financial institution must be approved by at least one regulator.</p>
<p>Separation of tests and the real: The customer transfers between normal and test client are prohibited.</p>
<p>On the FSX:</p>
<p>1. It must be able to pass an order on the FSX and get on the payment platform. (POST or GET)</p>
<p>2. B2B, B2C, C2B &#38; C2C: Let the payment works in 2 directions (merchant-seller while being accessible client-customer, merchant-customer and customer-merchant), briefly allow P2P. The right of withdrawal depends on the status of persons making the transactions and all, it is defined on the site of PSP.</p>
<p>2a. (optional: but it&#8217;s better to do) should be able to enable process automation. (XML)</p>
<p>3. XML: It is necessary that the source site (merchant / FSX) to obtain a trace of the transaction from the payment platform. (xml sent and saved in the database tables in sql) <span style="font-size:small;"><br style="font-family:Times New Roman;" /> </span><br style="font-family:Times New Roman;" /><strong>Existing: What is Moneybookers? </strong></p>
<p>- Moneybookers is a payment service secure online that lets you send and receive money instantly from an e-mail. Opening an account is free, and loading and withdrawal of money is through a credit card (Visa, Mastercard, Diners, American Express, JCB, Delta / Visa Debit and Visa Electron) or by bank transfer.</p>
<p>- Moneybookers is translated into 12 different languages. (English, German, French, Spanish, Italian, Polish, Modern Greek, Romanian, Russian, Turkish, Chinese, Czech)</p>
<p>- Transaction costs are low and the deals can be found in the account history at any time.</p>
<p>- Moneybookers is an issuer of electronic money that allows the merchant (or merchant company) to accept online payments from customers worldwide with no installation fees or monthly fees. (in English: Payment Service Provider)</p>
<p>- Moneybookers Ltd. is a company registered in the Trade Registry of England and Wales under No. 4260907. Headquarters: Welken House, 10-11 Charterhouse Square, London, EC1M 6EH. It is licensed under the laws of the United Kingdom and the European Union and regulated by the Financial Services Authority (FSA), the Financial Services Authority in the United Kingdom.<br />
Source:</p>
<ul>
<li>The Official Website of Moneybookers <a href="http://moneybookers.com/">http://moneybookers.com/</a></li>
<li>Electronic Commerce (EC Directive) Regulations&#8217; &#8211; Legal Notice <a href="http://www.moneybookers.com/app/help.pl?s=ecrcpr">http://www.moneybookers.com/app/help.pl?s=ecrcpr</a></li>
<li><span style="font-family:'Times New Roman';"><span style="font-size:small;">Financial 	Services Authority of the United Kingdom (FSA) </span></span><span style="color:#000000;"><span style="font-family:'Times New Roman';"><span style="font-size:small;">: 	<a href="http://www.fsa.gov.uk/">http://www.fsa.gov.uk/</a></span></span></span></li>
<li>Registration Number with Moneybookers FSA: 214225  <span style="color:#000000;"><span style="font-family:'Times New Roman';"><span style="font-size:small;"><a href="http://www.fsa.gov.uk/register/firmSearchForm.do">http://www.fsa.gov.uk/register/firmSearchForm.do</a></span></span></span></li>
<li>Financial Services and Markets Act 	2000 : <a href="http://www.opsi.gov.uk/acts/acts2000/ukpga_20000008_en_1">http://www.opsi.gov.uk/acts/acts2000/ukpga_20000008_en_1</a></li>
<li>The Electronic Commerce (EC 	Directive) Regulations 2002 	<span style="color:#000000;"><span style="font-family:'Times New Roman';"><span style="font-size:small;"><a href="http://www.opsi.gov.uk/si/si2002/20022013.htm">http://www.opsi.gov.uk/si/si2002/20022013.htm</a></span></span></span></li>
<li><a name="content"></a></li>
</ul>
<p><strong><span style="font-size:small;"><br style="font-family:Times New Roman;" /></span>Why a relationship with a PSP: </strong></p>
<p>The division of roles: The software can be seen as a plugin that interacts with the main software (financial institution) to bring him a new feature. The software is an open system that sends information to the internal (history) and outside (order).<br />
- The financial institution converts capital into e-money, make payments and make the conversion of checks.<br />
- The software can place orders for payment, exchanging payment orders and can make claims.</p>
<p>Dependence: The software is towards simplicity as compared to the previous version (FreePay), he subtracted the processes needed to manage money. This software saves the cost of initial capital (1 million Euros) for the creation of a financial institution issuing electronic money (in: e-money issuer) within the European Union. (ref: Article 4 paragraph 1 of Directive 2000 46 EC).</p>
<p>Independence: Each organization that sets up the software Give1Get2 is autonomous from other organizations. It is dependent only financial institution which helps to make payments (1 to many relationship).</p>
<div id="ol9e" dir="ltr"><strong>What is &#8220;Give1Get2?</strong></div>
<p>The trading system is based on a win-win. The trading platform is a place of confrontation in the supply of financial securities and the demand for money under the idea of laissez-faire economics. There are no goods exchanged on the system. It is a zero sum game in terms of the payment platform but not the trading system (1 euro securitized token issued for the initiation, exchange +1 +1 for each party to each transaction). It&#8217;s a virtuous circle. There is no entrance fee. It is a system of person to person (P2P) which further allows users to place trades on a payment platform. This was designed so that there is no risk of inverse proportionality. Since there is no order of sale, it may not be a stock market crash. All system users can get rich, but not at the same time. The user can then become, as it makes a trader. (en: Market Operator)</p>
<p>The gain is also adjustable (0 to 100% Sample: 25 euros become real to 100% -&#62; 50 euros securitized). This allows the user to speculate whether or not to do so. This allows the user to transform its capital and more capital represented by shares. (And then convert its shares capital by the sale, eg 50 euros securitized -&#62; 50 euro real). Finally: EUR 25 real -&#62; 50 euro real. This was to be demonstrated.<span style="font-size:small;"><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>Economic Explanation:</strong><span style="font-family:Times New Roman;"> The software is not intended to create inflation. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> From what I know, there are two types of inflation: </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; Inflation of prices: Higher prices for goods and services during a period of time. (source: Wikipedia) The income increases more slowly as rising commodity prices. → decrease in purchasing power. What is problematic. But what has Give1Get2 is to increase the income of players in the system, thereby increasing purchasing power. There are no services for sale on the platform and use is free. The &#8220;products&#8221; are selling financial claims payments. The purchase price is determined by the buyers themselves. If they decide to buy more expensive it is to earn more. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; Inflation of the money: When money suffers a global money creation. Money in circulation increases via interest rates. However, the software Give1Get2 not intended to increase the money supply or decrease it. There is no interest rate not in this system. For only the responsibility of banks. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The software allows the movement of money between players. </span><br style="font-family:Times New Roman;" /> <strong><br />
</strong></span><strong>Financial Explanation:</strong><span style="font-size:small;"><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Consider this example: Bob wants to send 10 cents to EUR Alice via Moneybookers. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Alice to a balance of EUR 10.82. Bob has a balance of EUR 78.19. Bob sending 10 cents to Alice. The balance of Bob becomes 78.09 EUR. The balance goes to Alice 10.92 EUR. This is without counting the cost variables (0.01) and fixed costs (0.29). Ultimately, the balance of Alice is EUR 10.62 at the end of the operation. </span><br style="font-family:Times New Roman;" /> </span></p>
<p style="color:#000000;font-family:Times New Roman;"><span style="font-size:small;"><br />
</span></p>
<div style="color:#000000;font-family:Times New Roman;">
<table id="bi7n" border="0" cellspacing="0" cellpadding="3" width="100%">
<tbody>
<tr>
<td width="20%"><span style="font-size:small;">People </span></td>
<td width="20%"><span style="font-size:small;"><strong>Alice</strong></span></td>
<td width="20%"><span style="font-size:small;"><br />
</span></td>
<td width="20%"><span style="font-size:small;"><strong>Bob</strong></span></td>
<td width="20%"><span style="font-size:small;"><br />
</span></td>
</tr>
<tr>
<td width="20%"><span style="font-size:small;">Time<br />
</span></td>
<td width="20%"><span style="font-size:small;">Before </span></td>
<td width="20%"><span style="font-size:small;">After </span></td>
<td width="20%"><span style="font-size:small;">Before </span></td>
<td width="20%"><span style="font-size:small;">After </span></td>
</tr>
<tr>
<td width="20%"><span style="font-size:small;">Balance </span></td>
<td width="20%"><span style="font-size:small;">10.82 EUR</span></td>
<td width="20%"><span style="font-size:small;">10.62 EUR</span></td>
<td width="20%"><span style="font-size:small;">78.19 EUR</span></td>
<td width="20%"><span style="font-size:small;">78.09 EUR</span></td>
</tr>
</tbody>
</table>
</div>
<p><span style="font-size:small;"><br style="color:#000000;font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> We note that the gain (10 cents) is less than the loss (30 cents). Bob was negatively charged (-0.10 EUR, which is normal). Alice was also negatively charged (total EUR -0.20). Thus a lose-lose situation. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> For a win-lose, we can establish a minimum quota of money to be set in automatic settings for all purchases through the API. Test: Bob (balance: EUR 78.09), after mature reflection, wants to send Alice to 3 euros (balance: EUR 8.52) via Moneybookers. Bob now has a balance of EUR 75.09. Alice has a balance of approximately EUR 11.12 (8.52 +3.00 -0.10 -0.29). </span></span></p>
<div style="color:#000000;font-family:Times New Roman;">
<table id="fwas" border="0" cellspacing="0" cellpadding="3" width="100%">
<tbody>
<tr>
<td width="20%"><span style="font-size:small;">People </span></td>
<td width="20%"><span style="font-size:small;"><strong>Alice</strong></span></td>
<td width="20%"><span style="font-size:small;"><br />
</span></td>
<td width="20%"><span style="font-size:small;"><strong>Bob</strong></span></td>
<td width="20%"><span style="font-size:small;"><br />
</span></td>
</tr>
<tr>
<td width="20%"><span style="font-size:small;">Time</span></td>
<td width="20%"><span style="font-size:small;">Before </span></td>
<td width="20%"><span style="font-size:small;">After </span></td>
<td width="20%"><span style="font-size:small;">Before </span></td>
<td width="20%"><span style="font-size:small;">After </span></td>
</tr>
<tr>
<td width="20%"><span style="font-size:small;">Balance </span></td>
<td width="20%"><span style="font-size:small;">8.52 EUR</span></td>
<td width="20%"><span style="font-size:small;">11.12 EUR</span></td>
<td width="20%"><span style="font-size:small;">78.09 EUR<br />
</span></td>
<td width="20%"><span style="font-size:small;">75.09 EUR</span></td>
</tr>
</tbody>
</table>
</div>
<p><span style="font-size:small;"><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> What we are seeing? Bob was negatively charged (EUR -3.00), while Alice was positively charged (difference +2.60 EUR). This is a win-lose. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> </span></p>
<div id="f0ed" dir="ltr">The trading process works as follows: The seller exchange goods cons money from the buyer. The seller of the property does that against a sum greater than what it cost him at first with these suppliers.</p>
<p>Similarly, when that person A makes a claim and receives money from a person B. This acts as a compensatory mechanism that allows B in turn place a claim for a price equal to or greater than what it cost him to his predecessor.</p>
<p>Traditionally, it is a relationship with 2 people only. The problem if one of the 2 party may pay or reimburse. (Relationship 1 to 1) With this software alternative market, there are multiple suppliers and multiple plaintiffs. (Relation of many to many) So, this reduces the risk (1 to many relationship in 2 directions) and there are more opportunities for success.</p>
<p>As I demonstrate, we can turn a win-lose strategy into a win-win strategy. That&#8217;s what we do now.</p>
</div>
<p><span style="font-size:small;"><br style="font-family:Times New Roman;" /> <strong>Download<br />
</strong><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The software is based on a policy of transparency and sustainable development. The chosen license is the GNU GPL. It is free software. Thus, it has been made freely available on SourceForge.net to be downloaded and installed on servers online. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> * Download the complete solution directly (the most current): </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <a id="cp50" style="font-family:Times New Roman;" title="http://give1get2.com/give1get2.zip" href="http://give1get2.com/give1get2.zip">http://give1get2.com/give1get2.zip</a><br style="font-family:Times New Roman;" /> <a id="ek6y" style="font-family:Times New Roman;" title="http://give1get2.com/give1get2.7z" href="http://give1get2.com/give1get2.7z">http://give1get2.com/give1get2.7z</a><span style="font-family:Times New Roman;"> (requires software 7zip)</span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> * Mirror full download (stable): </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <a id="ukh." style="font-family:Times New Roman;" title="http://sourceforge.net/projects/give1get2/" href="http://sourceforge.net/projects/give1get2/">http://sourceforge.net/projects/give1get2/</a><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> * [Moneybookers] Demo in action: </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <a id="u4qa" style="font-family:Times New Roman;" title="http://www.moneybookers.com/app/help.pl?s=m_gateway_demo" href="http://www.moneybookers.com/app/help.pl?s=m_gateway_demo">http://www.moneybookers.com/app/help.pl?s=m_gateway_demo</a><br style="font-family:Times New Roman;" /> <a id="nhc5" style="font-family:Times New Roman;" title="https://www.moneybookers.com/app/test_payment.pl" href="https://www.moneybookers.com/app/test_payment.pl">https://www.moneybookers.com/app/test_payment.pl</a><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> * [Moneybookers] The documentation for free download: </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <a id="a78u" style="font-family:Times New Roman;" title="http://www.moneybookers.com/merchant/en/moneybookers_gateway_manual.pdf" href="http://www.moneybookers.com/merchant/en/moneybookers_gateway_manual.pdf">http://www.moneybookers.com/merchant/en/moneybookers_gateway_manual.pdf</a><br style="font-family:Times New Roman;" /> <a id="ghil" style="font-family:Times New Roman;" title="http://www.moneybookers.com/merchant/en/automated_payments_interface_manual.pdf" href="http://www.moneybookers.com/merchant/en/automated_payments_interface_manual.pdf">http://www.moneybookers.com/merchant/en/automated_payments_interface_manual.pdf</a><span style="font-family:Times New Roman;"> (not needed)</span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>Software Installation </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 1. Buy a domain name (mytradingplatformsample.com) at a Registrar. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 2. Getting accommodation containing enough space (approx 50 MB) and sufficient bandwidth (several Giga) depending on the number of users expected. (and POP3, FTP, and MySQL included) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 3. De-compress the files previously downloaded. (as above) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 4. Edit the file &#8217;scripts sql tables &#38; champs.sql&#8217;: at line 85, replace the email (alice@give1get2.com) and the merchant id (6173206) with your email and your merchant id obtained from moneybookers at the opening of your account. Replace the email as per your email on line 108. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 5. Create a database &#8220;mocha&#8221; (without the double quotes) in your administration panel (usually the URL http://mytradingplatformsample.com/phpmyadmin/) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Create a user and give access rights to the database for reading and writing. (if not already done automatically). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 6. Click the SQL tab, paste the data file &#8217;scripts sql tables &#38; champs.sql&#8217; in the textbox and click Run. No error message should appear. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 7. Change the default values by those who have been provided by the host in the file &#8216;params.php&#8217; (without the single quotes) line 31 (host), line 32 (user), line 33 (password), line 34 (database) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 8. On the web server, copy and paste the modified source (with default settings) in 7z and zip. Also create a folder /give1get2/. Upload files via FTP (ex FireFTP, a Firefox extension) with the parameters of the host ( &#8216;params.php&#8217;) in the directory previously created. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 9. Launch the browser http://mytradingplatformsample.com/give1get2/. The index page should be displayed without an error message. Sources (7z and zip) should be downloadable from a tab &#8216;literature&#8217; or &#8216;download&#8217;. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 10. Suggest your site on search engines (eg </span><a id="pukr" style="font-family:Times New Roman;" title="http://www.google.com/addurl/?continue=/addurl" href="http://www.google.com/addurl/?continue=/addurl">http://www.google.com/addurl/?continue=/addurl</a><span style="font-family:Times New Roman;">) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 11. Generate an XML sitemap and put it in the root (eg </span><a id="fucp" style="font-family:Times New Roman;" title="http://www.xml-sitemaps.com/" href="http://www.xml-sitemaps.com/">http://www.xml-sitemaps.com/</a><span style="font-family:Times New Roman;">) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 12. Optimize your website (eg with </span><a id="axfk" style="font-family:Times New Roman;" title="Google Webmaster Tools" href="https://www.google.com/webmasters/tools">Google Webmaster Tools</a><span style="font-family:Times New Roman;">) </span><br style="font-family:Times New Roman;" /> <strong><br />
Prerequisite: </strong><br style="font-family:Times New Roman;" /><br />
</span>The only equipment needed is a PC, operating system, Internet connection and web browser.</p>
<div id="tbfn" dir="ltr">Multi-platform: runs on Windows or Linux using Internet Explorer or Firefox.</div>
<div id="i__g" dir="ltr">The training is free. It is the documentation.</div>
<p><br style="font-family:Times New Roman;" /><span style="font-size:small;"> <span style="font-family:Times New Roman;"> Designed in XHTML, CSS, JavaScript, PHP and SQL (CRUD). Requires MySQL, phpMyAdmin, POP3 for mail, FTP and a web browser. Has been tested and works with Apache (&#62; = 1.3.33), MySQL (&#62; = 4.1.9), PHP (&#62; = 4.3.10), PhpMyAdmin (&#62; = 2.6.1). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> It&#8217;s a multitier architecture (data, business logic and presentation). The architecture is based on the project FreePay: </span><a id="o.di" style="font-family:Times New Roman;" title="http://freepay.fr/freepay.zip" href="http://freepay.fr/freepay.zip">http://freepay.fr/freepay.zip</a><span style="font-family:Times New Roman;"> To deepen FreePay documentation is available. </span><a id="cmdl" style="font-family:Times New Roman;" title="http://freepay.fr/freepay/nav_telechargement.php?option=documentation" href="http://freepay.fr/freepay/nav_telechargement.php?option=documentation">http://freepay.fr/freepay/nav_telechargement.php?option=documentation</a><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> </span></p>
<div id="grzx" style="font-family:Times New Roman;" dir="ltr"><span style="font-size:small;">For non French-speaking or non English speaking, there are translation tools like <a id="m750" title="Google translate" href="http://www.google.com/language_tools?hl=en">Google translate</a> to read documents in your language.<br />
</span></div>
<p><span style="font-size:small;"><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The diagram of treatment processes the merchant side of the financial institution has been copied in an picture in attachment. &#8220;moneybookers_payment_gateway_api_details_interaction_diagram.png&#8221; </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> This script is also based on the API documentation &#8220;Moneybookers Payment Gateway &#8211; Merchant Integration Manual&#8221; (in English) &#8211; Version: &#60;6.5&#62;. </span><a id="ci23" style="font-family:Times New Roman;" title="http://www.moneybookers.com/merchant/fr/moneybookers_gateway_manual.pdf" href="http://www.moneybookers.com/merchant/fr/moneybookers_gateway_manual.pdf">http://www.moneybookers.com/merchant/fr/moneybookers_gateway_manual.pdf</a><span style="font-family:Times New Roman;"> (43 pages) A new version may be out on time or you read these lines, which could cause problems. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The script takes into account that the fields by way of simplification. Regarding the optional fields: refer to official documentation. </span></span><span style="font-size:small;"><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;">The ISIN code is used again in this software (ISO 6166). The codification created the ZZ is to make a clear distinction and there have no ambiguity with the countries or territories with securities, according to ISO 3166-1.</span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>The status of a transaction (statements): </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> </span> <span style="font-size:small;"><span style="color:#000000;">2 : </span></span><span style="font-size:small;"><span style="font-family:Times New Roman;">Processed</span></span><span style="font-size:small;"><br style="color:#000000;" /> <span style="color:#000000;"> 1 : </span></span><span style="font-size:small;"><span style="font-family:Times New Roman;">Test</span></span><span style="font-size:small;"> // status added, not in the documentation<br style="color:#000000;" /> <span style="color:#000000;"> 0 : </span></span><span style="font-size:small;"><span style="font-family:Times New Roman;">Pending</span></span><span style="font-size:small;"><br style="color:#000000;" /> <span style="color:#000000;"> -1 : </span></span><span style="font-size:small;"><span style="font-family:Times New Roman;">Cancelled</span></span><span style="font-size:small;"><br style="color:#000000;" /> <span style="color:#000000;">-2 : </span></span><span style="font-size:small;"><span style="font-family:Times New Roman;">Failed </span></span><span style="font-size:small;"><br style="color:#000000;" /> <span style="color:#000000;">-3 : </span></span><span style="font-size:small;"><span style="font-family:Times New Roman;">Chargeback</span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>The Stages of development (How) </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Vision: The payment module FreePay and all of the modules below are replaced by the external API Moneybookers (financial institution approved by the FSA). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Consequences: The support payment module is outsourced. The project name no longer matches. The meta tags do not correspond. Menus no longer match. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 1. Copy FreePay. All necessary modules are not removed unless the FSX. (+ Check that it works) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 2. API Implementation Moneybookers (+ check that it works) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 3. Mashup of two (Mashup) </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> creation of specific interface </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> creation of specific process </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> creation of the specific database (+ check that it works through a simulator engine of payment) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 4. Re-factoring: Optimization Mashup (+ check that it works) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 5. Publication on Internet </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>Architecture </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The source code is in French. The source code comments are in French too. Except for the financial standards that are in English. The project is oriented towards internationalization (I18N). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> All images are in a specific folder (/images).<br />
All CSS (Stylesheets cascading) are in a specific folder (/style).<br />
All that was attractive to user support is in the /support.<br />
The documentation is in the /support /docs. </span><br style="font-family:Times New Roman;" /> </span>Everything concerning the internationalization is in the folder named &#8220;services/i18n.<br />
<br style="font-family:Times New Roman;" /><span style="font-size:small;"> <span style="font-family:Times New Roman;"> The programming style is procedural: the methods are called in a specific order. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The visible part is composed of the main page of the history and documentation. </span></span></p>
<div id="result_box" style="font-family:Times New Roman;" dir="ltr"><span style="font-size:small;">The existence of a claim can be verified through history.</span></div>
<p><span style="font-size:small;"><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Restricting access is done through the sessions for the hidden part (payment process). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> </span></p>
<div id="kwwf" style="font-family:Times New Roman;" dir="ltr"><span style="font-size:small;">The availability of a claim can be verified by applying the filter with the ISIN number as parameter.<br />
</span></div>
<p><span style="font-size:small;"><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> As a web project, the human-machine interface is based on an architecture is client/server. And the server to a 3-tier architecture (database, processing, presentation). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>The database </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> It is composed of 4 tables per financial institution: ( &#8220;scripts sql tables &#38; champs.sql&#8221; at the root) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> -2 for the securities (already existing in FSX): </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; List of past transactions carried on securities. </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; List of securities for sale in their current states. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; 2 orders of payments (the before and after): </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; List of past orders in the securities of FSX. </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; List of payment orders sent by the API. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> It is composed of 2 insertions in the tables corresponding to a title and its history. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>The stages of payment for a user in FSX </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The user has created and supplied a Moneybookers account. (</span><a id="z5vv" style="font-family:Times New Roman;" title="https://www.moneybookers.com/app/register.pl" href="https://www.moneybookers.com/app/register.pl">https://www.moneybookers.com/app/register.pl</a><span style="font-family:Times New Roman;">) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 1. The link to the login page is on the first page top right. The connection is with the email and digital identifier (Customer ID) associated with Moneybookers account. </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> (Visible beneath the menu in the interface Moneybookers). (No password is managed by Moneybookers upon payment to avoid external recovery) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 2. The user goes to the purchase page and a ISIN number (defined as the value and benefit if necessary). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The purchase order is saved and accessible via the menu of the same name. It summarizes the status of the transaction (Active / Standby, Fails / Canceled or Finished). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 3. According to the parameters ( &#8220;params.php&#8221;) defined by the administrator, the user is redirected either: </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; On the test server (mb_test_payment.php) and valid </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; Or Moneybookers (</span></span> <span style="font-size:small;"><a id="gkl6" title="https://www.moneybookers.com/app/payment.pl" href="https://www.moneybookers.com/app/payment.pl">https://www.moneybookers.com/app/payment.pl</a></span><span style="font-size:small;"><span style="font-family:Times New Roman;">) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The redirection is done through a GET (passing all the required parameters). The solution has been chosen is a javascript redirect. (&#60;script type=&#8217;text/javascript&#8217;&#62;Code&#60;/ script&#62;) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 4. If the person given the right parameters, it falls just a password. Otherwise, it creates the account. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 5. The payment is reversed or validated by the user. Moneybookers transfer money between the parties. Moneybookers sends a return code &#8220;HTTP 200&#8243; POST only the status_url previously sent ( &#8220;Payment/pay/status_report.php&#8221;) and redirects the user to the platform FSX defined above. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The software uses a coupling data (parameter passing). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> if (isset ($ _POST [ 'mb_transaction_id'])) ($mb_transaction_id = $ _POST['mb_transaction_id'];) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The data are then filtered for security reasons. ( &#8220;status_report_filtre.php&#8221;) Verifies that all fields are filled, they have the right kind, good length and good data (technical filtering whitelist). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> example: checking that the original data (IP) is really from the financial institution to avoid any fraudulent attempt to send play money. (attack type &#8220;man in the middle&#8221;) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The amount returned by moneybookers be less than the amount indicated in the reservation (due to the taking of commission (fixed and variable) of the payment platform or GET parameters that can be modified en route by the user). The transfer of ownership of securities is based on new figures sent by the API only to avoid these problems. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 6. Then, if all criteria are validated then the data are stored in the table of the api. (+ Current date) and displays as required by the file &#8216;pay_liste.php&#8217; the customer reflected in his eyes when he returns to Give1Get2. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 7. continuing process of transferring ownership (the transaction on hold &#8220;pending&#8221; changes to &#8220;done&#8221;) with the transaction number recovered by Moneybookers previously sent) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Each sale of title, money is saved in the accounts of the financial institution. In a crisis (such as unavailability of the platform title), the money, it is always available. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 8. The user can see his tracks and refresh the page (F5). It can also use the emailling to expedite the payment process, then: </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The seller receives an email notification informing the FSX the transfer of title and the reception of money. (Transmitter + Silver + currency) </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The buyer receives an email notification from the financial institution. (+ Silver + dollar + product code) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> 9. Disconnecting the trading platform (FSX) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>Views: </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The architecture views is common FreePay (header and footer together on every page). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Menu: (Home, History of titles, title Buy, Purchase Order (Confirmation is visible if the order was successful) Consult your titles, Contact Us, Documentation) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The user can see the transaction history. </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The user can buy a ISIN number. </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The user can consult the list of purchase orders and click on the transaction number for details of the transaction (if it succeeded). </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The user can see his tracks. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Compliance with W3C standards: has been validated XHTML 1.0 Transitional and CSS 2.0 in Mozilla Firefox, Internet Explorer and Safari. </span><br style="font-family:Times New Roman;" /> <strong><br />
Controllers: </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> These are the same as those of FreePay. PHP and Javascript for the client and server respectively. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Transactions that fail after 1 day were classified as having failed. (status to -2). </span><br style="font-family:Times New Roman;" /><br />
</span><strong>Security </strong></p>
<p>The application has been designed and tested CAL9000 (OWASP) to be protected against attacks like Cross Site Scripting (XSS). In the Top 10 vulnerabilities in 2007 by the Open Web Application Security Project (OWASP).<br />
<br style="font-family:Times New Roman;" /><span style="font-size:small;"> <strong>Test and Verify: </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;">The test accounts are opened at the initiative of customers. Funding test are given free Moneybookers. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Pass the following test series: Requires minimum 2 users. (Alice and Bob) Preparation: Note the financial position of existing users: &#8220;Balance in Euro&#8221; and &#8220;Balance of ISIN&#8221; for each. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Make a purchase and for 3 cases (less than, equal, higher), check: </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The balance of the buyer (Alice) has he fallen? </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The value of the security of the buyer (Alice) has she grown? </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The balance of the receiver (Bob) has he grown? </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The titles of the receiver (Bob) have decreased? </span><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> &#8211; The receiver (Bob) as been notified by email? </span><br style="font-family:Times New Roman;" /> </span><span style="font-size:small;"><br style="font-family:Times New Roman;" /> </span><strong>Next development platform: </strong></p>
<p>FaceBook + Paypal<span style="font-size:small;"><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>Legal </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> I think my system is legal because I am doing research in this direction before putting it free. I believe it is in line with the principles of the European Union. (</span><a id="ztc." style="font-family:Times New Roman;" title="http://europa.eu/scadplus/european_convention/objectives_en.htm" href="http://europa.eu/scadplus/european_convention/objectives_en.htm">http://europa.eu/scadplus/european_convention/objectives_en.htm</a><span style="font-family:Times New Roman;">). I joined in the &#8220;Support&#8221;&#62; &#8220;docs&#8221; reference documents concerning the legislative, legal and regulatory framework that could be pertinent. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> The website of the European Commission is very instructive on this issue. (</span><a id="n7yd" style="font-family:Times New Roman;" title="http://ec.europa.eu/internal_market/top_layer/index_24_en.htm" href="http://ec.europa.eu/internal_market/top_layer/index_24_en.htm">http://ec.europa.eu/internal_market/top_layer/index_24_en.htm</a><span style="font-family:Times New Roman;">) Category: European Commission&#62; Internal Market&#62; Single Market for Services&#62; Financial Services. I am not completely agree on the choice of this category since the trading platform offers a free service (without compensation) and does not manage money (only confirmation that the money has been transferred). </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Fund investments&#62; Alternative investments: there is a Draft Directive on fund managers known as &#8220;alternative. The draft guideline can still be changed, and the final version will not necessarily apply to specific cases. </span><a id="buk4" style="font-family:Times New Roman;" title="http://ec.europa.eu/internal_market/investment/alternative_investments_en.htm" href="http://ec.europa.eu/internal_market/investment/alternative_investments_en.htm">http://ec.europa.eu/internal_market/investment/alternative_investments_en.htm</a><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Payment services&#62; E-Money: The trading platform does not change. So, this concerns only the PSP Moneybookers. </span><a id="kd4y" style="font-family:Times New Roman;" title="http://ec.europa.eu/internal_market/payments/emoney/index_en.htm" href="http://ec.europa.eu/internal_market/payments/emoney/index_en.htm">http://ec.europa.eu/internal_market/payments/emoney/index_en.htm</a><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Payment services&#62; e-Invoicing: PSP is Moneybookers which manages billing (it may disable) Only one copy is kept for archive purposes by the trading platform (or nothing depending on the setting) </span><a id="bo1l" style="font-family:Times New Roman;" title="http://ec.europa.eu/internal_market/payments/einvoicing/index_en.htm" href="http://ec.europa.eu/internal_market/payments/einvoicing/index_en.htm">http://ec.europa.eu/internal_market/payments/einvoicing/index_en.htm</a><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Financial conglomerates: Depending on the size of the trading system Give1Get2 and structure, it can enter or not enter this category. It is the selection of the contractors as opportunities for merger / acquisitions. </span><a id="m:ok" style="font-family:Times New Roman;" title="http://ec.europa.eu/internal_market/financial-conglomerates/index_en.htm" href="http://ec.europa.eu/internal_market/financial-conglomerates/index_en.htm">http://ec.europa.eu/internal_market/financial-conglomerates/index_en.htm</a><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Electronic Business: It depends on what is done by customers in return for money sent. </span><a id="ij4j" style="font-family:Times New Roman;" title="http://ec.europa.eu/internal_market/e-commerce/directive_en.htm" href="http://ec.europa.eu/internal_market/e-commerce/directive_en.htm">http://ec.europa.eu/internal_market/e-commerce/directive_en.htm</a><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>Copyright: </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> My copyright is protected by the GNU General Public License. </span><a id="w0mn" style="font-family:Times New Roman;" title="http://www.gnu.org/licenses/gpl.html" href="http://www.gnu.org/licenses/gpl.html">http://www.gnu.org/licenses/gpl.html</a><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> My creations are protected at European level by Council Directive 91/250/EEC of 14 May 1991 on the legal protection of computer programs. (</span><a id="fluo" style="font-family:Times New Roman;" title="http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:31991L0250:EN:HTML" href="http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:31991L0250:EN:HTML">http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:31991L0250:EN:HTML</a><span style="font-family:Times New Roman;">)</span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> My designs are protected internationally by the Berne Convention for the Protection of Literary and Artistic Works (currently managed by the World Intellectual Property Organization (WIPO), specialized agency within the UN). (source: </span><a id="dsum" style="font-family:Times New Roman;" title="http://www.wipo.int/treaties/en/ip/berne/trtdocs_wo001.html" href="http://www.wipo.int/treaties/en/ip/berne/trtdocs_wo001.html">http://www.wipo.int/treaties/en/ip/berne/trtdocs_wo001.html</a><span style="font-family:Times New Roman;">) </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <strong>Disclaimer: </strong><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Using this application value of acceptance of the disclaimer as follows: The author assumes no responsibility for any consequences arising from the use of this application. </span><br style="font-family:Times New Roman;" /> <br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> Script comes with no warranty. </span><br style="font-family:Times New Roman;" /> <strong><br />
</strong></span></p>
<div id="tg43" dir="ltr"><strong>The Organization </strong></p>
<p>The Indefinite Lifespan Foundation is a nonprofit charitable organization, nongovernmental, dedicated to reducing human mortality, to promote the extension of life expectancy and the pursuit of happiness using mainly preventive medicine, Public health and computer science. (Currently being created)</p>
<p><strong>Contact: </strong></p>
<p>As a developer, I always look for a way to produce more at lower cost. My motivation is based on the fact that the software works and it is useful. While I agree that the type of communication is more efficient face to face, I acknowledge that I am not always available and so I put up with written documentation. Under a policy of transparency, I also put my resume attached in order to learn who wants my identity and my professional skills (which leaves several ways to contact me). His reading is optional.</p>
<p>Also, I&#8217;m open to suggestions for improving the software. If there are bugs, so I can correct them, I must have accurate knowledge. From my experience, to improve a system requires that users can contact the author for improvement of the platform is through positive feedback loops at the initiative of users. This will return to the basic architecture of the next version (which will contain the existing + corrections).</p>
</div>
<p><span style="font-size:small;"><br style="font-family:Times New Roman;" /> <span style="font-family:Times New Roman;"> If you have a problem of a financial nature relating to your moneybookers account, please contact </span><a id="h_4l" style="font-family:Times New Roman;" title="Moneybookers customer service" href="http://www.moneybookers.com/app/faqmessaging.pl">Moneybookers customer service</a><span style="font-family:Times New Roman;">.</span></span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[web güvenliği e-dergi - sayı 2]]></title>
<link>http://omercakir.wordpress.com/2009/10/09/web-guvenligi-e-dergi-sayi-2/</link>
<pubDate>Fri, 09 Oct 2009 12:53:03 +0000</pubDate>
<dc:creator>Ömer Çakır</dc:creator>
<guid>http://omercakir.wordpress.com/2009/10/09/web-guvenligi-e-dergi-sayi-2/</guid>
<description><![CDATA[Bu sayıda bahsedilmiş konular; &#8220;Açılıma Ayak Uydurmak&#8221; yazısında yakın zamanda hayata ge]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://www.webguvenligi.org/" target="_blank"><img class="alignnone" title="dergi" src="http://dergi.webguvenligi.org/images/owasptr2.gif" alt="" width="253" height="94" /></a></p>
<p align="justify">Bu sayıda bahsedilmiş konular;</p>
<ul>
<li>
<div>&#8220;Açılıma Ayak Uydurmak&#8221; yazısında yakın zamanda hayata geçirmeyi planladığımız İngilizce E-Dergi`den,</div>
</li>
<li>
<div>&#8220;Web Güvenliğine Ses Getirin&#8221; yazısında 26 Eylül`de yaptığımız buluşmadan,</div>
</li>
<li>
<div>&#8220;Django ve Güvenlik&#8221; yazısında, Django çatısının güvenlik alt yapısından,</div>
</li>
<li>
<div>&#8220;X-Forwarded-For HTTP Başlığının Kötüye Kullanımı&#8221; yazısında, X-Forwarded-For HTTP başlığının kötüye kullanılmasından <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </div>
</li>
<li>
<div>&#8220;Yazılım Güvenliğinde İnsiyatif Alın&#8221; yazısında, olgunluk modelleri ve yazılım güvenliğine uygulanmasından,</div>
</li>
<li>
<div>&#8220;ModSecurity Core Rule Set&#8221; yazısında, ModSecurity`nin yeni kuralları ve getirdikleri ve götürdüklerinden,</div>
</li>
</ul>
<p align="justify">bunlardır.</p>
<blockquote>
<p align="justify">http://dergi.webguvenligi.org/</p>
</blockquote>
<p align="justify">adresinden dergiye olaşabilirsiniz.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Web güvenliği e-dergi`nin 2. sayısı ]]></title>
<link>http://belgelerim.wordpress.com/2009/10/09/web-guvenligi-e-derginin-2-sayisi/</link>
<pubDate>Fri, 09 Oct 2009 05:10:40 +0000</pubDate>
<dc:creator>belgelerim</dc:creator>
<guid>http://belgelerim.wordpress.com/2009/10/09/web-guvenligi-e-derginin-2-sayisi/</guid>
<description><![CDATA[Açılıma Ayak Uydurmak http://dergi.webguvenligi.org/ 2. Sayı &#8211; Bünyamin Demir     Dergimizin 2]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><table id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar" style="border-collapse:collapse;border-width:0;" border="0" cellspacing="0" rules="all">
<tbody>
<tr>
<td>
<div>
<h2><a id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl02_hypBaslik" href="http://belgelerim.wordpress.com/wp-admin/websec/10-acilima-ayak-uydurmak.wgt">Açılıma Ayak Uydurmak</a></h2>
<p><a href="http://dergi.webguvenligi.org/">http://dergi.webguvenligi.org/</a></p>
<h3><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl02_lblTarih">2. Sayı</span> &#8211; <span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl02_lblYazar">Bünyamin Demir</span></h3>
<div>
<p><img style="border-width:0;" src="http://belgelerim.wordpress.com/wp-admin/images/icerik/a3qup4o2.jpg" alt="" align="left" /><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl02_lblAciklama"> </span></p>
<p> </p>
<p> </p>
<p align="justify">Dergimizin 2. sayısı ile tekrar karşınızdayız. Ayrıca yenilikler de sizleri bekliyor olacak. Bu sayımızda neler varmış hep beraber göz atalım.</p>
</div>
<div>
<p><span style="color:#ff6500;">Tags: </span><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl02_lblTag">web güvenliği topluluğu, web güvenliği, e-dergi, 2. sayı</span></p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div>
<h2><a id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl03_hypBaslik" href="http://belgelerim.wordpress.com/wp-admin/websec/11-web-guvenligine-ses-getirin.wgt">Web Güvenliğine Ses Getirin</a></h2>
<p><a href="http://dergi.webguvenligi.org/">http://dergi.webguvenligi.org/</a></p>
<h3><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl03_lblTarih">2. Sayı</span> &#8211; <span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl03_lblYazar">Bedirhan Urgun</span></h3>
<div>
<p><img style="border-width:0;" src="http://belgelerim.wordpress.com/wp-admin/images/icerik/arpfglgm.jpg" alt="" align="left" /><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl03_lblAciklama"> </span></p>
<p> </p>
<p> </p>
<p align="justify">Bu yazımızda 26 Eylül`de İstanbulda düzenlenen Web Güvenlik Topluluğu <a href="http://www.webguvenligi.org/etkinlik/bulusma-26-eylul.html">buluşması</a> izlenimlerini Bedirhan Urgun sizlerle paylaşıyor.</p>
</div>
<div>
<p><span style="color:#ff6500;">Tags: </span><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl03_lblTag">web güvenliği topluluğu, buluşma, etkinlik, owasp/tr</span></p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div>
<h2><a id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl04_hypBaslik" href="http://belgelerim.wordpress.com/wp-admin/websec/12-django-ve-guvenlik.wgt">Django ve Güvenlik</a></h2>
<p><a href="http://dergi.webguvenligi.org/">http://dergi.webguvenligi.org/</a></p>
<h3><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl04_lblTarih">2. Sayı</span> &#8211; <span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl04_lblYazar">Emre Yılmaz</span></h3>
<div>
<p><img style="border-width:0;" src="http://belgelerim.wordpress.com/wp-admin/images/icerik/bai1peuc.jpg" alt="" align="left" /><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl04_lblAciklama"> </span></p>
<p> </p>
<p> </p>
<p align="justify">Bu sayımızın konuk yazarlarından olan Emre Yılmaz, Django platformu geliştiricileri için, &#8220;Django`da güvenli uygulama geliştirme&#8221; konusunda püf noktaları paylaşıyor.</p>
</div>
<div>
<p><span style="color:#ff6500;">Tags: </span><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl04_lblTag">django, framework, python</span></p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div>
<h2><a id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl05_hypBaslik" href="http://belgelerim.wordpress.com/wp-admin/websec/13-xforwardedfor-http-basliginin-kotuye-kullanimi.wgt">X-Forwarded-For HTTP Başlığının Kötüye Kullanımı</a></h2>
<p><a href="http://dergi.webguvenligi.org/">http://dergi.webguvenligi.org/</a></p>
<h3><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl05_lblTarih">2. Sayı</span> &#8211; <span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl05_lblYazar">Sertan Kolat</span></h3>
<div>
<p><img style="border-width:0;" src="http://belgelerim.wordpress.com/wp-admin/images/icerik/dijupx5u.jpg" alt="" align="left" /><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl05_lblAciklama"> </span></p>
<p> </p>
<p> </p>
<p align="justify">Bu sayımızda ki bir diğer konuk yazarımız olan Sertan Kolat, X-Forwarded-For başlığını güvenlik açısından ele alıyor.</p>
</div>
<div>
<p><span style="color:#ff6500;">Tags: </span><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl05_lblTag">HTTP header injection, x-forwarded-for</span></p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div>
<h2><a id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl06_hypBaslik" href="http://belgelerim.wordpress.com/wp-admin/websec/14-yazilim-guvenliginde-insiyatif-alin.wgt">Yazılım Güvenliğinde İnsiyatif Alın</a></h2>
<p><a href="http://dergi.webguvenligi.org/">http://dergi.webguvenligi.org/</a></p>
<h3><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl06_lblTarih">2. Sayı</span> &#8211; <span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl06_lblYazar">Bedirhan Urgun</span></h3>
<div>
<p><img style="border-width:0;" src="http://belgelerim.wordpress.com/wp-admin/images/icerik/xiydmcl2.jpg" alt="" align="left" /><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl06_lblAciklama"> </span></p>
<p> </p>
<p> </p>
<p align="justify">Bu yazımızda, &#8220;Yazılım Güvenliği Olgunluk Modellerine&#8221; değinerek, web güvenliğinde olgunluk modellerinin nasıl uygulanabileceği konusunda fikir vermeye çalışacağız.</p>
</div>
<div>
<p><span style="color:#ff6500;">Tags: </span><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl06_lblTag">yazılım güvenliği, samm, olgunluk modelleri</span></p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div>
<h2><a id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl07_hypBaslik" href="http://belgelerim.wordpress.com/wp-admin/websec/15-modsecurity-core-rule-set-2-0.wgt">ModSecurity Core Rule Set 2.0</a></h2>
<p><a href="http://dergi.webguvenligi.org/">http://dergi.webguvenligi.org/</a></p>
<h3><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl07_lblTarih">2. Sayı</span> &#8211; <span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl07_lblYazar">Bünyamin Demir</span></h3>
<div>
<p><img style="border-width:0;" src="http://belgelerim.wordpress.com/wp-admin/images/icerik/0h3yk54q.jpg" alt="" align="left" /><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl07_lblAciklama"> </span></p>
<p> </p>
<p> </p>
<p align="justify">Web uygulama güvenlik duvarlarının (WAF) en iyilerinden birisi olan ModSecurity`nin yenilenen core rule seti ile ilgili incelemelerimize bu yazımızdan ulaşabilirsiniz.</p>
</div>
<div>
<p><span style="color:#ff6500;">Tags: </span><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl07_lblTag">modsecurity, waf, core rule set</span></p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div>
<h2><a id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl08_hypBaslik" href="http://belgelerim.wordpress.com/wp-admin/websec/16-web-uygulamalarina-yonelik-saldirilar.wgt">Web Uygulamalarına Yönelik Saldırılar</a></h2>
<p><a href="http://dergi.webguvenligi.org/">http://dergi.webguvenligi.org/</a></p>
<h3><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl08_lblTarih">2. Sayı</span> &#8211; <span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl08_lblYazar">Onur Yılmaz</span></h3>
<div>
<p><img style="border-width:0;" src="http://belgelerim.wordpress.com/wp-admin/images/icerik/0xjtygxk.jpg" alt="" align="left" /><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl08_lblAciklama"> </span></p>
<p> </p>
<p> </p>
<p align="justify">Web Uygulamalarına Yönelik Saldırılar konulu iki bölüm şeklinde hazırlanacak bu makalede, teorik olarak uygulamaların çalışma mantığı incelenecek ve saldırıların bu bağlamda nasıl şekillenebileceği aktarılmaya çalışılacaktır.</p>
</div>
<div>
<p><span style="color:#ff6500;">Tags: </span><span id="ctl00_ContentPlaceHolderIcerik_ortaYazilar1_gridYazilar_ctl08_lblTag">web güvenliği, thread model, web uygulamaları</span></p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP Bangalore Free Return Air Tickets OR Complementary Conference ]]></title>
<link>http://ambatisreedhar.wordpress.com/2009/10/05/owasp-bangalore-free-return-air-tickets-or-complementary-conference/</link>
<pubDate>Mon, 05 Oct 2009 18:11:10 +0000</pubDate>
<dc:creator>ambatisreedhar</dc:creator>
<guid>http://ambatisreedhar.wordpress.com/2009/10/05/owasp-bangalore-free-return-air-tickets-or-complementary-conference/</guid>
<description><![CDATA[Only limited seats are available and the offer will open up on 6th October 2009 and will be valid on]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Only limited seats are available and the offer will open up on 6th October 2009 and will be valid only till 15th October 2009. Hope to see you gaining the benefits from this promo-campaign.</p>
<p>Detailed event agenda with pricing information and conditions attached to the offer is available at our wiki: <a href="http://www.owasp.org/index.php/SecurityByte_and_OWASP_Asia_AppSec_Conference_2009">http://www.owasp.org/index.php/SecurityByte_and_OWASP_Asia_AppSec_Conference_2009</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Watching Application Security Mature Around Us]]></title>
<link>http://supplychaintechnology.wordpress.com/2009/10/02/watching-application-security-mature-around-us/</link>
<pubDate>Fri, 02 Oct 2009 17:33:31 +0000</pubDate>
<dc:creator>Jim</dc:creator>
<guid>http://supplychaintechnology.wordpress.com/2009/10/02/watching-application-security-mature-around-us/</guid>
<description><![CDATA[Despite the goofy name, Security Ninja in the UK &#8212; the site&#8217;s subtitle is &#8220;Securit]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="size-thumbnail wp-image-372 alignright" title="3d key" src="http://supplychaintechnology.wordpress.com/files/2009/10/istock_000008600296xsmall.jpg?w=150" alt="3d key" width="150" height="149" />Despite the goofy name, Security Ninja in the UK &#8212; the site&#8217;s subtitle is &#8220;Security News, Research &#38; Guidance&#8221; &#8212; has some good resources for application security, and is a solid contribution to the discussion around application security that&#8217;s been growing over the last few years.  The primary contributor to the Security Ninja site is a security analyst working with an application called Realex Payments.</p>
<p>At the Security Ninja site they&#8217;ve developed 8 secure development principles which include:<!--more--></p>
<ol>
<li>Input Validation</li>
<li>Output Validation</li>
<li>Error Handling</li>
<li>Authentication and Authorization</li>
<li>Session Management</li>
<li>Secure Communications</li>
<li>Secure Resource Access</li>
<li>Secure Storage</li>
</ol>
<p>While they dive into more detail for each of these topics, they also are posting a series of articles mapping each of these to features of the OWASP Enterprise Security API (ESAPI) project.</p>
<p>You can read the first posting regarding input validation using the OWASP ESAPI here: <a href="http://www.securityninja.co.uk/input-validation-using-the-owasp-esapi">http://www.securityninja.co.uk/</a><a href="http://www.securityninja.co.uk/input-validation-using-the-owasp-esapi">input-validation-using-the-owasp-esapi</a>.</p>
<p>Libraries such as those OWASP provides are great resources; having real-life examples to work with makes them even more useful.  I hope the Security Ninja continues the series, adding to the ongoing development of the AppSec body of knowledge.</p>
<p><strong>Links:</strong></p>
<ul>
<li><a href="http://www.securityninja.co.uk/home/" target="_blank">Security Ninja website</a> &#38; on <a href="http://twitter.com/securityninja" target="_blank">Twitter</a></li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API" target="_blank">OWASP ESAPI</a></li>
<li><a href="http://www.securityninja.co.uk/input-validation-using-the-owasp-esapi">Input validation with the OWASP ESAPI</a></li>
</ul>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Web Güvenlik Topluluğu Buluşması Gerçekleşti]]></title>
<link>http://dorukdestan.wordpress.com/2009/09/27/web-guvenlik-toplulugu-bulusmasi-gerceklesti/</link>
<pubDate>Sun, 27 Sep 2009 16:04:09 +0000</pubDate>
<dc:creator>Destan Sarpkaya</dc:creator>
<guid>http://dorukdestan.wordpress.com/2009/09/27/web-guvenlik-toplulugu-bulusmasi-gerceklesti/</guid>
<description><![CDATA[OWASP Türkiye temsilciliğini de yapan Web Güvenlik Topluluğu&#8216;nun 26 Eylül cumartesi günkü bulu]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>OWASP Türkiye temsilciliğini de yapan <a href="http://www.webguvenligi.org" target="_blank">Web Güvenlik Topluluğu</a>&#8216;nun 26 Eylül cumartesi günkü buluşması Beyoğlu&#8217;ndaki Turkcell Akademi binasında gerçekleşti. Toplantıda topluluğun genel durumu, bitmiş / devam eden  projeler ve yeni proje teklifleri konuşuldu.<a href="http://dergi.webguvenligi.org/" target="_blank"> E-dergi</a>nin daha geniş kullanıcı kitlesine ulaştırılması da öne çıkan konulardan biriydi.</p>
<p><a href="http://www.sans.org/" target="_blank">SANS </a>firmasının Türkiye&#8217;deki mentorlarından İbrahim Saruhan &#8220;Sosyal Ağlarda Güvenlik&#8221; temalı bir sunum yaptı. Sunumda Facebook ve Twitter gibi iki büyük ağda DDoS ataklarına olanak sağlayabilecek açıklar üzerinde duruldu.</p>
<p>Son olarak Halil Öztürkci ve İbrahim Saruhan, SANS kuruluşunun Türkiye&#8217;de ilk kez açacağı “Security 560: Network Penetration Testing and Ethical Hacking” eğitimi hakkında bilgi verdiler. İlgilenenler için<a href="http://www.sans.org/mentor/details.php?nid=19944" target="_blank"> detaylı bilgi &#62;&#62;</a></p>
<p>Sonuç olarak samimi bir havada geçen buluşmanın benim için faydalı geçtiğini düşünüyorum.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exposed to XSS? Regain Your Composure (and Security)]]></title>
<link>http://artofdefence.wordpress.com/2009/09/22/exposed-to-xss-regain-your-composure-and-security/</link>
<pubDate>Tue, 22 Sep 2009 20:49:14 +0000</pubDate>
<dc:creator>hyperguard</dc:creator>
<guid>http://artofdefence.wordpress.com/2009/09/22/exposed-to-xss-regain-your-composure-and-security/</guid>
<description><![CDATA[I recently read a very interesting article, Tech Insight: XSS Exposed, by Dark Reading’s John Sawyer]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>I recently read a very interesting article, <a href="http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=219501411">Tech Insight: XSS Exposed</a>, by Dark Reading’s John Sawyer. He discusses how a cross-site scripting (XSS) attack can steal a user’s credentials, exploit their Web browsers and take action on their behalf without their knowledge. I wanted to add some of my thoughts on this article and share ways users can prevent and protect themselves against these attacks.</p>
<p>As stated in the article, XSS is always caused by missing input validation, the place where <a href="http://www.artofdefence.com/dokumente/Cloud_AppSec_Whitepaper.pdf">hyperguard</a> comes into play. It scans every request (and therefore every user input) for malicious code that wants to be stored or executed. When a user is tricked into clicking a link containing XSS, the request is denied by the distributed web application firewall (dWAF) and the script will not run. Also, the script will not get stored into a database if the dWAF prohibits the request with the data from entering the web application.<em> </em>The problem with persistent XSS is that it is typically done on a prepared site that has bait for the victim, resulting in running malicious code.</p>
<p>The mechanism behind the protection that hyperguard delivers is easy and contains blacklist rules. These patterns know what an XSS looks like and causes the dWAF to deny the request. The second and more secure approach is to whitelist all input in the application. This is more work, but it helps to create a very secure web application, where every user input is validated. XSS attacks can take on many forms so you should never trust input from users.</p>
<p>In John’s article, he mentions OWASP’s <a href="http://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%29_Prevention_Cheat_Sheet">XSS Prevention Cheat Sheet</a>, which provides detailed information on when and where encoding should be done. XSS attacks should be taken seriously because they do happen often and can be very costly for businesses. It is important to take the necessary steps to prevent them and learn how to protect yourself if they do occur.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Reaction to SearchSOA.com: Common WebAppSec exploits]]></title>
<link>http://artofdefence.wordpress.com/2009/09/17/reaction-to-searchsoa-com-common-webappsec-exploits/</link>
<pubDate>Thu, 17 Sep 2009 15:04:00 +0000</pubDate>
<dc:creator>hyperguard</dc:creator>
<guid>http://artofdefence.wordpress.com/2009/09/17/reaction-to-searchsoa-com-common-webappsec-exploits/</guid>
<description><![CDATA[Great article on the 16th from SearchSOA.com by Rob Barry. He interviews a developer at Mozilla Labs]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Great article on the 16<sup>th</sup> <a href="http://searchsoa.techtarget.com/tip/0,289483,sid26_gci1368439,00.html">from SearchSOA.com by Rob Barry</a>. He interviews a developer at Mozilla Labs – Joe Walker &#8211; about a few of the <a href="http://owasp.blogspot.com/">OWASP</a> Top 10 and how to develop around them. Walker’s focus as a developer is on creating / patching / managing security threats to apps. What’s missing from Barry’s article, however, is the incredible pain this approach causes companies right now.</p>
<p>Refactoring code once it’s in use (particularly WebApps and cloud services) is incredibly expensive, time consuming and difficult. Source code scanners play a role in easing some of this pain, although web application firewalls (WAF’s) are a much more practical fix, AND, linking the scanner software directly with the WAF cuts down the need for application downtime.</p>
<p>If done right, the scanner detects software vulnerabilities and feeds any findings directly into the WAF. For <a href="detects%20software%20vulnerabilities%20and%20feeds%20any%20findings%20directly%20into%20art%20of%20defence%E2%80%99s%20dWAF%20solution,%20hyperguard%E2%84%A2.%20All%20security%20lapses%20identified%20are%20immediately%20presented%20to%20the%20administrator%20through%20dynamic%20ruleset%20suggestions%20within%20hyperguard.%20Conflict">our distributed WAF (dWAF) solution</a>, hyperguard, all security lapses identified by a scanner are immediately presented to the administrator through dynamic ruleset suggestions. Conflicting dWAF rulesets, which may leave holes in web application shielding, are prevented. In plain English, this means that development, testing and deployment of new application security policies can happen in real-time without ever relaxing the established defenses or risking false positives. ‘Patches’ are applied through the dWAF until regular maintenance cycles can be scheduled to refactor the actual application code.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP NULL MEET 19th Sep 2009]]></title>
<link>http://ambatisreedhar.wordpress.com/2009/09/16/owasp-null-meet-19th-sep-2009/</link>
<pubDate>Wed, 16 Sep 2009 18:37:41 +0000</pubDate>
<dc:creator>ambatisreedhar</dc:creator>
<guid>http://ambatisreedhar.wordpress.com/2009/09/16/owasp-null-meet-19th-sep-2009/</guid>
<description><![CDATA[OWASP is combined with NULL Bangalore 19th September 2009 The following talks are scheduled 1. SSL C]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>OWASP is combined with NULL Bangalore</p>
<p>19th September 2009</p>
<p>The following talks are scheduled</p>
<p>1. SSL Cipher Ennumeration by Gursev<br />
This is what he will be covering<br />
    # Aim: Enumerate all ciphers suites supported by the web server.<br />
    # Application: Auditing of cipher suites supported by web server.<br />
Testing ciphers supported by web servers is mandatory for various<br />
activities like PCI tests, Penetration testing<br />
       and possibly other compliance issues.<br />
    # Discuss about SSL basics (very basics)<br />
    # Then we dig down and write a quick script using OpenSSL and Ruby<br />
to help achieve the same.</p>
<p>2. Demonstration of a tool – Amit Parekh<br />
3. Demo of the GIFAR attack &#8211; Amit Gupta<br />
4. Discussion on security incidents in the past – Led by Gursev //<br />
This may or mayn&#8217;t happen depending on the time we have</p>
<p>The talk Practical Aspects of Taking your Application to the Cloud by<br />
Simran Gambhir is postponed till after he recovers from a broken foot.<br />
Get well soon dude!</p>
<p>VENUE DETAILS</p>
<p>    Praxeva India Services Pvt. Ltd, Atrium Business Center, 66/1 2nd<br />
Floor, Coles Road, Frazer Town, Bangalore-560005</p>
<p>Praxeva India Office Location on Google Map -<br />
<a href="http://www.praxeva.com/contact_us.html">http://www.praxeva.com/contact_us.html</a></p>
<p>* End of mosque road there is a CCD, from there, if you look<br />
diagonally opposite (onto coles road), you will see a pizza hut<br />
(approx 100 meters). The office is on the 3rd floor of the pizza<br />
hut building.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP AppSec DC 2009 Coming Up - Remember to Register!]]></title>
<link>http://sintixerr.wordpress.com/2009/09/12/owasp-appsec-dc-2009-coming-up-remember-to-register/</link>
<pubDate>Sat, 12 Sep 2009 12:35:09 +0000</pubDate>
<dc:creator>Jack Whitsitt</dc:creator>
<guid>http://sintixerr.wordpress.com/2009/09/12/owasp-appsec-dc-2009-coming-up-remember-to-register/</guid>
<description><![CDATA[I just wanted to make sure everyone remembers to register for this great conference in DC this year.]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>I just wanted to make sure everyone remembers to register for this great conference in DC this year.  From their <a title="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009" href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2009" target="_blank">website</a>:</p>
<blockquote><p><span style="color:#000000;"><strong>Press Release August 20th 2009 &#8212; <a title="http://www.owasp.org/images/4/4d/Press_Release_AppSec_DC_August_20th_2009.pdf" rel="nofollow" href="http://www.owasp.org/images/4/4d/Press_Release_AppSec_DC_August_20th_2009.pdf" target="_blank">Speaker Agenda Released and Registration Open!</a></strong></span></p>
<p><span style="color:#000000;">We are pleased to announce that the <a title="http://www.owasp.org/index.php/Washington_DC" rel="nofollow" href="http://www.owasp.org/index.php/Washington_DC" target="_blank">OWASP DC chapter</a> will host the OWASP AppSec 2009 conference in Washington, DC. The AppSec DC OWASP Conference will be a premier gathering of Information Security leaders. Executives from Fortune 500 firms along with technical thought leaders such as security architects and lead developers will be traveling to hear the cutting-edge ideas presented by Information Security’s top talent. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 600-700 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.</span></p>
<p><span style="color:#000000;">AppSec DC 2009 will be held at the <a title="http://www.dcconvention.com/" rel="nofollow" href="http://www.dcconvention.com/" target="_blank">Walter E. Washington Convention Center</a> (801 Mount Vernon Place NW Washington, DC 20001) on November 10th through 13th 2009.</span></p>
<p><span style="color:#000000;"><strong>Who Should Attend AppSec DC 2009:</strong></span></p>
<ul>
<li><span style="color:#000000;">Application Developers</span></li>
<li><span style="color:#000000;">Application Testers and Quality Assurance</span></li>
<li><span style="color:#000000;">Application Project Management and Staff</span></li>
<li><span style="color:#000000;">Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff</span></li>
<li><span style="color:#000000;">Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance</span></li>
<li><span style="color:#000000;">Security Managers and Staff</span></li>
<li><span style="color:#000000;">Executives, Managers, and Staff Responsible for IT Security Governance</span></li>
<li><span style="color:#000000;">IT Professionals Interesting in Improving IT Security</span></li>
</ul>
</blockquote>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NULL Meet 19th Sep 2009]]></title>
<link>http://ambatisreedhar.wordpress.com/2009/09/07/null-meet-19th-sep-2009/</link>
<pubDate>Mon, 07 Sep 2009 17:39:01 +0000</pubDate>
<dc:creator>ambatisreedhar</dc:creator>
<guid>http://ambatisreedhar.wordpress.com/2009/09/07/null-meet-19th-sep-2009/</guid>
<description><![CDATA[Source: http://null.co.in/2009/09/07/null-bangalore-meeting-on-5th-september-2009-an-update/ NEXT ME]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Source: <a href="http://null.co.in/2009/09/07/null-bangalore-meeting-on-5th-september-2009-an-update/">http://null.co.in/2009/09/07/null-bangalore-meeting-on-5th-september-2009-an-update/</a></p>
<p>NEXT MEETING on 19th SEPTEMBER 2009 &#8211; 10 AM</p>
<p>The following talks are scheduled</p>
<p>1. Practical Aspects of Taking your Application to the Cloud &#8211; Simran Gambhir<br />
2. Discussion on security incidents in the past &#8211; Led by Gursev<br />
3. Demonstration of a tool &#8211; Amit Parekh</p>
<p>VENUE DETAILS</p>
<p>Venue : Praxeva India Services Pvt. Ltd, Atrium Business Center,<br />
66/1 2nd Floor, Coles Road, Frazer Town, Bangalore-560005</p>
<p>Map Location : <a href="http://www.praxeva.com/contact_us.html">http://www.praxeva.com/contact_us.html</a></p>
<p>* End of mosque road there is a CCD, from there, if you look diagonally<br />
opposite (onto coles road), you will see a pizza hut (approx 100 meters). The<br />
office is on the 3rd floor of the pizza hut building.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jeremiah's Right about Scalability]]></title>
<link>http://artofdefence.wordpress.com/2009/09/01/jeremiahs-right-about-scalability/</link>
<pubDate>Tue, 01 Sep 2009 23:59:05 +0000</pubDate>
<dc:creator>hyperguard</dc:creator>
<guid>http://artofdefence.wordpress.com/2009/09/01/jeremiahs-right-about-scalability/</guid>
<description><![CDATA[I recently read Web security is about scalability, a very interesting post by Jeremiah Grossman of W]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>I recently read <a href="http://jeremiahgrossman.blogspot.com/2009/08/web-security-is-about-scalability.html">Web security is about scalability</a>, a very interesting post by Jeremiah Grossman of White Hat Security. He discusses the importance of scalability in overcoming today’s Web security challenges. I would like to add some of my thoughts.</p>
<p>It has taken the industry over 10 years to realize that when dealing with Web application vulnerabilities, they must also deal with the scalability issues these applications face. This needs to happen in parallel with normal security testing. As Jeremiah highlights the incredible scaling needed today:</p>
<p><em>“Consider that there are 240+ million websites, millions more added every month, an unknown number of Intranet Web applications, 17+ million developers, and over one billion people on the Web. Any solution capable of making a real difference must be valued by its potential worldwide impact.”</em></p>
<p>Testing a web application on a single system (how most are tested before being sent out into the world) without taking into account scalability is costly. Once that application hits it’s performance limit it usually means a redesign and rewrite of core elements to make it more scalable, changing how and what is important to test. Think of the <a href="http://www.owasp.org/index.php/Top_10_2007">OWASP top 10</a> on Jeremiah’s scale!</p>
<p>Cluster computing, or cloud computing, presents a remedy to developing, testing and scaling web applications in a much more practical sense.</p>
<p>Flip the coin to protecting the applications once they’re live and in action, and Jeremiah’s scalability point becomes painfully apparent. Web application firewall’s (WAF) are the industry standard for this purpose, however they are predominantly hardware. Hardware doesn’t scale – you have to buy another box. More boxes, more resource drain, less virtualized resources and on and on.</p>
<p>The article Jeremiah references in his post (check <a href="http://www.artofdefence.com/dokumente/Cloud_AppSec_Whitepaper.pdf">here for the white paper</a>), outlines my view of what the market needs from a WAF.</p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
