<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>pt.webappsec &#187; ibwas</title>
	<atom:link href="http://webappsec.netmust.eu/tag/ibwas/feed/" rel="self" type="application/rss+xml" />
	<link>http://webappsec.netmust.eu</link>
	<description>Segurança de Aplicações Web</description>
	<lastBuildDate>Mon, 29 Nov 2010 11:35:52 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>IBWAS&#8217;10 Registration is open (and free)</title>
		<link>http://webappsec.netmust.eu/2010/11/29/ibwas10-registration-is-open-and-free/</link>
		<comments>http://webappsec.netmust.eu/2010/11/29/ibwas10-registration-is-open-and-free/#comments</comments>
		<pubDate>Mon, 29 Nov 2010 11:35:52 +0000</pubDate>
		<dc:creator>Carlos Serrao</dc:creator>
				<category><![CDATA[OWASP]]></category>
		<category><![CDATA[ibwas]]></category>
		<category><![CDATA[registration]]></category>

		<guid isPermaLink="false">http://webappsec.netmust.eu/2010/11/29/ibwas10-registration-is-open-and-free/</guid>
		<description><![CDATA[Registrations to the OWASP IBWAS&#8217;10 Conference Day, to be held on the 17th are now open. Registration is mandatory but free.






]]></description>
			<content:encoded><![CDATA[<p>Registrations to the <a href="http://www.owasp.org/index.php/IBWAS10">OWASP IBWAS&#8217;10</a> <a href="http://www.owasp.org/index.php/IBWAS10#tab=17th_December">Conference Day</a>, to be held on the 17th are <a href="http://ibwas10.eventbrite.com/">now open</a>. Registration is mandatory but free.<br /></p>

<div><br /><br /></div>

<p style="clear: both"><a href="http://webappsec.netmust.eu/wp-content/uploads/2010/11/620px-IBWAS10_logo.gif" class="image-link"><img class="linked-to-original" src="http://webappsec.netmust.eu/wp-content/uploads/2010/11/620px-IBWAS10_logo-thumb.gif" height="171" width="380" style=" text-align: center; display: block; margin: 0 auto 10px;" /></a></p>

<p><br class="final-break" style="clear: both" /></p>
]]></content:encoded>
			<wfw:commentRss>http://webappsec.netmust.eu/2010/11/29/ibwas10-registration-is-open-and-free/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Poster do IBWAS&#8217;10</title>
		<link>http://webappsec.netmust.eu/2010/07/29/poster-do-ibwas10/</link>
		<comments>http://webappsec.netmust.eu/2010/07/29/poster-do-ibwas10/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 21:11:32 +0000</pubDate>
		<dc:creator>Carlos Serrao</dc:creator>
				<category><![CDATA[OWASP]]></category>
		<category><![CDATA[ibwas]]></category>
		<category><![CDATA[poster]]></category>

		<guid isPermaLink="false">http://webappsec.netmust.eu/2010/07/29/poster-do-ibwas10/</guid>
		<description><![CDATA[Aqui fica igualmente uma versão em PDF.


]]></description>
			<content:encoded><![CDATA[<p style="clear: both"><a href="http://webappsec.netmust.eu/wp-content/uploads/2010/07/IBWAS10_Poster_EN.png" class="image-link"><img class="linked-to-original" src="http://webappsec.netmust.eu/wp-content/uploads/2010/07/IBWAS10_Poster_EN-thumb.png" height="532" width="380" style=" text-align: center; display: block; margin: 0 auto 10px;" /></a>Aqui fica igualmente uma versão em <a href="http://ibwas09.netmust.eu/files/ibwas10/IBWAS10_Poster_EN.pdf">PDF</a>.</p>

<p><br class="final-break" style="clear: both" /></p>
]]></content:encoded>
			<wfw:commentRss>http://webappsec.netmust.eu/2010/07/29/poster-do-ibwas10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP IBWAS&#8217;10 Call for Training Proposals</title>
		<link>http://webappsec.netmust.eu/2010/07/28/owasp-ibwas10-call-for-training-proposals/</link>
		<comments>http://webappsec.netmust.eu/2010/07/28/owasp-ibwas10-call-for-training-proposals/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 23:55:53 +0000</pubDate>
		<dc:creator>Carlos Serrao</dc:creator>
				<category><![CDATA[OWASP]]></category>
		<category><![CDATA[ibwas]]></category>
		<category><![CDATA[portugal]]></category>
		<category><![CDATA[Proposals]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://webappsec.netmust.eu/2010/07/28/owasp-ibwas10-call-for-training-proposals/</guid>
		<description><![CDATA[2nd. OWASP Ibero-American Web-Applications Security conference (IBWAS’10)ISCTE – Lisbon University Institute25th – 26th November 2010Lisboa, Portugalhttp://www.ibwas.com

**CALL FOR TRAINING SESSIONS**  

IBWAS and OWASP is currently soliciting training proposals for the OWASP Ibero-American Web Applications Security 2010 Conference (IBWAS&#8217;10) which will take place at ISCTE-IUL, Lisboa, Portugal, on November 24 through November 26, 2010. 

There will be training]]></description>
			<content:encoded><![CDATA[<p style="clear: both">2nd. OWASP Ibero-American Web-Applications Security conference (IBWAS’10)<br />ISCTE – Lisbon University Institute<br />25th – 26th November 2010<br />Lisboa, Portugal<br />http://www.ibwas.com</p>

<p style="clear: both">**CALL FOR TRAINING SESSIONS**  </p>

<p style="clear: both">IBWAS and OWASP is currently soliciting training proposals for the OWASP Ibero-American Web Applications Security 2010 Conference (IBWAS&#8217;10) which will take place at ISCTE-IUL, Lisboa, Portugal, on November 24 through November 26, 2010. </p>

<p style="clear: both">There will be training courses on November 24 followed by plenary sessions on the 25 and 26 with multiple tracks per day.  </p>

<p style="clear: both">We are seeking training proposals on the following topics (in no particular order): <br />- Application Threat Modeling <br />- Business Risks with Application Security <br />- Hands-on Source Code Review <br />- Metrics for Application Security <br />- OWASP Tools and Projects <br />- Privacy Concerns with Applications and Data Storage <br />- Secure Coding Practices (J2EE/.NET) <br />- Starting and Managing Secure Development Lifecycle Programs <br />- Technology specific presentations on security such as AJAX, XML, etc <br />- Web Application Security countermeasures <br />- Web Application Security Testing <br />- Web Services, XML and Application Security <br />- Anything else relating to OWASP and Application Security  </p>

<p style="clear: both">Proposals on topics not listed above but related to the conference (i.e. which are related to Application Security) may also be accepted. </p>

<p style="clear: both">To make a submission you must fill out the form available at http://ibwas09.netmust.eu/files/ibwas10/OWASP_IBWAS_2010_CFT.rtf.zip and submit by email to secretariat@ibwas.com.</p>

<p style="clear: both">There may be 1 or half a day courses. The proposals must respect the restrictions of the OWASP Speaker Agreement. The conference will reward trainers with at least 30% of the total revenue of their courses, based on a minimum attendance. Courses that attract more students may be granted higher percentages. No other compensation (such as tickets or lodging) will be provided. If you require a different arrangement, please contact the conference chair at the email address below.</p>

<p style="clear: both">**Compensation**<br />Instructors and authors will be paid based on the number of students in their training sessions. If the training gathers only the minimum number of students, the compensation will be 30% of the revenue. For each group of 10 extra students enrolled, the compensation will be increased by 5% of the revenue, up to a maximum of 45% of the training revenue. For example, a 1-day training with 10 to 19 students will generate a compensation of 30% of the revenue. For classes of 20 to 29 students, the compensation raises to 35% percent of the revenue.</p>

<p style="clear: both">In exceptional cases, different compensation schemes may be accepted. Please contact the conference organization team by email (secretariat@ibwas.com) for details.</p>

<p style="clear: both">**Training cost**<br /> half-day training: 250 EUR per student<br /> 1-day training: 450 EUR per student <br />All prices in Euros (EUR)</p>

<p style="clear: both">**Minimum number of students**<br /> half-day trainings: 10 students<br /> 1-day trainings: 20 students<br /> <br />**Important Dates:**  <br />Submission deadline is September 20, 2010.  <br />Notification of acceptance will be October 8, 2010.  <br />Final version is due October 29, 2010.  </p>

<p style="clear: both">The conference organization team may be contacted by email at secretariat@ibwas.com  </p>

<p style="clear: both">For more information, please see the following web pages:<br /> Conference Website: http://www.ibwas.com, http://www.owasp.org/index.php/IBWAS10<br /> OWASP Speaker Agreement: http://www.owasp.org/index.php/Speaker_Agreement<br /> OWASP Website: http://www.owasp.org<br /> Easychair conference site: http://www.easychair.org/conferences/?conf=ibwas10<br /> Presentation proposal form: http://ibwas09.netmust.eu/files/ibwas10/OWASP_IBWAS_2010_CFT.rtf.zip</p>

<p style="clear: both">********** WARNING: Submissions without all the information requested in the proposal form will not be considered ************</p>

<p style="clear: both">Please forward to all interested practitioners and colleagues.</p>

<p><br class="final-break" style="clear: both" /></p>
]]></content:encoded>
			<wfw:commentRss>http://webappsec.netmust.eu/2010/07/28/owasp-ibwas10-call-for-training-proposals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IBWAS&#8217;10 muda de data</title>
		<link>http://webappsec.netmust.eu/2010/07/15/ibwas10-muda-de-data/</link>
		<comments>http://webappsec.netmust.eu/2010/07/15/ibwas10-muda-de-data/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 22:12:36 +0000</pubDate>
		<dc:creator>Carlos Serrao</dc:creator>
				<category><![CDATA[OWASP]]></category>
		<category><![CDATA[conferências]]></category>
		<category><![CDATA[ibwas]]></category>
		<category><![CDATA[portugal]]></category>

		<guid isPermaLink="false">http://webappsec.netmust.eu/2010/07/15/ibwas10-muda-de-data/</guid>
		<description><![CDATA[A 2ª Conferência Ibero-Americana em Segurança de Aplicações Web (IBero-american Web Application Security conference &#8211; IBWAS), alterou as suas datas de realização, devido ao facto de que o OWASP SUMMIT 2010, ter sido marcado para uma data que era coincidente com a IBWAS&#8217;10, impedindo assim que muitos dos membros da OWASP perdessem a oportunidade de]]></description>
			<content:encoded><![CDATA[<p style="clear: both">A 2ª Conferência Ibero-Americana em Segurança de Aplicações Web (IBero-american Web Application Security conference &#8211; <a href="http://www.ibwas.com">IBWAS</a>), alterou as suas datas de realização, devido ao facto de que o OWASP SUMMIT 2010, ter sido marcado para uma data que era coincidente com a IBWAS&#8217;10, impedindo assim que muitos dos membros da OWASP perdessem a oportunidade de estarem presentes em ambos os eventos.</p>

<p style="clear: both">Assim, optou-se por adiar a realização da conferência <a href="http://www.ibwas.com">IBWAS&#8217;10</a> por duas semanas, sendo que as novas datas são dia <strong>25 e 26 de Novembro</strong>.</p>

<p style="clear: both">Aproveito igualmente para informar que os <a href="http://www.owasp.org/index.php/IBWAS10#tab=Call_for_Papers">prazos para a submissão de artigos</a> foram igualmente estendidos.</p>

<p style="clear: both">Continuamos apostados em fazer da IBWAS&#8217;10 um excelente evento na área da segurança de informação.</p>

<p><br class="final-break" style="clear: both" /></p>
]]></content:encoded>
			<wfw:commentRss>http://webappsec.netmust.eu/2010/07/15/ibwas10-muda-de-data/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IBWAS&#8217;10 &#8211; Call for Papers</title>
		<link>http://webappsec.netmust.eu/2010/03/23/ibwas10-call-for-papers/</link>
		<comments>http://webappsec.netmust.eu/2010/03/23/ibwas10-call-for-papers/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 18:30:06 +0000</pubDate>
		<dc:creator>Carlos Serrao</dc:creator>
				<category><![CDATA[OWASP]]></category>
		<category><![CDATA[call for papers]]></category>
		<category><![CDATA[ibwas]]></category>
		<category><![CDATA[OWASP portugal]]></category>

		<guid isPermaLink="false">http://webappsec.netmust.eu/2010/03/23/ibwas10-call-for-papers/</guid>
		<description><![CDATA[Second Ibero-American Conference on Web-Applications Security (IBWAS’10) ISCTE &#8211; Lisbon University Institute 11th – 12th November 2010 Lisboa, Portugal http://www.ibwas.com [organised by OWASP Portugal and OWASP Spain] 

Introduction 

There is a change in the information systems development paradigm. The emergence of Web 2.0 technologies led to the extensive deployment and use of web-based applications and]]></description>
			<content:encoded><![CDATA[<p style="clear: both"><strong>Second Ibero-American Conference on Web-Applications Security (IBWAS’10) <br /></strong><a href="http://www.iscte.pt">ISCTE &#8211; Lisbon University Institute</a> <br />11th – 12th November 2010 <br />Lisboa, Portugal <br /><a href="http://www.ibwas.com">http://www.ibwas.com</a> <br />[organised by <a href="http://www.owasp.org/index.php/Portuguese">OWASP Portugal</a> and <a href="http://www.owasp.org/index.php/Spain">OWASP Spain</a>] </p>

<p style="clear: both"><strong>Introduction </strong></p>

<p style="clear: both">There is a change in the information systems development paradigm. The emergence of Web 2.0 technologies led to the extensive deployment and use of web-based applications and web services as a way to developed new and flexible information systems. Such systems are easy to develop, deploy and maintain and demonstrate impressive features for users, resulting in their current wide use. </p>

<p style="clear: both">As a result of this paradigm shift, the security requirements have also changed. These web-based information systems have different security requirements, when compared to traditional systems. Important security issues have been found and privacy concerns have also been raised recently. In addition, the emerging Cloud Computing paradigm promises even greater flexibility; however corresponding security and privacy issues still need to be examined. The security environment should involve not only the surrounding environment but also the application core. </p>

<p style="clear: both">This conference aims to bring together application security experts, researchers, educators and practitioners from the industry, academia and international communities such as OWASP, in order to discuss open problems and new solutions in application security. In the context of this track academic researchers will be able to combine interesting results with the experience of practitioners and software engineers. </p>

<p style="clear: both"><strong>Conference Topics </strong></p>

<p style="clear: both">Suggested topics for papers submission include (but are not limited to): </p>

<p style="clear: both"><ul style="clear: both"><li>Secure application development </li><li>Security of service oriented architectures </li><li>Security of development frameworks </li><li>Threat modelling of web applications </li><li>Cloud computing security </li><li>Web applications vulnerabilities and analysis (code review, pen-test, static analysis etc.) </li><li>Metrics for application security </li><li>Countermeasures for web application vulnerabilities </li><li>Secure coding techniques </li><li>Platform or language security features that help secure web applications </li><li>Secure database usage in web applications </li><li>Access control in web applications </li><li>Web services security </li><li>Browser security </li><li>Privacy in web applications </li><li>Standards, certifications and security evaluation criteria for web applications </li><li>Application security awareness and education </li><li>Security for the mobile web </li><li>Attacks and Vulnerability Exploitation </li><li>Paper Submission Instructions <br /></li><li>&#8230; and more.</li></ul></p>

<p style="clear: both">Authors should submit an original paper in English, carefully checked for correct grammar and spelling, using the on-line submission procedure (http://paperman.ibwas.com). Please check the paper formats so you may be aware of the accepted paper page limits (12 pages, in accordance to a supplied template). </p>

<p style="clear: both">The guidelines for paper formatting provided at the conference web site must be strictly used for all submitted papers. The submission format is the same as the camera-ready format. Please check and carefully follow the instructions and templates provided. </p>

<p style="clear: both">Each paper should clearly indicate the nature of its technical/scientific contribution, and the problems, domains or environments to which it is applicable. </p>

<p style="clear: both">Papers that are out of the conference scope or contain any form of plagiarism will be rejected without reviews. </p>

<p style="clear: both">Remarks about the on-line submission procedure: </p>

<p style="clear: both"><ol style="clear: both"><li>A &#8220;double-blind&#8221; paper evaluation method will be used. To facilitate that, the authors are kindly requested to produce and provide the paper, WITHOUT any reference to any of the authors. This means that is necessary to remove the author’s personal details, the acknowledgements section and any reference that may disclose the authors identity </li><li>Papers in ODF, PDF, DOC, DOCX or RTF format are accepted </li><li>The web submission procedure automatically sends an acknowledgement, by e-mail, to the contact author. </li></ol></p>

<p style="clear: both"><strong>Paper submission types </strong></p>

<p style="clear: both"><strong>Regular Paper Submission </strong></p>

<p style="clear: both">A regular paper presents a work where the research is completed or almost finished. It does not necessary means that the acceptance is as a full paper. It may be accepted as a &#8220;full paper&#8221; (30 min. oral presentation), a &#8220;short paper&#8221; (15 min. oral presentation) or a &#8220;poster&#8221;. </p>

<p style="clear: both"><strong>Position Paper Submission </strong></p>

<p style="clear: both">A position paper presents an arguable opinion about an issue. The goal of a position paper is to convince the audience that your opinion is valid and worth listening to, without the need to present completed research work and/or validated results. It is, nevertheless, important to support your argument with evidence to ensure the validity of your claims. A position paper may be a short report and discussion of ideas, facts, situations, methods, procedures or results of scientific research (bibliographic, experimental, theoretical, or other) focused on one of the conference topic areas. The acceptance of a position paper is restricted to the categories of &#8220;short paper&#8221; or &#8220;poster&#8221;, i.e. a position paper is not a candidate to acceptance as &#8220;full paper&#8221;. </p>

<p style="clear: both"><strong>Camera-ready </strong></p>

<p style="clear: both">After the reviewing process is completed, the contact author (the author who submits the paper) of each paper will be notified of the result, by e-mail. The authors are required to follow the reviews in order to improve their paper before the camera-ready submission. </p>

<p style="clear: both"><strong>Publications </strong></p>

<p style="clear: both">All accepted papers will be published in the conference proceedings, under an ISBN reference. Conference proceedings will be published by Springer in the Communications in Computer and Information Science (CCIS) series. </p>

<p style="clear: both"><strong>Web-site </strong></p>

<p style="clear: both"><a href="http://www.ibwas.com">http://www.ibwas.com</a> </p>

<p style="clear: both"><strong>Secretariat </strong></p>

<p style="clear: both">E-mail: secretariat@ibwas.com </p>

<p style="clear: both"><strong>Important Dates </strong></p>

<p style="clear: both">Submission of papers and all other contributions due: <strong>24th September 2010</strong> Notification of acceptance: <strong>8th October 2010</strong> <br />Camera-ready version of accepted contributions: <strong>15th October 2010</strong> <br />Conference: <strong>11th – 12th November 2010 </strong></p>

<p><br class="final-break" style="clear: both" /></p>
]]></content:encoded>
			<wfw:commentRss>http://webappsec.netmust.eu/2010/03/23/ibwas10-call-for-papers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IBWAS&#8217;10</title>
		<link>http://webappsec.netmust.eu/2010/02/26/ibwas10/</link>
		<comments>http://webappsec.netmust.eu/2010/02/26/ibwas10/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 14:17:54 +0000</pubDate>
		<dc:creator>Carlos Serrao</dc:creator>
				<category><![CDATA[Eventos]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[ibwas]]></category>
		<category><![CDATA[OWASP portugal]]></category>

		<guid isPermaLink="false">http://webappsec.netmust.eu/2010/02/26/ibwas10/</guid>
		<description><![CDATA[Aí está&#8230; oficialmente lançada a organização da IBWAS&#8217;10 (2ª Conferência Ibero-Americana de Segurança em Aplicações Web) depois da edição do ano passado, em Madrid, a IBWAS&#8217;09.

Este ano, a IBWAS&#8217;10 realiza-se em Portugal, em Lisboa, no ISCTE-IUL. Toda comunidade de segurança nacional e internacional está convidada a participar. O respectivo Call for Papers já foi igualmente]]></description>
			<content:encoded><![CDATA[<p>Aí está&#8230; oficialmente lançada a organização da <a href="http://www.ibwas.com" target="_blank">IBWAS&#8217;10</a> (2ª Conferência Ibero-Americana de Segurança em Aplicações Web) depois da edição do ano passado, em Madrid, a <a href="http://ibwas09.netmust.eu" target="_blank">IBWAS&#8217;09</a>.</p>

<p>Este ano, a IBWAS&#8217;10 realiza-se em Portugal, em Lisboa, no ISCTE-IUL. Toda comunidade de segurança nacional e internacional está convidada a participar. O respectivo <a href="http://www.owasp.org/index.php/IBWAS10#tab=Call_for_Papers" target="_blank">Call for Papers</a> já foi igualmente lançado, e a organização da IBWAS&#8217;10 agradece a sua divulgação e disseminação.</p>

<p>Mais uma vez, a comunidade local e internacional do OWASP estará reunida durante 2 dias cheios, juntamente com a comunidade académica, profissionais e empresas para debater o estado actual e futuro da segurança na Web.</p>

<p>A organização está igualmente a estabelecer um painel de keynote speakers e de panel speakers de qualidade. Mais notícias irão surgindo à medida que se justifique.</p>

<p>Estão desde já todos convidados a <a href="http://www.owasp.org/index.php/IBWAS10" target="_blank">participar</a>.</p>

<p><br class="final-break" /></p>
]]></content:encoded>
			<wfw:commentRss>http://webappsec.netmust.eu/2010/02/26/ibwas10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Newsletter OWASP Q1 2010</title>
		<link>http://webappsec.netmust.eu/2010/01/23/newsletter-owasp-q1-2010/</link>
		<comments>http://webappsec.netmust.eu/2010/01/23/newsletter-owasp-q1-2010/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 17:44:03 +0000</pubDate>
		<dc:creator>Carlos Serrao</dc:creator>
				<category><![CDATA[OWASP]]></category>
		<category><![CDATA[ibwas]]></category>
		<category><![CDATA[newsletter]]></category>
		<category><![CDATA[OWASP portugal]]></category>

		<guid isPermaLink="false">http://webappsec.netmust.eu/2010/01/23/newsletter-owasp-q1-2010/</guid>
		<description><![CDATA[Aqui fica a newsletter do OWASP do Q1 de 2010. Entre outras coisas é possível observar aqui um pouco do que foi o IBWAS09.

Podem encontrar a newsletter neste link.


]]></description>
			<content:encoded><![CDATA[<p>Aqui fica a <a href="http://www.owasp.org/images/1/13/01_18_10_OWASP_Newsletter.pdf" target="_blank">newsletter</a> do <a href="http://www.owasp.org" target="_blank">OWASP</a> do Q1 de 2010. Entre outras coisas é possível observar aqui um pouco do que foi o <a href="http://www.ibwas.com" title="" target="_blank">IBWAS09</a>.</p>

<p>Podem encontrar a newsletter neste <a href="http://www.owasp.org/images/1/13/01_18_10_OWASP_Newsletter.pdf" target="_blank">link</a>.</p>

<p><br class="final-break" /></p>
]]></content:encoded>
			<wfw:commentRss>http://webappsec.netmust.eu/2010/01/23/newsletter-owasp-q1-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IBWAS&#8217;09 &#8211; Cerimónia de Abertura e Keynote do Bruce Schneier</title>
		<link>http://webappsec.netmust.eu/2010/01/15/ibwas09-cerimonia-de-abertura-e-keynote-do-bruce-schneier/</link>
		<comments>http://webappsec.netmust.eu/2010/01/15/ibwas09-cerimonia-de-abertura-e-keynote-do-bruce-schneier/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 11:27:32 +0000</pubDate>
		<dc:creator>Carlos Serrao</dc:creator>
				<category><![CDATA[OWASP]]></category>
		<category><![CDATA[espanha]]></category>
		<category><![CDATA[Eventos]]></category>
		<category><![CDATA[ibwas]]></category>
		<category><![CDATA[keynote]]></category>
		<category><![CDATA[Madrid]]></category>
		<category><![CDATA[portugal]]></category>
		<category><![CDATA[schneier]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://webappsec.netmust.eu/2010/01/15/ibwas09-cerimonia-de-abertura-e-keynote-do-bruce-schneier/</guid>
		<description><![CDATA[Foi finalmente colocada no Youtube a cerimónia de abertura da IBWAS&#8217;09, decorreu em Madrid no passado mês de Dezembro, assim como a keynote do Bruce Schneier sobre &#8220;O Futuro da Indústria de Segurança&#8221;. Se tiverem tempo (cerca de 1h20), vale a pena ver.




]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Foi finalmente colocada no <a href="http://www.youtube.com/" target="_blank">Youtube</a> a cerimónia de abertura da <a href="http://www.ibwas.com/" target="_blank">IBWAS&#8217;09</a>, decorreu em Madrid no passado mês de Dezembro, assim como a keynote do <a href="http://www.schneier.com/" target="_blank">Bruce Schneier</a> sobre &#8220;O Futuro da Indústria de Segurança&#8221;. Se tiverem tempo (cerca de 1h20), vale a pena ver.</p>

<p style="clear: both"><span style=" text-align: center; display: block; margin: 0 auto 10px;"><object height="295" width="480"><param name="movie" value="http://www.youtube.com/v/xFbET4aQHAA&#038;hl=en_US&#038;fs=1&#038;" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed src="http://www.youtube.com/v/xFbET4aQHAA&#038;hl=en_US&#038;fs=1&#038;" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="295" width="480"></embed></object></span></p>

<p><br class="final-break" style="clear: both" /></p>
]]></content:encoded>
			<wfw:commentRss>http://webappsec.netmust.eu/2010/01/15/ibwas09-cerimonia-de-abertura-e-keynote-do-bruce-schneier/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IBWAS&#8217;09 terminou&#8230; viva a IBWAS&#8217;10</title>
		<link>http://webappsec.netmust.eu/2009/12/29/ibwas09-terminou-viva-a-ibwas10/</link>
		<comments>http://webappsec.netmust.eu/2009/12/29/ibwas09-terminou-viva-a-ibwas10/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 23:23:49 +0000</pubDate>
		<dc:creator>Carlos Serrao</dc:creator>
				<category><![CDATA[OWASP]]></category>
		<category><![CDATA[ibwas]]></category>
		<category><![CDATA[portugal]]></category>

		<guid isPermaLink="false">http://webappsec.netmust.eu/2009/12/29/ibwas09-terminou-viva-a-ibwas10/</guid>
		<description><![CDATA[No início do mês de Dezembro realizou-se em Madrid a primeira edição da Conferência Ibérica em Segurança de Aplicações Web (IBWAS&#8217;09). A organização partiu de uma iniciativa conjunta entre o capítulo português e espanhol da OWASP. 

A conferência contou com a presença de um alargado número de researchers e de participantes da indústria, a IBWAS&#8217;09]]></description>
			<content:encoded><![CDATA[<p style="clear: both">No início do mês de Dezembro realizou-se em Madrid a primeira edição da Conferência Ibérica em Segurança de Aplicações Web (<a href="http://www.ibwas.com" target="_blank">IBWAS&#8217;09</a>). A organização partiu de uma iniciativa conjunta entre o capítulo <a href="http://www.owasp.org/index.php/Portuguese" target="_blank">português</a> e <a href="http://www.owasp.org/index.php/Spain" target="_blank">espanhol</a> da <a href="http://www.owasp.org" target="_blank">OWASP</a>. </p>

<p style="clear: both">A conferência contou com a presença de um alargado número de researchers e de participantes da indústria, a IBWAS&#8217;09 foi um sucesso! </p>

<p style="clear: both">A IBWAS&#8217;09 teve a presença de um conjunto de speakers de qualidade (nos quais se destaca a presença de Bruce Schneier, um dos maiores gurus mundiais em Segurança de Informação), que se organizaram em diversos painéis de científicos, de indústria e de keynotes. </p>

<p style="clear: both">No final da conferência foi ainda organizado um painel de discussão em que foram elaboradas um conjunto de <a href="http://webappsec.netmust.eu/2009/12/17/owasp-lanca-desafio-a-governos/" target="_blank">recomendações</a> a adoptar pelos governos mundiais em 2010. </p>

<p style="clear: both">Para o ano há mais&#8230; e já se prepara a IBWAS&#8217;10. A não perder. </p>

<p><br class="final-break" style="clear: both" /></p>
]]></content:encoded>
			<wfw:commentRss>http://webappsec.netmust.eu/2009/12/29/ibwas09-terminou-viva-a-ibwas10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP lança desafio a Governos</title>
		<link>http://webappsec.netmust.eu/2009/12/17/owasp-lanca-desafio-a-governos/</link>
		<comments>http://webappsec.netmust.eu/2009/12/17/owasp-lanca-desafio-a-governos/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 18:58:26 +0000</pubDate>
		<dc:creator>Carlos Serrao</dc:creator>
				<category><![CDATA[OWASP]]></category>
		<category><![CDATA[ibwas]]></category>
		<category><![CDATA[OWASP portugal]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://webappsec.netmust.eu/2009/12/17/owasp-lanca-desafio-a-governos/</guid>
		<description><![CDATA[Na última IBWAS&#8217;09, realizou-se um painel que debateu quais os aspectos relacionados com a segurança de informação (em particular da segurança de aplicações web) que deveriam estar na agenda dos diversos Governos para 2010.

Deste painel surgiu um conjunto de recomendações que se resumem no seguinte comunicado de imprensa emitido hoje pela OWASP, e o qual]]></description>
			<content:encoded><![CDATA[<p style="clear: both">Na última <a href="http://www.ibwas.com" target="_blank">IBWAS&#8217;09</a>, realizou-se um painel que debateu quais os aspectos relacionados com a segurança de informação (em particular da segurança de aplicações web) que deveriam estar na agenda dos diversos Governos para 2010.</p>

<p style="clear: both">Deste painel surgiu um conjunto de recomendações que se resumem no seguinte comunicado de imprensa emitido hoje pela <a href="http://www.owasp.org" target="_blank">OWASP</a>, e o qual se reproduz de seguida de forma integral.</p>

<p style="clear: both"><strong>IBWAS’09</strong><br /><em>Iberic Web Application Security Conference</em> </p>

<p style="clear: both"><strong>Comunicado de Imprensa</strong><br /><strong>A OWASP desafia Governos a melhorar segurança das aplicações <em>Web</em></strong> </p>

<p style="clear: both">Cerca de 40 participantes e dezenas de estudantes de tecnologia e os seus professores estiveram presentes na Conferência Ibérica de Segurança em Aplicações <em>Web</em> (<em>Iberic Web Application Security</em>, IBWAS&#8217;09) realizada a 10 e 11 de Dezembro último na <em>Escuela Universitaria de Ingeniería Técnica de Telecomunicación</em>, <em>Universidad Politécnica de Madrid</em>, Espanha. </p>

<p style="clear: both">Esta conferência, tendo sido organizada pelas delegações regionais de Espanha e Portugal da<em>Open Web Application Security Project</em> (OWASP) <em>Foundation</em>, juntou especialistas, investigadores e indústria com o intuito de discutir problemas e soluções associados à Segurança das Aplicações Informáticas que funcionam na Internet. </p>

<p style="clear: both">Através de uma intensa e bem sucedida discussão mantida no painel <strong>Segurança nas Aplicações<em>Web</em>: o que devem fazer os governos nacionais em 2010?</strong> várias conclusões foram tiradas. </p>

<p style="clear: both">Estas conclusões reflectem as decisões assumidas pelo painel e serão debatidas e actualizadas antes de serem publicadas pela OWASP sob a forma de um corpo de recomendações. </p>

<p style="clear: both"><strong>Conclusões do Painel:</strong></p>

<p style="clear: both"><ol style="clear: both"><li>Desafiamos os Governos a trabalhar com a OWASP no sentido de aumentar a transparência na segurança de aplicações web, particularmente no que respeita aos sistemas financeiros, de saúde e todos os outros onde as questões da privacidade e confidencialidade da informação são cruciais; </li><li>A OWASP procurará colaborar com os Governos mundiais no sentido de desenvolver recomendações para a incorporação de requisitos específicos de segurança nas aplicações e desenhar procedimentos de certificação adequados à selecção e aquisição governamental de software; </li><li>A OWASP oferecerá a sua assistência para clarificar e modernizar as leis de segurança informática, por forma a contribuir para que os Governos, cidadãos e organizações possam tomar decisões informadas sobre segurança; </li><li>A OWASP pedirá aos Governos que encorajem as empresas na criação de standards de segurança de aplicações que, quando utilizados, aumentarão a protecção contra quebras de segurança que podem potencialmente expor informação confidencial e permitir transacções fraudulentas gerando, assim, consequentes responsabilidades legais; </li><li>A OWASP estará disponível para trabalhar com os Governos regionais e nacionais no sentido de criar instrumentos de escrutínio e de suporte das decisões de investimento na área da segurança informática. </li></ol></p>

<p style="clear: both">Tal como anunciado previamente, os participantes da Conferência incluíram os seguintes <em>keynote</em> e<em>panel speakers</em>: </p>

<p style="clear: both"><strong><em>Keynote:</em></strong> </p>

<ul style="clear: both"><li><strong>Bruce Schneier</strong> — especialista de prestígio internacional e autor, descrito pela Economist como um <em>security guru</em>, é conhecido pela imparcialidade e lucidez dos seus comentários nas questões de segurança <em>web</em>.</li><li><strong>Jorge Martin</strong> — inspector do <em>Cuerpo Nacional de Policía</em> da Espanha e Chefe do Grupo de Segurança Lógica da Unidade de Crimes Tecnológicos da <em>Comisaria General de Policía Judicial</em>.</li></ul>

<p style="clear: both"><strong><em>Panel:</em></strong> </p>

<ul style="clear: both"><li><strong>Justin Clarke</strong> — <a href="http://www.ibwas.com/files/presentations/Justin_Clarke_IBWAS-SQLInjection.pdf"><em>SQL Injection how far does the rabbit hole go?</em></a></li><li><strong>Dinis Cruz</strong> — OWASP 3.0 — <em>Where are we going?</em> e <em>OWASP 02 Platform-Open Platform for automating application security knowledge and workflows</em>.</li><li><strong>Luis Corrons</strong> — <a href="http://www.ibwas.com/files/presentations/Luis_Corrons_IBWAS09.pdf"><em>Growth and complexity of the underground cybercrime economy</em></a>.</li><li><strong>Marc Chisinevski</strong> — <a href="http://www.ibwas.com/files/presentations/Marc_Chisinevski_IBWAS09_Presentation_Logging.pdf"><em>The OWASP Logging Project</em></a>.</li><li><strong>Simon Roses</strong> — <a href="http://www.ibwas.com/files/presentations/Simon_Roses_MS_INFOSEC_IBWAS09.pdf"><em>Microsoft Infosec Team: Security Tools Roadmap</em></a>.</li><li><strong>Dave Harper</strong> — <a href="http://www.ibwas.com/files/presentations/David_Harper_Empirical_Software_Security_Assurance_IBWAS09.pdf"><em>Empirical Software Security Assurance</em></a>.</li><li><strong>Raul Siles</strong> — <a href="http://www.ibwas.com/files/presentations/Raul_Siles_Samurai-WTF_IBWAS09_Dec09.pdf"><em>Assessing and Exploiting Web Applications with the open-source Samurai Web Testing Framework</em></a>.</li><li><strong>Miguel Almeida</strong> — <a href="http://www.ibwas.com/files/presentations/Miguel_Almeida_IBWAS09_Authentication_20091210.pdf"><em>Authentication: choosing a method that fits</em></a>.</li><li><strong>Daniele Catteddu</strong> — <em>Cloud Computing: Benefits, risks and recommendations for information security</em>.</li><li><strong>Fabio E Cerullo</strong> — <a href="http://www.ibwas.com/files/presentations/Fabio_Cerullo_OWASP_Top_10_2010_IBWAS09.pdf"><em>OWASP TOP 10 2010</em></a>.</li><li><strong>Martin Knobloch</strong> — <em>Threat Modelling</em>.</li><li><strong>Paulo Querido</strong> — <em>What Security in a Liquid Web?</em>.</li></ul>

<p style="clear: both"><strong>IBWAS ’09 — Endereços <em>Web</em>:</strong><br /><a href="http://www.owasp.org/index.php/OWASP_AppSec_Iberia_2009">http://www.owasp.org/index.php/OWASP_AppSec_Iberia_2009</a><br /><a href="http://www.ibwas.com/">http://www.ibwas.com</a> </p>

<p style="clear: both"><strong>Sobre a OWASP (<em>Open Web Application Security Project Foundation</em>):</strong><br /><a href="http://www.owasp.org/">http://www.owasp.org</a><br />Sendo em termos legais uma Fundação regida pelo direito dos Estados Unidos da América, a OWASP é uma organização internacional, não lucrativa, com uma forte cultura <em>open-source</em>, que tem por missão promover a segurança do <em>software</em> e das aplicações informáticas que funcionam na Internet. </p>

<p style="clear: both"><strong>Contactos</strong></p>

<ul style="clear: both"><li>Vicente Aguilera, OWASP <em>Spain Chapter Leader</em>, <a href="mailto:vicente.aguilera@owasp.org">vicente.aguilera@owasp.org</a></li><li>Carlos Serrão, OWASP <em>Portuguese Chapter Leader</em>, <a href="mailto:carlos.j.serrao@gmail.com">carlos.j.serrao@gmail.com</a></li><li>Fabio Cerullo, OWASP <em>Global Education Committee</em>, <a href="mailto:fcerullo@owasp.org">fcerullo@owasp.org</a></li></ul>

<p style="clear: both"></p>

<p><br class="final-break" style="clear: both" /></p>
]]></content:encoded>
			<wfw:commentRss>http://webappsec.netmust.eu/2009/12/17/owasp-lanca-desafio-a-governos/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

