<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Glenn Leifheit</title>
	<atom:link href="http://glennleifheit.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://glennleifheit.com</link>
	<description>A Secure Software Excursion</description>
	<lastBuildDate>Fri, 07 May 2010 05:30:31 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Secure Software Development Lifecycle</title>
		<link>http://glennleifheit.com/?p=19</link>
		<comments>http://glennleifheit.com/?p=19#comments</comments>
		<pubDate>Fri, 07 May 2010 05:30:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://glennleifheit.com/?p=19</guid>
		<description><![CDATA[I had the opportunity to speak at TechFuse this week here in the Twin Cities.&#160; Many thanks to the organizers and sponsors of the event.&#160; I presented on The Secure Software Development Lifecycle, a journey to secure software, here are the resources I promised.&#160; 
&#160;
Resources:
Presentation&#160;
Microsoft’s SDL Site
OWASP
SANS
SANS Internet Storm Center
TechMasters
]]></description>
			<content:encoded><![CDATA[<p>I had the opportunity to speak at <a href="http://www.benchmarklearning.com/Event/techfuse/sessions.aspx">TechFuse</a> this week here in the Twin Cities.&#160; Many thanks to the organizers and sponsors of the event.&#160; I presented on The Secure Software Development Lifecycle, a journey to secure software, here are the resources I promised.&#160; </p>
<p>&#160;</p>
<p>Resources:</p>
<p><a href="SecureSoftwareDevelopmentLifecycleTechFuse.pptx">Presentation</a>&#160;</p>
<p><a href="http://www.microsoft.com/security/sdl/default.aspx">Microsoft’s SDL Site</a></p>
<p><a href="http://owasp.org">OWASP</a></p>
<p><a href="http://www.sans.org/">SANS</a></p>
<p><a href="http://isc.sans.org">SANS Internet Storm Center</a></p>
<p><a href="http://Techmasters-tc.com">TechMasters</a></p>
]]></content:encoded>
			<wfw:commentRss>http://glennleifheit.com/?feed=rss2&amp;p=19</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Iowa Code Camp, a round up</title>
		<link>http://glennleifheit.com/?p=16</link>
		<comments>http://glennleifheit.com/?p=16#comments</comments>
		<pubDate>Mon, 03 May 2010 05:03:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Code Camp]]></category>
		<category><![CDATA[Fortify 360]]></category>
		<category><![CDATA[Iowa]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Twin Cities]]></category>

		<guid isPermaLink="false">http://glennleifheit.com/?p=16</guid>
		<description><![CDATA[I had a blast at the Iowa Code Camp this last weekend.  Here is a roundup of the presentations I saw:
 
Arrays, Collections and Hash tables &#8212; Oh My! &#8212; Jon VonGillern 
As usual Jon had an interesting twist to what could be a long presentation.  Other than not having the use of a whiteboard this [...]]]></description>
			<content:encoded><![CDATA[<p>I had a blast at the Iowa Code Camp this last weekend.  Here is a roundup of the presentations I saw:</p>
<p> </p>
<p><strong>Arrays, Collections and Hash tables &#8212; Oh My! &#8212; Jon VonGillern </strong></p>
<p>As usual Jon had an interesting twist to what could be a long presentation.  Other than not having the use of a whiteboard this presentation went well.  We learned quite a bit and the demos went well.</p>
<p> </p>
<p><strong>Kanban to Cash: Stolen Ideas Make a Beautiful Process &#8212; Lee Brandt</strong></p>
<p>This was a very informative discussion on lean development, especially focusing on Kanban.  Kanban is based on a Toyota manufacturing process, and modified for software development.  Lee did a great job with this and I recommend seeing this next time Lee presents it, especially if you lead your software methodology at work. </p>
<p> </p>
<p><strong>Intro to WordPress&#8217; architecture and plug-in/theme development &#8212; Kenny Younger &amp; Andy Brudtkuhl</strong></p>
<p>This was a great intro to WordPress development.  They covered a lot of information very quickly, and gave us some great resources to look at.</p>
<p> </p>
<p><strong>I need to secure my code, now what? – Glenn Leifheit</strong></p>
<p>See my previous <a href="http://glennleifheit.com/?p=15">blog post</a></p>
<p> </p>
<p><strong>Being a Technology Entrepreneur – Scott Davis</strong></p>
<p>This was a fantastic presentation by Scott, to a nearly packed house.  He gave great ideas, resources and a great overall discussion on being a technology entrepreneur.</p>
<p> </p>
<p>All in all it was a great event, even with both the Chicago Code Camp and Iowa Code Camp on the same day.  As a speaker I would also like to thank everyone who came to my session as well.  I look forward to seeing everyone in the fall!</p>
]]></content:encoded>
			<wfw:commentRss>http://glennleifheit.com/?feed=rss2&amp;p=16</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>I need to secure my code, now what?</title>
		<link>http://glennleifheit.com/?p=15</link>
		<comments>http://glennleifheit.com/?p=15#comments</comments>
		<pubDate>Mon, 03 May 2010 04:29:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://glennleifheit.com/?p=15</guid>
		<description><![CDATA[When your suddenly asked to “make your code secure, right now”, you need to know where to go.&#160;&#160; This presentation is designed to inform the developers, architects and others where to go to find informative resources in secure development. This was last given at the Twin Cities Code Camp and the Iowa Code Camp during [...]]]></description>
			<content:encoded><![CDATA[<p>When your suddenly asked to “make your code secure, right now”, you need to know where to go.&#160;&#160; This presentation is designed to inform the developers, architects and others where to go to find informative resources in secure development. This was last given at the Twin Cities Code Camp and the Iowa Code Camp during April/May 2010.</p>
<p>&#160;</p>
<h6></h6>
<h3>Additional Resources:</h3>
<ul>
<li><a href="http://www.glennleifheit.com/attachments/ineedtosecuremycode.pptx">Slide Deck</a></li>
<li><a href="http://www.owasp.org">OWASP</a></li>
<ul>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_Guide_Project">OWASP Developers Guide</a></li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project">OWASP Top 10</a></li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project">OWASP Code Review Guide</a></li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project">WebGoat</a></li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project">WebScarab</a></li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project">OWASP Application Vulnerability Standards Project</a></li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API">Enterprise Security API (ESAPI)</a></li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_Chapter#Starting_a_Chapter">Starting an OWSAP Chapter</a></li>
</ul>
<li><a href="http://www.sans.org/">SANS</a></li>
<li><a href="http://isc.sans.org/">SANS Internet Security Center</a> </li>
<li><a href="http://www.fortify.com/security-resources/">Fortify Resources portal</a></li>
<li><a href="http://www.microsoft.com/security/sdl/default.aspx">Microsoft Secure Development Lifecyle</a></li>
<li><a href="http://www.secure360.org/">Secure 360</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://glennleifheit.com/?feed=rss2&amp;p=15</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>New OWASP Top 10 Release Candidate Released for 2010!</title>
		<link>http://glennleifheit.com/?p=14</link>
		<comments>http://glennleifheit.com/?p=14#comments</comments>
		<pubDate>Mon, 16 Nov 2009 05:57:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://glennleifheit.com/?p=14</guid>
		<description><![CDATA[OWASP Released a new version of their OWASP Top 10 in a Release Candidate has been released, just in time for 2010.&#160; A copy of this can be found here.&#160;&#160; OWASP releases a Top 10 list periodically of the tem most critical web application security risks.&#160; There were two new entries:

Security Misconfiguration was added at [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.owasp.org/">OWASP</a> Released a new version of their OWASP Top 10 in a Release Candidate has been released, just in time for 2010.&#160; A copy of this can be found <a href="http://www.owasp.org/index.php/File:OWASP_T10_-_2010_rc1.pdf">here</a>.&#160;&#160; OWASP releases a Top 10 list periodically of the tem most critical web application security risks.&#160; There were two new entries:</p>
<ul>
<li>Security Misconfiguration was added at #6 </li>
<li>Unvalidated Redirects and Forwards at #8 </li>
</ul>
<p>&#160;</p>
<p>Removed were:</p>
<ul>
<li>Malicious File Execution – Still a problem but appears to be under control more then the other 10. </li>
<li>Information Leakage and Improper Error Handling – Also appears to be under some control compared to the rest of the top 10. </li>
</ul>
<p>NOTE:&#160; Just because Malicious File Execution and Information Leakage and Improper Error Handling have been removed from the top 10 does not mean that they are not important to take care of.&#160; It just means they are more understood now and happen much less then they did in 2007.</p>
<p>For more information on the <a href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project">OWASP top 10</a> visit <a href="http://www.owasp.org">OWASP</a> at <a href="http://www.owasp.org">http://www.owasp.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://glennleifheit.com/?feed=rss2&amp;p=14</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where should you start with web security</title>
		<link>http://glennleifheit.com/?p=12</link>
		<comments>http://glennleifheit.com/?p=12#comments</comments>
		<pubDate>Mon, 16 Nov 2009 05:15:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://glennleifheit.com/?p=12</guid>
		<description><![CDATA[When I first started looking into security within web applications years ago there really was no resource that you could take advantage of.  This has now changed with OWASP.  Their mission is to make application security visible, so that people can make informed decisions.  OWASP is a 5013c organization using mostly volunteers.  They have over [...]]]></description>
			<content:encoded><![CDATA[<p>When I first started looking into security within web applications years ago there really was no resource that you could take advantage of.  This has now changed with <a href="http://www.owasp.org">OWASP</a>.  Their mission is to make application security visible, so that people can make informed decisions.  OWASP is a 5013c organization using mostly volunteers.  They have over <a href="http://www.owasp.org/index.php/Category:OWASP_Chapter">130 local chapters worldwide</a> that hold meetings to discuss application security, some chapters hold conferences as well.  They have over 100 projects in many stages, all carrying the goal of improving application security.  OWASP also creates a large number of tools and guides to encourage building applications more securely.  The <a href="http://www.owasp.org/index.php/Category:OWASP_Guide_Project">OWASP Development Guide</a>, and the <a href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project">OWASP top ten</a> are essential reading for developers.  Other projects such as OWASP’s <a href="http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API">Enterprise Security API (ESAPI)</a> and <a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project">WebGoat</a> are also essential tools in web security.  I will be posting articles that talk about each of their projects over the next few months.  I encourage you to check out your local <a href="http://www.owasp.org/index.php/Category:OWASP_Chapter">OWASP Chapter</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://glennleifheit.com/?feed=rss2&amp;p=12</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Welcome</title>
		<link>http://glennleifheit.com/?p=9</link>
		<comments>http://glennleifheit.com/?p=9#comments</comments>
		<pubDate>Mon, 28 Sep 2009 01:01:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://glennleifheit.com/?p=9</guid>
		<description><![CDATA[Welcome to GlennLeifheit.com I will be posting information and discussions on information security, software security, and other miscellaneous Technology topics.&#160; Enjoy!
]]></description>
			<content:encoded><![CDATA[<p>Welcome to GlennLeifheit.com I will be posting information and discussions on information security, software security, and other miscellaneous Technology topics.&#160; Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://glennleifheit.com/?feed=rss2&amp;p=9</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
