<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>R&#38;D &#187; Security</title>
	<atom:link href="http://blog.adnanmasood.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.adnanmasood.com</link>
	<description>Adnan on Technology, Research &#38; Development</description>
	<lastBuildDate>Thu, 17 May 2012 15:39:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>CloudCamp LA 2012, CQRS and NoSQL</title>
		<link>http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/</link>
		<comments>http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 14:20:23 +0000</pubDate>
		<dc:creator>Adnan Masood</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.adnanmasood.com/?p=846</guid>
		<description><![CDATA[Cloud camp LA happened couple of weeks ago at the coresite campus in downtown LA. The highlights of the evening were Dave Nielsen&#8217;s intro, Lynn Langit&#8217;s NOSQL session, Bret Statham&#8216;s CQRS (Command Query Responsibility Segregation) talk and coresite&#8217;s datacenter tour. Slides from Bret&#8217;s lightning talk can be downloaded here. NoSQL for the SQL Server DBA View more [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.adnanmasood.com/2012/04/11/cloudcamp-in-la-wed-april-11th/" target="_blank">Cloud camp LA</a> happened couple of weeks ago at the coresite campus in downtown LA. The highlights of the evening were Dave Nielsen&#8217;s intro, Lynn Langit&#8217;s NOSQL session, <a href="http://bretstateham.com/">Bret Statham</a>&#8216;s <a href="http://martinfowler.com/bliki/CQRS.html" target="_blank">CQRS </a>(Command Query Responsibility Segregation) talk and coresite&#8217;s datacenter tour.</p>
<p><a href="http://bretstateham.com/downloads/CQRSCloudApplicationArchitecture120411.zip" target="_blank">Slides from Bret&#8217;s lightning talk can be downloaded here</a>.</p>
<p><a href="http://bretstateham.com/downloads/CQRSCloudApplicationArchitecture120411.zip"><img class="aligncenter size-medium wp-image-889" title="CQRS-Cloud-Application-Architecture-Screen-Shot" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/CQRS-Cloud-Application-Architecture-Screen-Shot-300x225.png" alt="" width="300" height="225" /></a></p>
<p><strong style="display: block; margin: 12px 0 4px;"><a title="NoSQL for the SQL Server DBA" href="http://www.slideshare.net/lynnlangit/nosql-for-the-sql-server-dba" target="_blank">NoSQL for the SQL Server DBA</a></strong></p>
<div id="__ss_12124895" style="width: 425px;"><iframe src="http://www.slideshare.net/slideshow/embed_code/12124895" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" width="425" height="355"></iframe></p>
<div style="padding: 5px 0 12px;">View more <a href="http://www.slideshare.net/thecroaker/death-by-powerpoint" target="_blank">PowerPoint</a> from <a href="http://www.slideshare.net/lynnlangit" target="_blank">Lynn Langit</a></div>
</div>
<p>I have attended cloudcamps organized by <a href="https://twitter.com/#!/davenielsen" target="_blank">Dave Nielsen</a> in the past but this particular event wasn&#8217;t as organized as the one at Microsoft campus couple of years ago (and through no fault of his own). Dave is a Co-Founder of CloudCamp and author of the book PayPal Hacks. The event started late and hence the unconference style sessions and panels were cut short and disrupted. Lots of echo so it was hard to hear and topics which came out of un-conference discussion weren&#8217;t quite diverse and well organized even for an unconference. However, the data center tour was fun!</p>
<p>and a much nicer write-up by morphlaps on CloudCamp LA – <a href="http://www.morphlabs.com/blog/cloudcamp-la-why-open-source-and-openstack-matters-to-the-enterprise/" target="_blank">Why Open Source (and OpenStack) Matters To the Enterprise</a></p>
<p>I get to meet Jason Woloz who is heading up the <a href="http://www.meetup.com/LASC-CSA/" target="_blank">Cloud security alliance LA chapter</a>. The <a href="http://www.meetup.com/LASC-CSA/events/61819422/" target="_blank">first meetup</a> is coming soon. <a href="http://www.meetup.com/LASC-CSA/">http://www.meetup.com/LASC-CSA/</a></p>
<p>&nbsp;</p>
<p><a href="http://blog.adnanmasood.com/2012/04/11/cloudcamp-in-la-wed-april-11th/" target="_blank">
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image/' title='image'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image-150x150.jpg" class="attachment-thumbnail" alt="image" title="image" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_1/' title='image_1'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_1-150x150.jpg" class="attachment-thumbnail" alt="image_1" title="image_1" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_2/' title='image_2'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_2-150x150.jpg" class="attachment-thumbnail" alt="image_2" title="image_2" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_3/' title='image_3'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_3-150x150.jpg" class="attachment-thumbnail" alt="image_3" title="image_3" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_4/' title='image_4'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_4-150x150.jpg" class="attachment-thumbnail" alt="image_4" title="image_4" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_5/' title='image_5'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_5-150x150.jpg" class="attachment-thumbnail" alt="image_5" title="image_5" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_6/' title='image_6'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_6-150x150.jpg" class="attachment-thumbnail" alt="image_6" title="image_6" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_7/' title='image_7'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_7-150x150.jpg" class="attachment-thumbnail" alt="image_7" title="image_7" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_8/' title='image_8'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_8-150x150.jpg" class="attachment-thumbnail" alt="image_8" title="image_8" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_9/' title='image_9'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_9-150x150.jpg" class="attachment-thumbnail" alt="image_9" title="image_9" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_10/' title='image_10'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_10-150x150.jpg" class="attachment-thumbnail" alt="image_10" title="image_10" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_11/' title='image_11'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_11-150x150.jpg" class="attachment-thumbnail" alt="image_11" title="image_11" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_12/' title='image_12'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_12-150x150.jpg" class="attachment-thumbnail" alt="image_12" title="image_12" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_13/' title='image_13'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_13-150x150.jpg" class="attachment-thumbnail" alt="image_13" title="image_13" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_14/' title='image_14'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_14-150x150.jpg" class="attachment-thumbnail" alt="image_14" title="image_14" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_15/' title='image_15'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_15-150x150.jpg" class="attachment-thumbnail" alt="image_15" title="image_15" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_17/' title='image_17'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_17-150x150.jpg" class="attachment-thumbnail" alt="image_17" title="image_17" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_18/' title='image_18'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_18-150x150.jpg" class="attachment-thumbnail" alt="image_18" title="image_18" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_19/' title='image_19'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_19-150x150.jpg" class="attachment-thumbnail" alt="image_19" title="image_19" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/image_20/' title='image_20'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/image_20-150x150.jpg" class="attachment-thumbnail" alt="image_20" title="image_20" /></a>
<a href='http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/cqrs-cloud-application-architecture-screen-shot/' title='CQRS-Cloud-Application-Architecture-Screen-Shot'><img width="150" height="150" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/CQRS-Cloud-Application-Architecture-Screen-Shot-150x150.png" class="attachment-thumbnail" alt="CQRS-Cloud-Application-Architecture-Screen-Shot" title="CQRS-Cloud-Application-Architecture-Screen-Shot" /></a>
</p>
<p></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>References:</p>
<ul>
<li><a title="Permalink to New 1-day Class ‘NoSQL for the SQL Server Pro’" href="http://lynnlangit.wordpress.com/2012/04/23/new-1-day-class-nosql-for-the-sql-server-pro/" rel="bookmark">New 1-day Class ‘NoSQL for the SQL Server Pro’</a> - Lynn Langit</li>
<li><a href="http://brets.me/bterkalycqrsp1" target="_blank">Bruno Terkaly on CQRS</a></li>
<li><a href="https://cloudsecurityalliance.org/" target="_blank">Cloud Security Alliance</a></li>
<li><a href="http://brets.me/gycqrs100216" target="_blank">Greg Young on what CQRS is and isn’t</a></li>
<li><a href="http://brets.me/mfcqrs01" target="_blank">Martin Fowler’s overview of CQRS</a></li>
<li><a href="http://brets.me/udcqrs01" target="_blank">Udi Dahan’s CQRS clarification</a></li>
</ul>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.adnanmasood.com%2F2012%2F04%2F24%2Fcloudcamp-la-2012-cqrs-and-nosql%2F&amp;title=CloudCamp%20LA%202012%2C%20CQRS%20and%20NoSQL" id="wpa2a_2"><img src="http://blog.adnanmasood.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.adnanmasood.com/2012/04/24/cloudcamp-la-2012-cqrs-and-nosql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>On Panel @ OWASP LA Security Summit: April 25, 2012, 3:00PM &#8211; 8PM</title>
		<link>http://blog.adnanmasood.com/2012/04/23/on-panel-owasp-la-security-summit-april-25-2012-300pm-8pm/</link>
		<comments>http://blog.adnanmasood.com/2012/04/23/on-panel-owasp-la-security-summit-april-25-2012-300pm-8pm/#comments</comments>
		<pubDate>Mon, 23 Apr 2012 14:34:01 +0000</pubDate>
		<dc:creator>Adnan Masood</dc:creator>
				<category><![CDATA[Enterprise Architecture]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.adnanmasood.com/?p=848</guid>
		<description><![CDATA[This Wednesday April 25th, I will be part of a panel at the OWASP LA Security Summit where Jerry Hoff VP, Static Code Analysis Division at WhiteHat Security, will be speaking about Webgoat. Shakeel Tufail, Federal Practice Director for HP Enterprise Security Solutions, will be speaking on &#8220;Software (In)Security &#8211; Challenges to securing software&#8221;. Noa Bar Yosef, Senior [...]]]></description>
			<content:encoded><![CDATA[<p>This Wednesday April 25th, I will be part of a panel at the <a href="https://www.owasp.org/index.php/Los_Angeles" target="_blank">OWASP LA</a> Security Summit where Jerry Hoff VP, Static Code Analysis Division at WhiteHat Security, will be speaking about Webgoat. Shakeel Tufail, Federal Practice Director for HP Enterprise Security Solutions, will be speaking on <em>&#8220;Software (In)Security &#8211; Challenges to securing software&#8221;</em>. <a href="http://www.securityweek.com/authors/noa-bar-yosef" target="_blank">Noa Bar Yosef</a>, Senior Security Strategist at Imperva, will be speaking on <em>&#8220;De-Anonymizing Anonymous&#8221;</em>. A concluding panel, moderated by Richard Greenberg, Information Security Officer for LA County Public Health, will have the speakers and myself discussing different aspects of <em>De-Anonymizing Anonymous. </em></p>
<p><em></em>The focus of the panel is upon Recruitment and communication i.e. how Anonymous leverages social networks to recruit its members and pick a target, application attack i.e sequence the steps Anonymous hackers deploy to take data and bring down websites, DDoS i.e. the DDoS techniques deployed to take down websites and finally the key mitigation steps that organizations need to take if they ever become a target.</p>
<p><strong>Location:</strong></p>
<p><strong>Four Points by Sheraton Los Angeles<br />
</strong>5990 Green Valley Cir<br />
Culver City, CA 90230<br />
(310) 641-7740<br />
RSVP at <a href="http://www.meetup.com/OWASP-Los-Angeles/" rel="nofollow">http://www.meetup.com/OWASP-Los-Angeles/</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.adnanmasood.com%2F2012%2F04%2F23%2Fon-panel-owasp-la-security-summit-april-25-2012-300pm-8pm%2F&amp;title=On%20Panel%20%40%20OWASP%20LA%20Security%20Summit%3A%20April%2025%2C%202012%2C%203%3A00PM%20%26%238211%3B%208PM" id="wpa2a_4"><img src="http://blog.adnanmasood.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.adnanmasood.com/2012/04/23/on-panel-owasp-la-security-summit-april-25-2012-300pm-8pm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The evolution of malware and the threat landscape &#8211; a decade in overview</title>
		<link>http://blog.adnanmasood.com/2012/04/01/the-evolution-of-malware-and-the-threat-landscape-a-decade-in-overview/</link>
		<comments>http://blog.adnanmasood.com/2012/04/01/the-evolution-of-malware-and-the-threat-landscape-a-decade-in-overview/#comments</comments>
		<pubDate>Sun, 01 Apr 2012 18:17:26 +0000</pubDate>
		<dc:creator>Adnan Masood</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.adnanmasood.com/?p=787</guid>
		<description><![CDATA[Microsoft Security Intelligence Report provides summarized information from the last 10 years focusing on software vulnerabilities, software vulnerability exploits, malicious, and potentially unwanted software. The report discusses the origin of malware following it through the decade of mutation all the way upto cloud. However, the report does not cover specific threats to cloud in detail [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft Security Intelligence Report provides summarized information from the last 10 years focusing on software vulnerabilities, software vulnerability exploits, malicious, and potentially unwanted software. The report discusses the origin of malware following it through the decade of mutation all the way upto cloud. However, the report does not cover specific threats to cloud in detail at this point.</p>
<p><a href="http://www.microsoft.com/download/en/details.aspx?id=29046" target="_blank"><img class="aligncenter size-medium wp-image-801" title="Malware and portentially unwanted software families" src="http://blog.adnanmasood.com/wp-content/uploads/2012/04/Malware-and-portentially-unwanted-software-families-300x185.png" alt="" width="300" height="185" /></a></p>
<p>Brief introductions to threat families ranging from Win32/Nimda to Win32/Bagle, Win32/Conficker, JS/Pornpop(of specially crafted JavaScript-enabled objects that attempt to display pop-under advertisements) and Win32/OpenCandy are provided. This report makes a good executive summary of software threats and trends they follow. It can be <a href="http://www.microsoft.com/download/en/details.aspx?id=29046" target="_blank">downloaded from here.</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.adnanmasood.com%2F2012%2F04%2F01%2Fthe-evolution-of-malware-and-the-threat-landscape-a-decade-in-overview%2F&amp;title=The%20evolution%20of%20malware%20and%20the%20threat%20landscape%20%26%238211%3B%20a%20decade%20in%20overview" id="wpa2a_6"><img src="http://blog.adnanmasood.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.adnanmasood.com/2012/04/01/the-evolution-of-malware-and-the-threat-landscape-a-decade-in-overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Resources &#8211; talk @ 10th Annual SecureIT conference</title>
		<link>http://blog.adnanmasood.com/2012/03/21/resources-talk-10th-annual-secureit-conference/</link>
		<comments>http://blog.adnanmasood.com/2012/03/21/resources-talk-10th-annual-secureit-conference/#comments</comments>
		<pubDate>Wed, 21 Mar 2012 19:30:50 +0000</pubDate>
		<dc:creator>Adnan Masood</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Speaking]]></category>

		<guid isPermaLink="false">http://blog.adnanmasood.com/?p=796</guid>
		<description><![CDATA[Following are the resources from my and Tin Zaw&#8216;s talk @ 10th Annual SecureIT conference- “Practical Web Application Security and OWASP Top 10 implementation on Microsoft Platform” OWASP Top 10 Presentation AppSec Tutorial Videos OWASP Cheat Sheets ASP.NET MVC Best Practices Microsoft Partners in Learning OWASP 2010 Top 10 Cheat Sheet Free eBook: OWASP Top [...]]]></description>
			<content:encoded><![CDATA[<p>Following are the resources from my and <a href="https://twitter.com/#!/tzaw" target="_blank">Tin Zaw</a>&#8216;s talk @ <a href="http://blog.adnanmasood.com/2012/03/05/speaking-10th-annual-secureit-conference-practical-web-application-security-and-owasp-top-10-implementation-on-microsoft-platform/" target="_blank">10th Annual SecureIT conference- “Practical Web Application Security and OWASP Top 10 implementation on Microsoft Platform”</a></p>
<ul>
<li><a href="http://owasptop10.googlecode.com/files/OWASP_Top_10_-_2010%20Presentation.pptx" target="_blank">OWASP Top 10 Presentation</a></li>
<li><a href="http://www.youtube.com/user/AppsecTutorialSeries" target="_blank">AppSec Tutorial Videos</a></li>
<li><a href="http://www.youtube.com/user/AppsecTutorialSeries" target="_blank">OWASP Cheat Sheets</a></li>
<li><a href="http://blogs.msdn.com/b/aspnetue/archive/2010/09/17/second_2d00_post.aspx" target="_blank">ASP.NET MVC Best Practices</a></li>
<li><a href="http://www.pil-network.com/" target="_blank">Microsoft Partners in Learning</a></li>
<li><a href="http://www.greebo.net/owasp/OWASP%202010%20Top%2010%20Cheat%20Sheet.pdf" target="_blank">OWASP 2010 Top 10 Cheat Sheet</a></li>
<li><a href="http://www.troyhunt.com/2011/12/free-ebook-owasp-top-10-for-net.html" target="_blank">Free eBook: OWASP Top 10 for .NET developers</a></li>
<li><a href="http://www.troyhunt.com/search/label/OWASP" target="_blank">Troy Hunt (MVP) OWASP Related posts</a></li>
<li><a href="http://weblogs.asp.net/dixin/archive/2010/05/22/anti-forgery-request-recipes-for-asp-net-mvc-and-ajax.aspx" target="_blank">Anti-Forgery Request Recipes For ASP.NET MVC And AJAX</a></li>
<li><a href="http://www.microsoft.com/security/sdl/adopt/tools.aspx" target="_blank">Microsoft Security Development Lifecycle</a></li>
<li><a href="http://msdn.microsoft.com/en-us/library/system.web.mvc.authorizeattribute.aspx" target="_blank">Authorize Attribute</a></li>
<li><a href="https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project" target="_blank">OWASP Webgoat Project</a></li>
<li><a href="http://blog.andreloker.de/post/2008/06/16/Keep-your-config-clean-with-external-config-files.aspx" target="_blank">Keep your .config clean with external config files</a></li>
<li><a href="http://stackoverflow.com/questions/4074199/jquery-ajax-calls-and-the-html-antiforgerytoken" target="_blank">jQuery Ajax calls and the Html.AntiForgeryToken()</a></li>
<li><a href="http://security.stackexchange.com/questions/8744/does-asp-net-viewstate-implicitly-prevent-csrf-attacks-what-does-this-mean-for" target="_blank">Does ASP.NET Viewstate implicitly prevent CSRF attacks? What does this mean for MVC?</a></li>
<li><a href="http://blog.slaks.net/2012/01/protecting-against-csrf-attacks-in.html" target="_blank">Protecting against CSRF attacks in ASP.Net MVC</a></li>
<li><a href="http://haacked.com/archive/2009/04/02/anatomy-of-csrf-attack.aspx" target="_blank">Anatomy of a Cross-site Request Forgery Attack</a></li>
<li><a href="https://github.com/adnanmasood/webgoat.mvc" target="_blank">webgoat.mvc</a> (<a href="https://github.com/kahanu/webgoat.mvc" target="_blank">kahanu fork</a> - complete)</li>
<li><a href="http://weblogs.asp.net/srkirkland/archive/2010/04/14/guarding-against-csrf-attacks-in-asp-net-mvc2.aspx" target="_blank">Step by Step improvement in Guarding against CSRF in MVC</a></li>
</ul>
<p>&nbsp;</p>
<p>Happy Secure Coding!</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.adnanmasood.com%2F2012%2F03%2F21%2Fresources-talk-10th-annual-secureit-conference%2F&amp;title=Resources%20%26%238211%3B%20talk%20%40%2010th%20Annual%20SecureIT%20conference" id="wpa2a_8"><img src="http://blog.adnanmasood.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.adnanmasood.com/2012/03/21/resources-talk-10th-annual-secureit-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Speaking @ 10th Annual SecureIT conference- “Practical Web Application Security and OWASP Top 10 implementation on Microsoft Platform”</title>
		<link>http://blog.adnanmasood.com/2012/03/05/speaking-10th-annual-secureit-conference-practical-web-application-security-and-owasp-top-10-implementation-on-microsoft-platform/</link>
		<comments>http://blog.adnanmasood.com/2012/03/05/speaking-10th-annual-secureit-conference-practical-web-application-security-and-owasp-top-10-implementation-on-microsoft-platform/#comments</comments>
		<pubDate>Tue, 06 Mar 2012 03:23:30 +0000</pubDate>
		<dc:creator>Adnan Masood</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Speaking]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.adnanmasood.com/?p=773</guid>
		<description><![CDATA[On March 18th, I will be speaking at the 10th Annual SecureIT conference in a workshop titled “Practical Web Application Security and OWASP Top 10 implementation on Microsoft Platform”. This is a joint session with Tin Zaw, chapter leader and president of OWASP LA. Here is the abstract. Practical Web Application Security and OWASP Top [...]]]></description>
			<content:encoded><![CDATA[<p>On March 18th, I will be speaking at the 10th Annual SecureIT conference in a <a href="http://secureitconf.com/agenda.asp" target="_blank">workshop </a>titled “Practical Web Application Security and OWASP Top 10 implementation on Microsoft Platform”. This is a joint session with Tin Zaw, chapter leader and president of <a href="https://www.owasp.org/index.php/Los_Angeles" target="_blank">OWASP LA</a>.</p>
<p><a href="http://secureitconf.com/agenda.asp" target="_blank"><br />
<img class="aligncenter" title="SecureIT_Web_banner_2012" src="http://blog.adnanmasood.com/wp-content/uploads/2012/03/SecureIT_Web_banner_2012-300x68.jpg" alt="" width="300" height="68" /></a></p>
<p>Here is the abstract.</p>
<p><a href="http://secureitconf.com/agenda.asp" target="_blank">Practical Web Application Security and OWASP Top 10 implementation on Microsoft Platform</a></p>
<p>Presenters: Adnan Masood, Tin Zaw</p>
<p>This session is a hands-on introduction to the web application security threats using the OWASP top 10 list of potential security flaws. The OWASP Top Ten provides a powerful awareness list for web application security and represents a broad consensus about what the most critical web application security flaws are.</p>
<p>Focusing on Microsoft platform with examples in ASP.NETand ASP.NETMVC, we will go over some of the common exploits and techniques for writing secure code in the light of OWASP top 10. In this code centric talk, we will discuss built in security features ofASP.NET and MVC such as cross site request forgery token and secure cookies and how to leverage them to write secure code. The OWASP Top 10 Web Application Security Risks for 2010 which will be covered in this presentation include Injection flaws, Cross-Site Scripting (XSS), Broken Authentication and Session Management, Insecure Direct Object References, Cross-Site Request Forgery (CSRF),Security Misconfiguration, Insecure Cryptographic Storage, Failure to Restrict URL Access, Insufficient Transport Layer Protection and Unvalidated Redirects and Forwards.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.adnanmasood.com%2F2012%2F03%2F05%2Fspeaking-10th-annual-secureit-conference-practical-web-application-security-and-owasp-top-10-implementation-on-microsoft-platform%2F&amp;title=Speaking%20%40%2010th%20Annual%20SecureIT%20conference-%20%E2%80%9CPractical%20Web%20Application%20Security%20and%20OWASP%20Top%2010%20implementation%20on%20Microsoft%20Platform%E2%80%9D" id="wpa2a_10"><img src="http://blog.adnanmasood.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.adnanmasood.com/2012/03/05/speaking-10th-annual-secureit-conference-practical-web-application-security-and-owasp-top-10-implementation-on-microsoft-platform/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Speaking @ UCLA &#8211; LA.NET UG Tonight &#8211; Practical Web Application Security &#8211; A Primer with OWASP Top 10 and ASP.NET/MVC</title>
		<link>http://blog.adnanmasood.com/2010/11/01/speaking-ucla-la-net-ug-tonight-practical-web-application-security-a-primer-with-owasp-top-10-and-asp-netmvc/</link>
		<comments>http://blog.adnanmasood.com/2010/11/01/speaking-ucla-la-net-ug-tonight-practical-web-application-security-a-primer-with-owasp-top-10-and-asp-netmvc/#comments</comments>
		<pubDate>Tue, 02 Nov 2010 00:37:34 +0000</pubDate>
		<dc:creator>Adnan Masood</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.adnanmasood.com/?p=526</guid>
		<description><![CDATA[Tonight I&#8217;ll be speaking at LA .NET Users Group on Practical Web Application Security &#8211; A Primer with OWASP Top 10 and ASP.NET/MVC This session is a developer&#8217;s introduction to the web application security threats using the OWASP top 10 list of potential security flaws. With examples in ASP.NET and ASP.NET MVC, we will go [...]]]></description>
			<content:encoded><![CDATA[<div id="_mcePaste"></div>
<div>Tonight I&#8217;ll be speaking at LA .NET Users Group on Practical Web Application Security &#8211; A Primer with OWASP Top 10 and ASP.NET/MVC</div>
<div></div>
<div id="_mcePaste">This session is a developer&#8217;s introduction to the web application security threats using the OWASP top 10 list of potential security flaws. With examples in ASP.NET and ASP.NET MVC, we will go over some of the common exploits and techniques for writing secure code in the light of OWASP top 10.</div>
<div id="_mcePaste"></div>
<div>The OWASP Top Ten provides a powerful awareness list for web application security and represents a broad consensus about what the most critical web application security flaws are. In this code centric talk, we will discuss built in security features of ASP.NET and MVC such as cross site request forgery token and secure cookies and how to leverage them to write secure code. The OWASP Top 10 Web Application Security Risks for 2010 which will be covered in this presentation include Injection flaws, Cross-Site Scripting (XSS), Broken Authentication and Session Management, Insecure Direct Object References, Cross-Site Request Forgery (CSRF),Security Misconfiguration, Insecure Cryptographic Storage, Failure to Restrict URL Access, Insufficient Transport Layer Protection and Unvalidated Redirects and Forwards.</div>
<div id="_mcePaste"></div>
<div>For details and directions to the meeting, please visit http://ladotnet.org/default.asp</div>
<div id="_mcePaste">The talk is based on my OWASP Top 10 project on codeplex.</div>
<div id="_mcePaste"></div>
<div>When: Monday, November 01, 2010, 6:30 PM to 9:30 PM</div>
<div id="_mcePaste">Where: UCLA campus, Center for Health Sciences Room 53-105. * Print our rint our <a href="http://www.ladotnet.org/directions_printer_friendly.asp" target="_blank">directions page</a> and bring it with you.</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.adnanmasood.com%2F2010%2F11%2F01%2Fspeaking-ucla-la-net-ug-tonight-practical-web-application-security-a-primer-with-owasp-top-10-and-asp-netmvc%2F&amp;title=Speaking%20%40%20UCLA%20%26%238211%3B%20LA.NET%20UG%20Tonight%20%26%238211%3B%20Practical%20Web%20Application%20Security%20%26%238211%3B%20A%20Primer%20with%20OWASP%20Top%2010%20and%20ASP.NET%2FMVC" id="wpa2a_12"><img src="http://blog.adnanmasood.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.adnanmasood.com/2010/11/01/speaking-ucla-la-net-ug-tonight-practical-web-application-security-a-primer-with-owasp-top-10-and-asp-netmvc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AppSec 2010 Conference</title>
		<link>http://blog.adnanmasood.com/2010/08/10/appsec-conference-2010/</link>
		<comments>http://blog.adnanmasood.com/2010/08/10/appsec-conference-2010/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 07:23:35 +0000</pubDate>
		<dc:creator>Adnan Masood</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.adnanmasood.com/?p=500</guid>
		<description><![CDATA[AppSec USA 2010 is the premier web application security conference of the year. From IT decision makers and managers to security conscious developers and engineers, AppSec USA will provide answers to a wide variety of questions on application security. Online registration is open till September 3. We have 5 keynote speakers, 2 panel discussions, 6 [...]]]></description>
			<content:encoded><![CDATA[<p>AppSec USA 2010 is the premier web application security conference of the year. From IT decision makers and managers to security conscious developers and engineers, AppSec USA will provide answers to a wide variety of questions on application security.</p>
<p><a href="http://appsecUSA.org/reg" target="_blank"><img class="aligncenter size-full wp-image-501" title="AppSec 2010 Conference" src="http://blog.adnanmasood.com/wp-content/uploads/2010/08/appSecUSA2010.jpg" alt="AppSec 2010 Conference" width="619" height="145" /></a></p>
<p>Online registration is open till September 3. We have 5 keynote speakers, 2 panel discussions, 6 training classes and 20 plus high quality presentations.</p>
<p>Website: <a href="http://www.appsecUSA.org" target="_blank">http://www.appsecUSA.org</a><br />
URL to register is <a href="http://appsecUSA.org/reg" target="_blank">http://appsecUSA.org/reg</a><br />
Agenda: <a href="http://www.appsecUSA.org/agenda" target="_blank">http://www.appsecUSA.org/agenda</a></p>
<p><a href="http://www.appsecusa.org/volunteer-opportunities.html" target="_blank">Volunteer opportunities</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.adnanmasood.com%2F2010%2F08%2F10%2Fappsec-conference-2010%2F&amp;title=AppSec%202010%20Conference" id="wpa2a_14"><img src="http://blog.adnanmasood.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.adnanmasood.com/2010/08/10/appsec-conference-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Step by Step Guide for Authenticating WCF Service with Username and Password over SSL</title>
		<link>http://blog.adnanmasood.com/2010/04/29/step-by-step-guide-for-authenticating-wcf-service-with-username-and-password-over-ssl/</link>
		<comments>http://blog.adnanmasood.com/2010/04/29/step-by-step-guide-for-authenticating-wcf-service-with-username-and-password-over-ssl/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 14:42:57 +0000</pubDate>
		<dc:creator>Adnan Masood</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Research & Development]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Services]]></category>

		<guid isPermaLink="false">http://blog.adnanmasood.com/?p=423</guid>
		<description><![CDATA[Here is a short step by step guide on how to get your WCF service to perform Message and Transport level security over SSL with user name and password. I ran into this recently and thought should document it along with source code to provide reference for the rest of us. 1. If your development [...]]]></description>
			<content:encoded><![CDATA[<p>Here is a short step by step guide on how to get your WCF service to perform Message and Transport level security over SSL with user name and password. I ran into this recently and thought should document it along with source code to provide reference for the rest of us.</p>
<p>1. If your development machine is XP (or 2K3 server) and you need dev SSL cert installed on it, follow the instructions mentioned in the articles here. The SelfSSL makes it real easy to do self signed certificates, literally one  statement.</p>
<p><a href="http://www.visualwin.com/SelfSSL/" target="_self">Setting up SSL with a SelfSSL certificate on Windows Server 2003 (and XP)</a></p>
<p><a href="http://www.somacon.com/p42.php" target="_blank">Create a self-signed SSL certificate with IIS 6.0 Resource Kit SelfSSL</a></p>
<p>2. Create a WCF Service Project. Name the service and contracts appropriately. In my sample it is a simple contract like follows.</p>
<pre class="brush: csharp;" lang="C#">   [ServiceContract]
    public interface IWcfService
    {
        [OperationContract]
        string GetData(int value);
    }</pre>
<p>Make sure you make the appropriate config changes matching with your service contract.</p>
<p>2. Add a custom validator class in your service. You can create a separate file for it. In this example I have added it to the main service file WcfService.svc.cs. You are going to need to add the reference (not just adding these lines at the top, go to add-reference and add the corresponding dll&#8217;s to the project)</p>
<pre>using System.IdentityModel.Selectors;
using System.IdentityModel.Tokens;</pre>
<p>and the custom validator code.</p>
<pre class="brush: csharp;" lang="C#">public class CustomValidator : UserNamePasswordValidator
    {
        public override void Validate(string userName, string password)
        {
            if (userName == "test" &amp;&amp; password == "test")
                return;
            throw new SecurityTokenException(
                "Unknown Username or Password");
        }
    }</pre>
<p>You probably want to make this user name and password moved to a more secure location or point to your database/authentication store for security and maintainability perspective.</p>
<p>3. Now the code part is done. Move to config file. Enable custom errors so you know details about the errors happening.</p>
<p>&lt;customErrors mode=&#8221;Off&#8221; defaultRedirect=&#8221;GenericErrorPage.htm&#8221;&gt;</p>
<p>4. Add a new bindings attribute in the config called SafeServiceConf which will specify the TransportWithMessageCredential type of security. You can add this right before &lt;/system.serviceModel&gt;</p>
<pre class="brush: csharp;" lang="C#">
&lt;bindings&gt;
&lt;wsHttpBinding&gt;
&lt;binding name="SafeServiceConf" maxReceivedMessageSize="65536"&gt;
&lt;readerQuotas maxStringContentLength="65536" maxArrayLength="65536"
maxBytesPerRead="65536" /&gt;
&lt;security mode="TransportWithMessageCredential"&gt;
&lt;message clientCredentialType="UserName" /&gt;
&lt;/security&gt;
&lt;/binding&gt;
&lt;/wsHttpBinding&gt;
&lt;/bindings&gt;
&lt;bindings&gt;       &lt;wsHttpBinding&gt;          &lt;binding name="SafeServiceConf" maxReceivedMessageSize="65536"&gt;             &lt;readerQuotas maxStringContentLength="65536" maxArrayLength="65536"                maxBytesPerRead="65536" /&gt;             &lt;security mode="TransportWithMessageCredential"&gt;                &lt;message clientCredentialType="UserName" /&gt;             &lt;/security&gt;          &lt;/binding&gt;       &lt;/wsHttpBinding&gt;    &lt;/bindings&gt;</pre>
<p>5. Modify your end point address to refer to this binding configuration</p>
<pre class="brush: csharp;" lang="C#">			&lt;endpoint address="" binding="wsHttpBinding" contract="MySamples.IWcfService" bindingConfiguration="SafeServiceConf"&gt;</pre>
<p>also modify your metadata exchange endpoint to use mexHttpsBinding</p>
<pre class="brush: csharp;" lang="C#">				&lt;endpoint address="mex" binding="mexHttpsBinding" contract="IMetadataExchange"/&gt;</pre>
<p>6. Modify your service behavior to look like this</p>
<pre class="brush: csharp;" lang="C#">				&lt;behavior name="WcfService.Service1Behavior"&gt;
					&lt;serviceMetadata httpGetEnabled="true"/&gt;
          &lt;serviceDebug includeExceptionDetailInFaults="true" /&gt;
          &lt;serviceCredentials&gt;
            &lt;userNameAuthentication
                 userNamePasswordValidationMode="Custom"
                 customUserNamePasswordValidatorType="MySamples.CustomValidator,WcfService"
                                                                          /&gt;

          &lt;/serviceCredentials&gt;
        &lt;/behavior&gt;</pre>
<p>It&#8217;s recommended that &#8220;Include exception in faults&#8221; should be disabled when moved to production.</p>
<p>7. Now you are almost ready to run the service however before you do this, make sure that you are running it in the IIS AND you have the SSL enabled on the server as specified in step 1 otherwise you&#8217;ll run into WCF error stating that there is no HTTPS endpoint available.</p>
<div id="attachment_424" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.adnanmasood.com/wp-content/uploads/2010/04/setupVD.jpg"><img class="size-medium wp-image-424" title="Setup Virtual Directory IIS from Visual Studio" src="http://blog.adnanmasood.com/wp-content/uploads/2010/04/setupVD-300x258.jpg" alt="Setup Virtual Directory in IIS from Visual Studio" width="300" height="258" /></a><p class="wp-caption-text">Setup Virtual Directory in IIS from Visual Studio</p></div>
<p>You should be able to run and see the service end point as follows.</p>
<div id="attachment_431" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.adnanmasood.com/wp-content/uploads/2010/04/running-service-1.jpg"><img class="size-medium wp-image-431" title="Running WCF Service over SSL" src="http://blog.adnanmasood.com/wp-content/uploads/2010/04/running-service-1-300x214.jpg" alt="Running WCF Service over SSL" width="300" height="214" /></a><p class="wp-caption-text">Running WCF Service over SSL</p></div>
<div id="attachment_432" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.adnanmasood.com/wp-content/uploads/2010/04/running-service-2.jpg"><img class="size-medium wp-image-432" title="Running WCF Service over SSL 2" src="http://blog.adnanmasood.com/wp-content/uploads/2010/04/running-service-2-300x189.jpg" alt="Running WCF Service over SSL 2" width="300" height="189" /></a><p class="wp-caption-text">Running WCF Service over SSL 2</p></div>
<p>8. Now that the service is done, let&#8217;s move towards building the client. Add the service reference to the service end point. You can do it either via entering the entire URL or using the discover feature.</p>
<div id="attachment_428" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.adnanmasood.com/wp-content/uploads/2010/04/addWCFReference2.jpg"><img class="size-medium wp-image-428" title="Add WCF Reference" src="http://blog.adnanmasood.com/wp-content/uploads/2010/04/addWCFReference2-300x237.jpg" alt="Add WCF Reference" width="300" height="237" /></a><p class="wp-caption-text">Add WCF Reference</p></div>
<p>9. Name your reference &#8220;Client&#8221; or modify your code appropriately. Following is the code for client implementation.</p>
<pre class="brush: csharp;" lang="C#">       private static void Main(string[] args)
        {
           ServicePointManager.ServerCertificateValidationCallback = new RemoteCertificateValidationCallback(
                delegate { return true; });

            var client = new WcfServiceClient();
            GetCredentials();
            client.ClientCredentials.UserName.UserName = username;
            client.ClientCredentials.UserName.Password = password;
            Console.Write(client.GetData(1));
            client.Close();
            Console.Read();
        }</pre>
<p>The  RemoteCertificateValidationCallback part is used to programatically avoid the following warning which would popup due to self signed cert usage.</p>
<div id="attachment_429" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.adnanmasood.com/wp-content/uploads/2010/04/certwarning.jpg"><img class="size-medium wp-image-429" title="Certificate Warning" src="http://blog.adnanmasood.com/wp-content/uploads/2010/04/certwarning-300x231.jpg" alt="Certificate Warning" width="300" height="231" /></a><p class="wp-caption-text">Self signed Certificate Warning</p></div>
<p>10. Now run the program.</p>
<div id="attachment_430" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.adnanmasood.com/wp-content/uploads/2010/04/running-WCF-client.jpg"><img class="size-medium wp-image-430" title="Running WCF client" src="http://blog.adnanmasood.com/wp-content/uploads/2010/04/running-WCF-client-300x173.jpg" alt="Running WCF client" width="300" height="173" /></a><p class="wp-caption-text">Running WCF client</p></div>
<p>You can see that for the right credentials, service will run just fine. Otherwise a security exception will be thrown.</p>
<p>Source code can be downloaded from here.<a href="http://blog.adnanmasood.com/wp-content/uploads/2010/04/WCFAuthSample.zip">WCFAuthSample</a></p>
<p>Feel free to drop me an email or comment here if you have any questions.</p>
<p><strong>References and Further Readings:</strong></p>
<p><a href="http://msdn.microsoft.com/en-us/library/ms733131.aspx">How to: Authenticate with a User Name and Password</a></p>
<p><a href="http://www.codeproject.com/KB/WCF/wcf_https_usernameauth.aspx">WCF Service over HTTPS with custom username and password validator in IIS</a></p>
<p><a href="http://wcfsecurityguide.codeplex.com/wikipage?title=Ch%2005%20-%20Authentication,%20Authorization%20and%20Identities%20in%20WCF&amp;ProjectName=wcfsecurityguide">Chapter 5 – Authentication, Authorization and Identities in WCF</a></p>
<p><a href="http://msdn.microsoft.com/en-us/library/ms789011.aspx">How to: Use Transport Security and Message Credentials</a></p>
<p><a href="http://msdn.microsoft.com/en-us/library/system.servicemodel.securitymode.aspx">SecurityMode Enumeration</a></p>
<p><a href="http://www.thejoyofcode.com/WCF_Could_not_establish_trust_relationship_for_the_SSL_TLS_secure_channel_with_authority.aspx">WCF: Could not establish trust relationship for the SSL/TLS secure channel with authority</a></p>
<p><a href="http://msdn.microsoft.com/en-us/library/aa751792.aspx">Deploying an Internet Information Services-Hosted WCF Service</a></p>
<p><a href="http://social.msdn.microsoft.com/Forums/en/wcf/thread/308dcb5a-34c0-415b-a7d3-3ec9d142849a">How messages are encrypted when security mode is &#8220;Message&#8221;?<br />
</a></p>
<p><a href="http://www.codeproject.com/kb/wcf/senthil.aspx">Simple WCF &#8211; X509 Certificate</a></p>
<p><a href="http://www.microsoft.com/downloads/en/confirmation.aspx?familyId=c42e27ac-3409-40e9-8667-c748e422833f&amp;displayLang=en">Windows HTTP Services Certificate Configuration Tool (WinHttpCertCfg.exe)</a></p>
<p><a href="http://www.visualwin.com/SelfSSL/">Setting up SSL with a SelfSSL certificate on Windows Server 2003 (and XP)</a></p>
<p><a href="http://www.somacon.com/p42.php">Create a self-signed SSL certificate with IIS 6.0 Resource Kit SelfSSL</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.adnanmasood.com%2F2010%2F04%2F29%2Fstep-by-step-guide-for-authenticating-wcf-service-with-username-and-password-over-ssl%2F&amp;title=Step%20by%20Step%20Guide%20for%20Authenticating%20WCF%20Service%20with%20Username%20and%20Password%20over%20SSL" id="wpa2a_16"><img src="http://blog.adnanmasood.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.adnanmasood.com/2010/04/29/step-by-step-guide-for-authenticating-wcf-service-with-username-and-password-over-ssl/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP Top 10 FINAL 2010 &#8211; Web Application Security Risks</title>
		<link>http://blog.adnanmasood.com/2010/04/19/owasp-top-10-final-2010-web-application-security-risks/</link>
		<comments>http://blog.adnanmasood.com/2010/04/19/owasp-top-10-final-2010-web-application-security-risks/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 07:29:23 +0000</pubDate>
		<dc:creator>Adnan Masood</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.adnanmasood.com/?p=408</guid>
		<description><![CDATA[OWASP Top 10 Web Application Security Risks 2010 has been released today 4/19 as FINAL. The OWASP Top 10 Web Application Security Risks for 2010 are: A1: Injection A2: Cross-Site Scripting (XSS) A3: Broken Authentication and Session Management A4: Insecure Direct Object References A5: Cross-Site Request Forgery (CSRF) A6: Security Misconfiguration A7: Insecure Cryptographic Storage [...]]]></description>
			<content:encoded><![CDATA[<p>OWASP Top 10 Web Application Security Risks 2010 has been released today 4/19 as FINAL.</p>
<p>The OWASP Top 10 Web Application Security Risks for 2010 are:</p>
<ul>
<li>A1: Injection</li>
<li>A2: Cross-Site Scripting (XSS)</li>
<li>A3: Broken Authentication and Session Management</li>
<li>A4: Insecure Direct Object References</li>
<li>A5: Cross-Site Request Forgery (CSRF)</li>
<li>A6: Security Misconfiguration</li>
<li>A7: Insecure Cryptographic Storage</li>
<li>A8: Failure to Restrict URL Access</li>
<li>A9: Insufficient Transport Layer Protection</li>
<li>A10: Unvalidated Redirects and Forwards</li>
</ul>
<p><a title="http://www.owasp.org/images/4/44/OWASP_Top_10_-_2010.pdf" rel="nofollow" href="http://www.owasp.org/images/4/44/OWASP_Top_10_-_2010.pdf">Click here to download the OWASP Top 10 &#8211; 2010</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.adnanmasood.com%2F2010%2F04%2F19%2Fowasp-top-10-final-2010-web-application-security-risks%2F&amp;title=OWASP%20Top%2010%20FINAL%202010%20%26%238211%3B%20Web%20Application%20Security%20Risks" id="wpa2a_18"><img src="http://blog.adnanmasood.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.adnanmasood.com/2010/04/19/owasp-top-10-final-2010-web-application-security-risks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OWASP Top 10 and Data Mining in Financial Sector</title>
		<link>http://blog.adnanmasood.com/2008/07/21/owasp-top-10-and-data-mining-in-financial-sector/</link>
		<comments>http://blog.adnanmasood.com/2008/07/21/owasp-top-10-and-data-mining-in-financial-sector/#comments</comments>
		<pubDate>Mon, 21 Jul 2008 05:50:26 +0000</pubDate>
		<dc:creator>Adnan Masood</dc:creator>
				<category><![CDATA[Generic]]></category>
		<category><![CDATA[Research & Development]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.adnanmasood.com/PermaLink.aspx?guid=1fc6f501-cfc9-4daf-a4bc-db44d00ec130</guid>
		<description><![CDATA[OWASP’s list have been changed since 2004 in terms of priorities; XSS and inject flaws are on the rise. Details can be found on OWASP’s website. 2007 2004 A1 &#8211; Cross Site Scripting (XSS) A1 - Unvalidated Input A2 &#8211; Injection Flaws A2 &#8211; Broken Access Control A3 &#8211; Malicious File Execution A3 &#8211; Broken [...]]]></description>
			<content:encoded><![CDATA[<style type="text/css">
<!--
.style1 {font-family: Arial, Helvetica, sans-serif;
	font-size: small;}
-->
</style>
<p class="style1"> <font color="#000000"><b>OWASP’s list have been changed since 2004 in terms of priorities; XSS  and inject flaws are on the rise. Details can be found on</b> </font><a href="http://www.owasp.org/">OWASP’s website</a>.</p>
<p><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="ProgId" content="Word.Document"><meta name="Generator" content="Microsoft Word 12"><meta name="Originator" content="Microsoft Word 12">
<link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CADNAN%7E1.MAS%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml">
<link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CADNAN%7E1.MAS%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx">
<link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CADNAN%7E1.MAS%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"><!--[if gte mso 9]><xml><br />
 <w:WordDocument><br />
  <w:View>Normal</w:View><br />
  <w:Zoom>0</w:Zoom><br />
  <w:TrackMoves/><br />
  <w:TrackFormatting/><br />
  <w:PunctuationKerning/><br />
  <w:ValidateAgainstSchemas/><br />
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid><br />
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent><br />
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText><br />
  <w:DoNotPromoteQF/><br />
  <w:LidThemeOther>EN-US</w:LidThemeOther><br />
  <w:LidThemeAsian>X-NONE</w:LidThemeAsian><br />
  <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript><br />
  <w:Compatibility><br />
   <w:BreakWrappedTables/><br />
   <w:SnapToGridInCell/><br />
   <w:WrapTextWithPunct/><br />
   <w:UseAsianBreakRules/><br />
   <w:DontGrowAutofit/><br />
   <w:SplitPgBreakAndParaMark/><br />
   <w:DontVertAlignCellWithSp/><br />
   <w:DontBreakConstrainedForcedTables/><br />
   <w:DontVertAlignInTxbx/><br />
   <w:Word11KerningPairs/><br />
   <w:CachedColBalance/><br />
  </w:Compatibility><br />
  <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel><br />
  <m:mathPr><br />
   <m:mathFont m:val="Cambria Math"/><br />
   <m:brkBin m:val="before"/><br />
   <m:brkBinSub m:val="--"/><br />
   <m:smallFrac m:val="off"/><br />
   <m:dispDef/><br />
   <m:lMargin m:val="0"/><br />
   <m:rMargin m:val="0"/><br />
   <m:defJc m:val="centerGroup"/><br />
   <m:wrapIndent m:val="1440"/><br />
   <m:intLim m:val="subSup"/><br />
   <m:naryLim m:val="undOvr"/><br />
  </m:mathPr></w:WordDocument><br />
</xml><![endif]--><!--[if gte mso 9]><xml><br />
 <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"<br />
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"<br />
  LatentStyleCount="267"><br />
  <w:LsdException Locked="false" Priority="0" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/><br />
  <w:LsdException Locked="false" Priority="9" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/><br />
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/><br />
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/><br />
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/><br />
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/><br />
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/><br />
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/><br />
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/><br />
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/><br />
  <w:LsdException Locked="false" Priority="39" Name="toc 1"/><br />
  <w:LsdException Locked="false" Priority="39" Name="toc 2"/><br />
  <w:LsdException Locked="false" Priority="39" Name="toc 3"/><br />
  <w:LsdException Locked="false" Priority="39" Name="toc 4"/><br />
  <w:LsdException Locked="false" Priority="39" Name="toc 5"/><br />
  <w:LsdException Locked="false" Priority="39" Name="toc 6"/><br />
  <w:LsdException Locked="false" Priority="39" Name="toc 7"/><br />
  <w:LsdException Locked="false" Priority="39" Name="toc 8"/><br />
  <w:LsdException Locked="false" Priority="39" Name="toc 9"/><br />
  <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/><br />
  <w:LsdException Locked="false" Priority="10" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Title"/><br />
  <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/><br />
  <w:LsdException Locked="false" Priority="11" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/><br />
  <w:LsdException Locked="false" Priority="22" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/><br />
  <w:LsdException Locked="false" Priority="20" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/><br />
  <w:LsdException Locked="false" Priority="59" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Table Grid"/><br />
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/><br />
  <w:LsdException Locked="false" Priority="1" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/><br />
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Shading"/><br />
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light List"/><br />
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Grid"/><br />
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 1"/><br />
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 2"/><br />
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 1"/><br />
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 2"/><br />
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 1"/><br />
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 2"/><br />
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 3"/><br />
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Dark List"/><br />
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Shading"/><br />
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful List"/><br />
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Grid"/><br />
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/><br />
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light List Accent 1"/><br />
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/><br />
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/><br />
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/><br />
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/><br />
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/><br />
  <w:LsdException Locked="false" Priority="34" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/><br />
  <w:LsdException Locked="false" Priority="29" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/><br />
  <w:LsdException Locked="false" Priority="30" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/><br />
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/><br />
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/><br />
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/><br />
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/><br />
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Dark List Accent 1"/><br />
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/><br />
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/><br />
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/><br />
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/><br />
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light List Accent 2"/><br />
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/><br />
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/><br />
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/><br />
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/><br />
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/><br />
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/><br />
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/><br />
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/><br />
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Dark List Accent 2"/><br />
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/><br />
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/><br />
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/><br />
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/><br />
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light List Accent 3"/><br />
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/><br />
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/><br />
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/><br />
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/><br />
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/><br />
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/><br />
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/><br />
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/><br />
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Dark List Accent 3"/><br />
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/><br />
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/><br />
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/><br />
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/><br />
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light List Accent 4"/><br />
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/><br />
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/><br />
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/><br />
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/><br />
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/><br />
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/><br />
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/><br />
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/><br />
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Dark List Accent 4"/><br />
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/><br />
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/><br />
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/><br />
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/><br />
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light List Accent 5"/><br />
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/><br />
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/><br />
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/><br />
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/><br />
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/><br />
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/><br />
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/><br />
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/><br />
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Dark List Accent 5"/><br />
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/><br />
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/><br />
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/><br />
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/><br />
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light List Accent 6"/><br />
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/><br />
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/><br />
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/><br />
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/><br />
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/><br />
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/><br />
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/><br />
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/><br />
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Dark List Accent 6"/><br />
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/><br />
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/><br />
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"<br />
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/><br />
  <w:LsdException Locked="false" Priority="19" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/><br />
  <w:LsdException Locked="false" Priority="21" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/><br />
  <w:LsdException Locked="false" Priority="31" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/><br />
  <w:LsdException Locked="false" Priority="32" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/><br />
  <w:LsdException Locked="false" Priority="33" SemiHidden="false"<br />
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/><br />
  <w:LsdException Locked="false" Priority="37" Name="Bibliography"/><br />
  <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/><br />
 </w:LatentStyles><br />
</xml><![endif]--><br />
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:roman;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1107304683 0 0 159 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1073750139 0 0 159 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:"";
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.0pt;
	margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
.MsoChpDefault
	{mso-style-type:export-only;
	mso-default-props:yes;
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
.MsoPapDefault
	{mso-style-type:export-only;
	margin-bottom:10.0pt;
	line-height:115%;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
-->
</style>
<p><!--[if gte mso 10]></p>
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin-top:0in;
	mso-para-margin-right:0in;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
</style>
<p><![endif]--></p>
<table class="MsoNormalTable" style="border: medium none ; margin-left: -3.9pt; border-collapse: collapse;" border="1" cellpadding="0" cellspacing="0">
<tbody>
<tr style="height: 16.65pt;">
<td style="border-style: solid none none; border-color: rgb(75, 172, 198) -moz-use-text-color -moz-use-text-color; border-width: 1pt medium medium; padding: 0in 1.5pt; width: 237.05pt; height: 16.65pt;" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: center; line-height: normal;" align="center"><b><span style="font-size: 10pt;">2007<o:p></o:p></span></b></p>
</td>
<td style="border-style: solid none none; border-color: rgb(75, 172, 198) -moz-use-text-color -moz-use-text-color; border-width: 1pt medium medium; padding: 0in 1.5pt; width: 228.15pt; height: 16.65pt;" width="304">
<p class="MsoNormal" style="background: white none repeat scroll 0% 0%; margin-bottom: 1.2pt; text-align: center; line-height: 18pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" align="center"><b><span style="font-size: 10pt;" lang="EN">2004<o:p></o:p></span></b></p>
</td>
</tr>
<tr style="">
<td style="border: medium none ; padding: 0in 1.5pt; background: rgb(210, 234, 241) none repeat scroll 0% 0%; width: 237.05pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;"><a href="http://www.owasp.org/index.php/Top_10_2007-A1"><span style="color: windowtext; text-decoration: none;">A1 &#8211; Cross Site Scripting (XSS)</span></a><br />
  <o:p></o:p></span></p>
</td>
<td style="border: medium none ; padding: 0in 1.5pt; background: rgb(210, 234, 241) none repeat scroll 0% 0%; width: 228.15pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top" width="304">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;" lang="EN"><a href="http://www.owasp.org/index.php/A1_2004_Unvalidated_Input"><span style="color: windowtext; text-decoration: none;">A1 -<br />
  Unvalidated Input</span></a> <o:p></o:p></span></p>
</td>
</tr>
<tr style="">
<td style="border: medium none ; padding: 0in 1.5pt; width: 237.05pt;" valign="top" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;"><a href="http://www.owasp.org/index.php/Top_10_2007-A2"><span style="color: windowtext; text-decoration: none;">A2 &#8211; Injection Flaws</span></a> <o:p></o:p></span></p>
</td>
<td style="border: medium none ; padding: 0in 1.5pt; width: 228.15pt;" valign="top" width="304">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;" lang="EN"><a href="http://www.owasp.org/index.php?title=A2_2004_Broken_Access_Control&amp;action=edit"><span style="color: windowtext; text-decoration: none;">A2 &#8211; Broken<br />
  Access Control</span></a> <o:p></o:p></span></p>
</td>
</tr>
<tr style="">
<td style="border: medium none ; padding: 0in 1.5pt; background: rgb(210, 234, 241) none repeat scroll 0% 0%; width: 237.05pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;"><a href="http://www.owasp.org/index.php/Top_10_2007-A3"><span style="color: windowtext; text-decoration: none;">A3 &#8211; Malicious File Execution</span></a><br />
  <o:p></o:p></span></p>
</td>
<td style="border: medium none ; padding: 0in 1.5pt; background: rgb(210, 234, 241) none repeat scroll 0% 0%; width: 228.15pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top" width="304">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;" lang="EN"><a href="http://www.owasp.org/index.php?title=A3_2004_Broken_Authentication_and_Session_Management&amp;action=edit"><span style="color: windowtext; text-decoration: none;">A3 &#8211; Broken<br />
  Authentication and Session Management</span></a> <o:p></o:p></span></p>
</td>
</tr>
<tr style="">
<td style="border: medium none ; padding: 0in 1.5pt; width: 237.05pt;" valign="top" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;"><a href="http://www.owasp.org/index.php/Top_10_2007-A4"><span style="color: windowtext; text-decoration: none;">A4 &#8211; Insecure Direct Object<br />
  Reference</span></a> <o:p></o:p></span></p>
</td>
<td style="border: medium none ; padding: 0in 1.5pt; width: 228.15pt;" valign="top" width="304">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;" lang="EN"><a href="http://www.owasp.org/index.php?title=A4_2004_Cross_Site_Scripting&amp;action=edit"><span style="color: windowtext; text-decoration: none;">A4 &#8211; Cross<br />
  Site Scripting</span></a> <o:p></o:p></span></p>
</td>
</tr>
<tr style="">
<td style="border: medium none ; padding: 0in 1.5pt; background: rgb(210, 234, 241) none repeat scroll 0% 0%; width: 237.05pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;"><a href="http://www.owasp.org/index.php/Top_10_2007-A5"><span style="color: windowtext; text-decoration: none;">A5 &#8211; Cross Site Request Forgery<br />
  (CSRF)</span></a> <o:p></o:p></span></p>
</td>
<td style="border: medium none ; padding: 0in 1.5pt; background: rgb(210, 234, 241) none repeat scroll 0% 0%; width: 228.15pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top" width="304">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;" lang="EN"><a href="http://www.owasp.org/index.php?title=A5_2004_Buffer_Overflow&amp;action=edit"><span style="color: windowtext; text-decoration: none;">A5 &#8211; Buffer<br />
  Overflow</span></a> <o:p></o:p></span></p>
</td>
</tr>
<tr style="">
<td style="border: medium none ; padding: 0in 1.5pt; width: 237.05pt;" valign="top" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;"><a href="http://www.owasp.org/index.php/Top_10_2007-A6"><span style="color: windowtext; text-decoration: none;">A6 &#8211; Information Leakage and<br />
  Improper Error Handling</span></a> <o:p></o:p></span></p>
</td>
<td style="border: medium none ; padding: 0in 1.5pt; width: 228.15pt;" valign="top" width="304">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;" lang="EN"><a href="http://www.owasp.org/index.php?title=A6_2004_Injection_Flaws&amp;action=edit"><span style="color: windowtext; text-decoration: none;">A6 -<br />
  Injection Flaws</span></a> <o:p></o:p></span></p>
</td>
</tr>
<tr style="">
<td style="border: medium none ; padding: 0in 1.5pt; background: rgb(210, 234, 241) none repeat scroll 0% 0%; width: 237.05pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;"><a href="http://www.owasp.org/index.php/Top_10_2007-A7"><span style="color: windowtext; text-decoration: none;">A7 &#8211; Broken Authentication and<br />
  Session Management</span></a> <o:p></o:p></span></p>
</td>
<td style="border: medium none ; padding: 0in 1.5pt; background: rgb(210, 234, 241) none repeat scroll 0% 0%; width: 228.15pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top" width="304">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;" lang="EN"><a href="http://www.owasp.org/index.php?title=A7_2004_Improper_Error_Handling&amp;action=edit"><span style="color: windowtext; text-decoration: none;">A7 -<br />
  Improper Error Handling</span></a><span style="">&nbsp; </span><o:p></o:p></span></p>
</td>
</tr>
<tr style="">
<td style="border: medium none ; padding: 0in 1.5pt; width: 237.05pt;" valign="top" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;"><a href="http://www.owasp.org/index.php/Top_10_2007-A8"><span style="color: windowtext; text-decoration: none;">A8 &#8211; Insecure Cryptographic Storage</span></a><br />
  <o:p></o:p></span></p>
</td>
<td style="border: medium none ; padding: 0in 1.5pt; width: 228.15pt;" valign="top" width="304">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;" lang="EN"><a href="http://www.owasp.org/index.php?title=A8_2004_Insecure_Storage&amp;action=edit"><span style="color: windowtext; text-decoration: none;">A8 -<br />
  Insecure Storage</span></a> <o:p></o:p></span></p>
</td>
</tr>
<tr style="">
<td style="border: medium none ; padding: 0in 1.5pt; background: rgb(210, 234, 241) none repeat scroll 0% 0%; width: 237.05pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;"><a href="http://www.owasp.org/index.php/Top_10_2007-A9"><span style="color: windowtext; text-decoration: none;">A9 &#8211; Insecure Communications</span></a><br />
  <o:p></o:p></span></p>
</td>
<td style="border: medium none ; padding: 0in 1.5pt; background: rgb(210, 234, 241) none repeat scroll 0% 0%; width: 228.15pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top" width="304">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;" lang="EN"><a href="http://www.owasp.org/index.php?title=A9_2004_Application_Denial_of_Service&amp;action=edit"><span style="color: windowtext; text-decoration: none;">A9 -<br />
  Application Denial of Service</span></a> <o:p></o:p></span></p>
</td>
</tr>
<tr style="">
<td style="border-style: none none solid; border-color: -moz-use-text-color -moz-use-text-color rgb(75, 172, 198); border-width: medium medium 1pt; padding: 0in 1.5pt; width: 237.05pt;" valign="top" width="316">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;"><a href="http://www.owasp.org/index.php/Top_10_2007-A10"><span style="color: windowtext; text-decoration: none;">A10 &#8211; Failure to<br />
  Restrict URL Access</span></a> <o:p></o:p></span></p>
</td>
<td style="border-style: none none solid; border-color: -moz-use-text-color -moz-use-text-color rgb(75, 172, 198); border-width: medium medium 1pt; padding: 0in 1.5pt; width: 228.15pt;" valign="top" width="304">
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt;" lang="EN"><a href="http://www.owasp.org/index.php?title=A10_2004_Insecure_Configuration_Management&amp;action=edit"><span style="color: windowtext; text-decoration: none;">A10 -<br />
  Insecure Configuration Management</span></a> <o:p></o:p></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal" style=""><span style=""><o:p>&nbsp;</o:p></span></p>
<p class="style1"><font color="#000000">OWASP .NET Projects</font><br />
  <a href="http://www.owasp.org/index.php/Category:OWASP_.NET_Project">http://www.owasp.org/index.php/Category:OWASP_.NET_Project</a>
</p>
<p class="style1"><font color="#000000"><strong>References and Papers on Financial Data Mining</strong></font></p>
<ul>
<li><font color="#000000"><a href="http://www.dmreview.com/specialreports/20071002/1093412-1.html">Mine Your  Way to Combat Money Laundering</a></font></li>
<li><font color="#000000">OFAC SDN  List <a href="http://www.ustreas.gov/offices/enforcement/ofac/sdn/">www.ustreas.gov/offices/enforcement/ofac/sdn/</a></font></li>
<li><font color="#000000">FinCen <a href="http://www.fincen.gov/">www.fincen.gov/</a></font></li>
<li><font color="#000000">FATF <a href="http://www.fatf-gafi.org/">www.fatf-gafi.org/</a></font></li>
<li><font color="#000000"><a href="http://www.irs.gov/businesses/small/article/0,,id=154555,00.html">Suspicious  Activity Report</a></font></li>
<li><font color="#000000"><u><a href="http://www.fincen.gov/suspiciousactivityreport.ppt">Keys to a Well  Prepared Suspicious Activity Report</a></u></font></li>
<li><font color="#000000"><a href="http://www.emeraldinsight.com/Insight/viewContentItem.do?contentType=Article&amp;hdAction=lnkhtml&amp;contentId=1603663">A  framework for data mining-based anti-money laundering research</a></font></li>
<li><font color="#000000"><a href="http://www.lse.ac.uk/collections/informationSystems/pdf/theses/canhoto.pdf">Profiling  Behavior: The social construction of categories in the detection of financial  crime; dissertation by Ana Canhoto</a></font></li>
<li><font color="#000000"><a href="http://ieeexplore.ieee.org/Xplore/login.jsp?url=/iel5/4351372/4351373/04351389.pdf?isnumber=4351373&amp;prod=CNF&amp;arnumber=4351389&amp;arSt=55&amp;ared=64&amp;arAuthor=Edge%2C+Michael+E.%3B+Sampaio%2C+Pedro+R.+Falcone%3B+Choudhary%2C+Mohammed">Towards  a Proactive Fraud Management Framework for Financial Data Streams</a></font></li>
<li><font color="#000000">T. Senator.  &#8220;The financial crimes enforcement network AI system (FAIS).&#8221; <em>AI  Magazine</em> 4, 1995. </font></li>
<li><font color="#000000">M. Sparrow.  &#8220;The State of the Fraud Control Game; and the Impact of Electronic Claims  Processing on Fraud and Fraud Control.&#8221; Proceedings of the International  Symposium on Criminal Justice Information Systems and Technology, 1994. </font></li>
<li><font color="#000000">U.S.  Congress, Office of Technology Assessment (OTA). &#8220;Information Technologies  for Control of Money Laundering.&#8221; <em>OTA-ITC-630</em>. Washington, DC: U.S.  Government Printing Office, September 1995.</font></li>
<li><font color="#000000">Zdanowicz,  J.S. (2004), &#8220;Detecting money laundering and terrorist financing via data  mining&#8221;, <em>Communications of the ACM</em>, Vol. 47 No.5</font></li>
<li><font color="#000000">Watkins,  R.C., Reynolds, K.M., Demara, R., Georgiopoulos, M., Gonzalez, A., Eaglin, R.  (2003), &#8220;Tracking dirty proceeds: exploring data mining technologies as  tools to investigate money laundering&#8221;, <em>Police Practice and Research</em>,  Vol. 4 No.2, pp.163-78.</font></li>
<li><font color="#000000">Vikram, A., Chennuru, S., Rao, H.R., Upadhyaya, S. (2004), &#8220;A  solution architecture for financial institutions to handle illegal activities:  a neural networks approach&#8221;, <em>Proceedings of the 37th Hawaii  International Conference on System Sciences-2004</em></font></li>
<li><font color="#000000">Zhang, Z.,  Salerno, J.J., Yu, P.S. (2003), &#8220;Applying data mining in investigating  money laundering crimes&#8221;, paper presented at SIGKDD&#8217;03, Washington, DC,  pp.747-52. </font></li>
<li><font color="#000000">Senator,  T.E., Goldberg, H.G., Wooton, J. (1995), &#8220;The financial crimes enforcement  network AI system (FAIS): identifying potential money laundering from reports  of large cash transactions&#8221;, <em>AI Magazine</em>, Vol. 16 No.4, pp.21-39. </font></li>
<li><font color="#000000">Tang, J.,  Yin, J. (2005), &#8220;Developing an intelligent data discriminating system of  antimony laundering based on SVM&#8221;, <em>Proceedings of the Fourth  International Conference on Machine Learning and Cybernetics. Guangzhou</em>,  pp.3453-7. </font></li>
<li><font color="#000000">Kingdon, J.  (2004), &#8220;AI fights money laundering&#8221;, <em>IEEE Intelligent Systems</em>,  Vol. 5/6 pp.87</font></li>
<li><font color="#000000">Goldberg,  H.G., Wong, R.W.H. (1998), &#8220;Restructuring transactional data for link  analysis in the FinCEN AI System&#8221;, <em>Proceedings of 1998 AAAI Fall  Symposium on Artificial Intelligence and Link Analysis</em>, AAAI Press, Menlo  Park, CA, . </font></li>
<li><font color="#000000">Fawcett,  T., Provost, F. (1997), &#8220;Adaptive fraud detection&#8221;, <em>Data Mining  and Knowledge Discovery</em>, Vol. 1 No.3, pp.291-316. </font></li>
</ul>
<ul class="style1">
</ul>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.adnanmasood.com%2F2008%2F07%2F21%2Fowasp-top-10-and-data-mining-in-financial-sector%2F&amp;title=OWASP%20Top%2010%20and%20Data%20Mining%20in%20Financial%20Sector" id="wpa2a_20"><img src="http://blog.adnanmasood.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.adnanmasood.com/2008/07/21/owasp-top-10-and-data-mining-in-financial-sector/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

