<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=Content-Type content="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 12 (filtered medium)">
<style>
<!--
 /* Font Definitions */
 @font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page Section1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.Section1
        {page:Section1;}
 /* List Definitions */
 @list l0
        {mso-list-id:6710376;
        mso-list-template-ids:1308365618;}
@list l0:level1
        {mso-level-number-format:image;
        list-style-image:url("PicExportError");
        mso-level-text:\F0A7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l1
        {mso-list-id:97140507;
        mso-list-template-ids:1755863210;}
@list l1:level1
        {mso-level-start-at:11;
        mso-level-text:%1;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:66.0pt;
        text-indent:-66.0pt;}
@list l1:level2
        {mso-level-start-at:45;
        mso-level-text:"%1\.%2";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:66.0pt;
        text-indent:-66.0pt;}
@list l1:level3
        {mso-level-start-at:12;
        mso-level-text:"%1\.%2-%3\.0";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:66.0pt;
        text-indent:-66.0pt;}
@list l1:level4
        {mso-level-number-format:arabic-leading-zero;
        mso-level-text:"%1\.%2-%3\.%4";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:66.0pt;
        text-indent:-66.0pt;}
@list l1:level5
        {mso-level-text:"%1\.%2-%3\.%4\.%5";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:66.0pt;
        text-indent:-66.0pt;}
@list l1:level6
        {mso-level-text:"%1\.%2-%3\.%4\.%5\.%6";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:1.0in;
        text-indent:-1.0in;}
@list l1:level7
        {mso-level-text:"%1\.%2-%3\.%4\.%5\.%6\.%7";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:1.0in;
        text-indent:-1.0in;}
@list l1:level8
        {mso-level-text:"%1\.%2-%3\.%4\.%5\.%6\.%7\.%8";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:1.25in;
        text-indent:-1.25in;}
@list l1:level9
        {mso-level-text:"%1\.%2-%3\.%4\.%5\.%6\.%7\.%8\.%9";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        margin-left:1.5in;
        text-indent:-1.5in;}
@list l2
        {mso-list-id:249311777;
        mso-list-template-ids:-1815156788;}
@list l2:level1
        {mso-level-number-format:image;
        list-style-image:url("PicExportError");
        mso-level-text:\F0A7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l3
        {mso-list-id:549651703;
        mso-list-template-ids:1099066796;}
@list l3:level1
        {mso-level-number-format:image;
        list-style-image:url("PicExportError");
        mso-level-text:\F0A7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l4
        {mso-list-id:1036468418;
        mso-list-template-ids:383397564;}
@list l4:level1
        {mso-level-number-format:image;
        list-style-image:url("PicExportError");
        mso-level-text:\F0A7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l5
        {mso-list-id:1934896908;
        mso-list-template-ids:1011881482;}
@list l5:level1
        {mso-level-number-format:image;
        list-style-image:url("PicExportError");
        mso-level-text:\F0A7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l6
        {mso-list-id:2000037226;
        mso-list-template-ids:-34561542;}
@list l6:level1
        {mso-level-number-format:image;
        list-style-image:url("PicExportError");
        mso-level-text:\F0A7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l6:level2
        {mso-level-number-format:image;
        list-style-image:url("PicExportError");
        mso-level-text:\F0A7;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext="edit">
  <o:idmap v:ext="edit" data="1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=EN-US link=blue vlink=purple>

<div class=Section1>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'>OWASP
chapter members<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'>This
is reminder of the OWASP meeting next Wednesday. The presentation is scheduled
for next Wednesday at 12.00 and 11.45-12.00 for registration, food refreshments
will be provided by Breach Security<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'>Thanks
for the ones that already RSVP, for the ones that did not please provide your
RSVP not later than Monday 23<sup>rd</sup>.<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal style='margin-bottom:1.2pt;line-height:18.0pt;background:
white'><span lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'>Looking forward to your participation<o:p></o:p></span></p>

<p class=MsoNormal style='margin-bottom:1.2pt;line-height:18.0pt;background:
white'><span lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal style='margin-bottom:1.2pt;line-height:18.0pt;background:
white'><span lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'>Marco Morana<o:p></o:p></span></p>

<p class=MsoNormal style='margin-bottom:1.2pt;line-height:18.0pt;background:
white'><span lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'>OWASP Chapter Lead<o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'>P.S..Here
are the details of the presentation:</span> <span style='font-size:12.0pt;
font-family:"Times New Roman","serif"'><a
href="http://www.owasp.org/index.php/Cincinnati#Upcoming_November_Meeting">http://www.owasp.org/index.php/Cincinnati#Upcoming_November_Meeting</a><o:p></o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal style='mso-margin-top-alt:auto;margin-bottom:1.2pt;
line-height:18.0pt;background:white'><b><span lang=EN style='font-size:12.0pt;
font-family:"Times New Roman","serif";color:black'>Presenter: Ryan Barnett,
Director of Application Security Research, Breach Security Inc.</span></b><span
lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'> <o:p></o:p></span></p>

<p class=MsoNormal style='mso-margin-top-alt:auto;margin-bottom:1.2pt;
line-height:18.0pt;background:white'><b><span lang=EN style='font-size:12.0pt;
font-family:"Times New Roman","serif";color:black'>What: Virtual Patching for
Web Applications: Theory and Practice</span></b><span lang=EN style='font-size:
12.0pt;font-family:"Times New Roman","serif";color:black'> <o:p></o:p></span></p>

<p class=MsoNormal style='margin-bottom:1.2pt;line-height:18.0pt;background:
white'><span lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'>Fixing identified vulnerabilities in web application always
requires time. Organizations often do not have access to a commercial
application's source code and are at the vendor's mercy while waiting for a
patch. Even if they have access to the code, implementing a patch in
development takes time. This leaves a window of opportunity for the attacker to
exploit. External patching (also called &quot;just-in-time patching&quot; and
&quot;virtual patching&quot;) is one of the biggest advantages of web
application firewalls as they can fix this problem externally. A fix for a
specific vulnerability is usually very easy to design and in most cases it can
be done in less than 15 minutes. This presentation will outline exactly when
and where Virtual Patching is appropriate and will show the proper steps for
their creation and testing. <o:p></o:p></span></p>

<p class=MsoNormal style='mso-margin-top-alt:auto;margin-bottom:1.2pt;
line-height:18.0pt;background:white'><b><span lang=EN style='font-size:12.0pt;
font-family:"Times New Roman","serif";color:black'>Presenter Bio: Ryan C.
Barnett is the Director of Application Security Research at Breach Security </span></b><span
lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'>where he leads Breach Security Labs. He is a frequent speaker at
industry conferences such as Blackhat and is a Faculty Member for the SANS
Institute and Team Lead for the Center for Internet Security Apache Benchmark
Project. He is the OWASP ModSecurity Core Rule Set (CRS) Project Leader and a
member of the Web Application Security Consortium where he leads the
Distributed Open Proxy Honeypot Project. Mr. Barnett has also authored a web
security book for Addison/Wesley Publishing entitled &quot;Preventing Web
Attacks with Apache&quot;. <o:p></o:p></span></p>

<p class=MsoNormal style='mso-margin-top-alt:auto;margin-bottom:1.2pt;
line-height:18.0pt;background:white'><b><span lang=EN style='font-size:12.0pt;
font-family:"Times New Roman","serif";color:black'>Location / Venue Sponsor: </span></b><span
lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'><a href="http://www.citibank.com/" title="http://www.citibank.com/"><span
style='color:#3366BB'>Citibank</span></a> 9997 Carver Road, Bldg. 1,
Cincinnati, Ohio, 45242-5537 <o:p></o:p></span></p>

<p class=MsoNormal style='margin-bottom:1.2pt;line-height:18.0pt;background:
white'><span lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'>For help with directions contact Citi Blue Ash help desk at (513)
979-9000 or check directions <a
href="http://maps.google.com/maps?f=q&amp;hl=en&amp;geocode=&amp;q=9997+carver+rd+ohio+45242-5537&amp;sll=40.712476,-74.009485&amp;sspn=0.007709,0.013218&amp;ie=UTF8&amp;ll=39.243986,-84.388239&amp;spn=0.007877,0.013218&amp;z=16&amp;iwloc=addr"
title="http://maps.google.com/maps?f=q&amp;hl=en&amp;geocode=&amp;q=9997+carver+rd+ohio+45242-5537&amp;sll=40.712476,-74.009485&amp;sspn=0.007709,0.013218&amp;ie=UTF8&amp;ll=39.243986,-84.388239&amp;spn=0.007877,0.013218&amp;z=16&amp;iwloc=addr"><span
style='color:#3366BB'>herein</span></a>. <o:p></o:p></span></p>

<p class=MsoNormal style='margin-bottom:1.2pt;line-height:18.0pt;background:
white'><span lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal style='margin-bottom:1.2pt;line-height:18.0pt;background:
white'><span lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'>Please access the building from the visitor lobby. OWASP meetings
are held at the &quot;Buckeyes&quot; lecture room. <o:p></o:p></span></p>

<p class=MsoNormal style='mso-margin-top-alt:auto;margin-bottom:1.2pt;
line-height:18.0pt;background:white'><b><span lang=EN style='font-size:12.0pt;
font-family:"Times New Roman","serif";color:black'>Proof of ID is required to
attend the meeting</span></b><span lang=EN style='font-size:12.0pt;font-family:
"Times New Roman","serif";color:black'> <o:p></o:p></span></p>

<p class=MsoNormal style='margin-bottom:1.2pt;line-height:18.0pt;background:
white'><span lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'>Citi guards verify that you pre-registered to the meeting by
checking the RSVP list. Once you are checked and identified (please bring a proof
of ID) you will be granted visitor access to the training facilities. <o:p></o:p></span></p>

<p class=MsoNormal style='margin-bottom:1.2pt;line-height:18.0pt;background:
white'><span lang=EN style='font-size:12.0pt;font-family:"Times New Roman","serif";
color:black'><o:p>&nbsp;</o:p></span></p>

<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p>&nbsp;</o:p></span></p>

</div>

</body>

</html>