Hi, I am working out a proposal on this OWASP Education track: http://www.owasp.org/index.php/Education_Track:_What_Developers_Should_Know_ on_Web_Application_Security
Assume this company that is convinced that they need to do something on web application security. They decide to send their developers on a 4h course on web application security. Limitation: the course can not be tuned to the company risk profile or development environment. I know this should be done, but amuse me on this one. What would you add as minimal topics to cover? Thx, Seba _______________________________________________ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. _______________________________________________