<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Imelven</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Imelven"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Imelven"/>
		<updated>2026-05-21T09:24:05Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2019_Training_Day&amp;diff=252365</id>
		<title>OWASP Portland 2019 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2019_Training_Day&amp;diff=252365"/>
				<updated>2019-06-12T01:47:52Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For the fourth year in a row, the Portland OWASP chapter is proud to host our information security training day! This is be an excellent opportunity for the local Portland security community to receive top quality information security and application security training for prices far lower than normally offered. It's also a great chance to network with other local infosec and appsec enthusiasts and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
The 4th annual OWASP Portland 2019 Training Day date will be on September 25, 2019. See [[#Details|Details]] for more info.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:red&amp;quot;&amp;gt;General registration date will be announced soon.&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Want to get news and information on our 2019 Training Day? Subscribe to the [https://groups.google.com/a/owasp.org/forum/#!forum/portland-chapter] Portland OWASP mailing list or follow [https://twitter.com/portlandowasp @PortlandOWASP] on Twitter!&lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses will be held in two tracks: four in the morning session, and four in the afternoon session.  Each participant can register for one morning course, one afternoon course, or one of each. &lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Classes are TBD ===&lt;br /&gt;
&lt;br /&gt;
=2019 Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor? Watch this space for 2019 sponsorship information or contact us via the mailing list or Twitter!'''&lt;br /&gt;
&lt;br /&gt;
== 2018 Sponsors == &lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:OCI Logo.png|link=https://cloud.oracle.com/en_US/iaas]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:ForgeRock logo.png|link=https://www.forgerock.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Security Innovation logo.png|link=https://www.securityinnovation.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Morning Coffee Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:OCI Logo.png|link=https://cloud.oracle.com/en_US/iaas]] &lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:simple.png|link=https://simple.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
OWASP Portland 2019 Training Day will be on September 25, 2019.  &lt;br /&gt;
&lt;br /&gt;
This year for the 2nd time, we'll be located at:&lt;br /&gt;
&lt;br /&gt;
 World Trade Center Portland&lt;br /&gt;
 121 SW Salmon St.&lt;br /&gt;
 Portland, OR 97204. &lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rock Bottom Restaurant &amp;amp; Brewery, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 206 SW Morrison St&lt;br /&gt;
 Portland, OR 97204&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
Schedule TBD!&lt;br /&gt;
&lt;br /&gt;
Interested in teaching a training at Training Day 2019? Contact Portland OWASP via the mailing list or Twitter!&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
Here are some lunch ideas:&lt;br /&gt;
* Farmhouse Cafe, 101 SW Main St.&lt;br /&gt;
* The Good Earth Cafe, 1136 SW 3rd Ave.&lt;br /&gt;
* Chipotle Mexican Grill, 240 SW Yamhill St.&lt;br /&gt;
* Luc Lac Vietnamese Kitchen, 835 SW 2nd Ave.&lt;br /&gt;
* Rock Bottom Restaurant &amp;amp; Brewery, 206 SW Morrison St.&lt;br /&gt;
* Buffalo Wild Wings, 327 SW Morrison St.&lt;br /&gt;
* Cafe Yumm, 301 SW Morrison St.&lt;br /&gt;
* Killer Burger, 510 SW 3rd Ave.&lt;br /&gt;
* House of Ramen, 223 SW Columbia St.&lt;br /&gt;
* There are some food carts north of the World Trade Center on SW 3rd Ave. and SW Stark St.&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
&lt;br /&gt;
Registration will again be via EventBrite&lt;br /&gt;
&lt;br /&gt;
Thank you to the OWASP Foundation and the many sponsors, trainers, volunteers and trainers that have helped make Training Day a success and allow us to continue!&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2019_Training_Day&amp;diff=252364</id>
		<title>OWASP Portland 2019 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2019_Training_Day&amp;diff=252364"/>
				<updated>2019-06-12T01:21:19Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For the fourth year in a row, the Portland OWASP chapter is proud to host our information security training day! This is be an excellent opportunity for the local Portland security community to receive top quality information security and application security training for prices far lower than normally offered. It's also a great chance to network with other local infosec and appsec enthusiasts and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
The 4th annual OWASP Portland 2019 Training Day date will be '''announced soon!''' See [[#Details|Details]] for more info.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:red&amp;quot;&amp;gt;General registration date will be announced soon.&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Want to get news and information on our 2019 Training Day? Subscribe to the [https://groups.google.com/a/owasp.org/forum/#!forum/portland-chapter] Portland OWASP mailing list or follow [https://twitter.com/portlandowasp @PortlandOWASP] on Twitter!&lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses will be held in two tracks: four in the morning session, and four in the afternoon session.  Each participant can register for one morning course, one afternoon course, or one of each. &lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Classes are TBD ===&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor? Watch this space for 2019 sponsorship information or contact us via the mailing list or Twitter!'''&lt;br /&gt;
&lt;br /&gt;
== A huge thank you to our 2018 sponsors! == &lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:OCI Logo.png|link=https://cloud.oracle.com/en_US/iaas]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:ForgeRock logo.png|link=https://www.forgerock.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Security Innovation logo.png|link=https://www.securityinnovation.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Morning Coffee Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:OCI Logo.png|link=https://cloud.oracle.com/en_US/iaas]] &lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:simple.png|link=https://simple.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
OWASP Portland 2019 Training Day will be Fall 2019. &lt;br /&gt;
&lt;br /&gt;
This year for the 2nd time, we'll be located at:&lt;br /&gt;
&lt;br /&gt;
 World Trade Center Portland&lt;br /&gt;
 121 SW Salmon St.&lt;br /&gt;
 Portland, OR 97204. &lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rock Bottom Restaurant &amp;amp; Brewery, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 206 SW Morrison St&lt;br /&gt;
 Portland, OR 97204&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
Schedule TBD!&lt;br /&gt;
&lt;br /&gt;
Interested in teaching a training at Training Day 2019? Contact Portland OWASP via the mailing list or Twitter!&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
Here are some lunch ideas:&lt;br /&gt;
* Farmhouse Cafe, 101 SW Main St.&lt;br /&gt;
* The Good Earth Cafe, 1136 SW 3rd Ave.&lt;br /&gt;
* Chipotle Mexican Grill, 240 SW Yamhill St.&lt;br /&gt;
* Luc Lac Vietnamese Kitchen, 835 SW 2nd Ave.&lt;br /&gt;
* Rock Bottom Restaurant &amp;amp; Brewery, 206 SW Morrison St.&lt;br /&gt;
* Buffalo Wild Wings, 327 SW Morrison St.&lt;br /&gt;
* Cafe Yumm, 301 SW Morrison St.&lt;br /&gt;
* Killer Burger, 510 SW 3rd Ave.&lt;br /&gt;
* House of Ramen, 223 SW Columbia St.&lt;br /&gt;
* There are some food carts north of the World Trade Center on SW 3rd Ave. and SW Stark St.&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
&lt;br /&gt;
Registration will again be via EventBrite&lt;br /&gt;
&lt;br /&gt;
Thank you to the OWASP Foundation and the many sponsors, trainers, volunteers and trainers that have helped make Training Day a success and allow us to continue!&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Portland&amp;diff=251701</id>
		<title>Portland</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Portland&amp;diff=251701"/>
				<updated>2019-05-17T17:20:42Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the Portland, Oregon OWASP Chapter.&lt;br /&gt;
&lt;br /&gt;
[[File:Portland_and_Mt_Hood.jpg]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Events=&lt;br /&gt;
&lt;br /&gt;
Past and future event information can be found in [http://calagator.org/events/search?query=OWASP Calagator] or on our [https://www.meetup.com/OWASP-Portland-Chapter/ meetup group page].&lt;br /&gt;
&lt;br /&gt;
The Portland OWASP chapter aims to hold a chapter meeting once every month. There is also an OWASP training day held each year, featuring workshops ranging in multiple information security practices.&lt;br /&gt;
&lt;br /&gt;
Feel free to join us on [https://www.meetup.com/OWASP-Portland-Chapter/ Meetup], [https://www.linkedin.com/groups/4223013/ LinkedIn], and follow us on [https://twitter.com/PortlandOWASP Twitter] for upcoming events!&lt;br /&gt;
=For Participants=&lt;br /&gt;
OWASP Foundation ([https://docs.google.com/a/owasp.org/presentation/d/1ZgY25F0F7QgScMlB1X7LAa70LtyJql8XqcYdR4suPUo/edit#slide=id.p Overview Slides]) is a professional association of[[Membership | global members]] and is and open to anyone interested in learning more about software security. Local chapters are run independently by volunteers and guided by the [[Chapter_Leader_Handbook|Handbook]]. &lt;br /&gt;
&lt;br /&gt;
If you are interested in attending chapter meetings or otherwise getting involved, we &amp;lt;i&amp;gt;strongly&amp;lt;/i&amp;gt; encourage you to join the [https://groups.google.com/a/owasp.org/forum/#!forum/portland-chapter/join local chapter email list].  This list is low-volume, but acts as a great resource for local security information and announcements about chapter meetings.&lt;br /&gt;
&lt;br /&gt;
=== Ways You Can Get Involved ===&lt;br /&gt;
&lt;br /&gt;
==== Speakers / Venues ====&lt;br /&gt;
For our monthly meetings it would be wonderful if you would help us think of topics, volunteer to speak or help find a good person for a topic, or help us secure a venue capable of hosting ~75 members and guests.  &lt;br /&gt;
&lt;br /&gt;
==== Training Day ====&lt;br /&gt;
We need volunteers for Training Day every year to take tickets, direct people to classes, assist trainers, etc. Many people volunteer for a half a day and take a class the other half.  We'd love to have your help.&lt;br /&gt;
&lt;br /&gt;
==== Mentorship ====&lt;br /&gt;
Interested in being a mentor or being mentored ? Please reach out to David Quisenberry, our membership coordinator, to get involved.  Focus of mentoring can be Public Speaking, AppSec Skills, Career Development and we will work to align interests of mentors and those being mentored.  &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leadership ====&lt;br /&gt;
Chapter leaders take the initiative to make sure monthly meetings, Training Day, and mentorships run smoothly (or at least run).  If you are looking for a more significant way to get involved over the course of a year this is a great opportunity.&lt;br /&gt;
&lt;br /&gt;
=For Speakers=&lt;br /&gt;
We would be thrilled if you would like to come give a talk at one of our chapter meetings.  Anything security-related is a good candidate for a talk and will likely draw an interested audience.  Suggestions for possible topics for future meetings:&lt;br /&gt;
&lt;br /&gt;
* Integrating security into an SDLC&lt;br /&gt;
* HTML5 security&lt;br /&gt;
* Social engineering&lt;br /&gt;
* Application Security Tools Review &amp;amp; Comparisons&lt;br /&gt;
* Discussion starters for controversial security topics&lt;br /&gt;
* Your experiences trying to implement a security solution&lt;br /&gt;
* Security basics talks; introductions to secure coding practices&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Our OWASP meetings typically draw between 40 - 75 attendees. Chapter meetings are a great place to do a dry run of talks you intend to give at conferences or just to connect with locals.  Before you present, please be sure you carefully review the [[Speaker_Agreement | speaker agreement]].&lt;br /&gt;
&lt;br /&gt;
= OWASP Annual Training Day =&lt;br /&gt;
[[OWASP Portland 2019 Training Day|2019 Training Day]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland 2018 Training Day|2018 Training Day]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland 2017 Training Day|2017 Training Day]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland 2016 Training Day|2016 Training Day]]&lt;br /&gt;
&lt;br /&gt;
=Presentations=&lt;br /&gt;
&amp;lt;big&amp;gt;'''2019'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''January'''&lt;br /&gt;
&lt;br /&gt;
Docker Exploits with Josh Farwell&lt;br /&gt;
&lt;br /&gt;
[https://github.com/sparklespdx/conference-talks/blob/master/OWASP_PDX_2019-01-09/slides.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''February'''&lt;br /&gt;
&lt;br /&gt;
Building a Security Program with Kendra Ash&lt;br /&gt;
&lt;br /&gt;
[https://github.com/kendraash/talks/blob/master/SecurityProgramTalk%20-%20Kendra%20Ash.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''March'''&lt;br /&gt;
&lt;br /&gt;
Breaching the Cyber-Security Job Industry with Ryan Krause&lt;br /&gt;
&lt;br /&gt;
[https://github.com/ryankrause/talks/blob/master/Breaching%20the%20Cyber%20Security%20Job%20Industry.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''April'''&lt;br /&gt;
&lt;br /&gt;
OWASP Top Ten For JavaScript Developers with Lewis Ardern&lt;br /&gt;
&lt;br /&gt;
=Contact=&lt;br /&gt;
&lt;br /&gt;
Your current Portland Chapter Board:&lt;br /&gt;
&lt;br /&gt;
*Ian Melven - 2019 Chapter Leader (ian.melven@owasp.org)&lt;br /&gt;
*Bhushan Gupta - 2019 Vice Leader (bhushan.gupta@owasp.org) &lt;br /&gt;
*Benny Zhao - 2019 Treasurer (benny.zhao@owasp.org)&lt;br /&gt;
*David Quisenberry - Community Outreach (david.quisenberry@owasp.org)&lt;br /&gt;
&lt;br /&gt;
A huge THANK YOU to the other members of the chapter leadership team and our volunteers, past and present ! &lt;br /&gt;
&lt;br /&gt;
*Philip Jenkins&lt;br /&gt;
*Brian Ventura&lt;br /&gt;
*Sonny Nallamilli - 2018 Treasurer&lt;br /&gt;
*James Bohem&lt;br /&gt;
*Adam Russell (adam.russell@owasp.org) &lt;br /&gt;
*Matthew Lapworth&lt;br /&gt;
*Katie Feucht&lt;br /&gt;
*Timothy D. Morgan - Founder (tim.morgan@owasp.org)&lt;br /&gt;
*AJ Dexter - Founder (aj.dexter@gmail.com - now retired)&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Chapter Supporters =&lt;br /&gt;
Besides being funded through individual contributions and chapter memberships, our chapter is also supported through corporate sponsors.  We would like to thank our sponsors for making many excellent activities possible:&lt;br /&gt;
&lt;br /&gt;
== 2019 ==&lt;br /&gt;
=== Champion Supporters ===&lt;br /&gt;
[[File:simple-logo.png|x100px|link=https://simple.com/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Newrelic-logo.png|x100px|frameless|link=https://newrelic.com/]]&lt;br /&gt;
&lt;br /&gt;
[[File:Vacasa Logo .png|frameless|375x375px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland Sponsorship Archive|Past Chapter Supporters]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;&amp;lt;big&amp;gt;Want to become a chapter supporter?  See the [[OWASP Portland Sponsorship Policy]] for more information.&amp;lt;/big&amp;gt;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Donate ==&lt;br /&gt;
OWASP is non-profit, volunteer-managed organization.  All chapters are organized by volunteers.  By donating to your local chapter or becoming an OWASP member, you help support a variety of activities and events including chapter meetings, competitions, and training.  As a [[About_OWASP | 501(c)(3)]] non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible.  Financial contributions should only be made online using the authorized online chapter donation button.&lt;br /&gt;
&lt;br /&gt;
[[Image:Btn_donate_SM.gif|link=http://www.regonline.com/donation_1044369]] to this chapter or become a local chapter supporter.&lt;br /&gt;
&lt;br /&gt;
Or consider the value of [[Membership | Individual, Corporate, or Academic Supporter membership]]. Ready to become a member? [[Image:Join_Now_BlueIcon.JPG|75px|link=https://myowasp.force.com/memberappregion]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Oregon]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Portland&amp;diff=251637</id>
		<title>Portland</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Portland&amp;diff=251637"/>
				<updated>2019-05-15T17:52:45Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the Portland, Oregon OWASP Chapter.&lt;br /&gt;
&lt;br /&gt;
[[File:Portland_and_Mt_Hood.jpg]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Events=&lt;br /&gt;
&lt;br /&gt;
Past and future event information can be found in [http://calagator.org/events/search?query=OWASP Calagator] or on our [https://www.meetup.com/OWASP-Portland-Chapter/ meetup group page].&lt;br /&gt;
&lt;br /&gt;
The Portland OWASP chapter aims to hold a chapter meeting once every month. There is also an OWASP training day held each year, featuring workshops ranging in multiple information security practices.&lt;br /&gt;
&lt;br /&gt;
Feel free to join us on [https://www.meetup.com/OWASP-Portland-Chapter/ Meetup], [https://www.linkedin.com/groups/4223013/ LinkedIn], and follow us on [https://twitter.com/PortlandOWASP Twitter] for upcoming events!&lt;br /&gt;
=For Participants=&lt;br /&gt;
OWASP Foundation ([https://docs.google.com/a/owasp.org/presentation/d/1ZgY25F0F7QgScMlB1X7LAa70LtyJql8XqcYdR4suPUo/edit#slide=id.p Overview Slides]) is a professional association of[[Membership | global members]] and is and open to anyone interested in learning more about software security. Local chapters are run independently by volunteers and guided by the [[Chapter_Leader_Handbook|Handbook]]. &lt;br /&gt;
&lt;br /&gt;
If you are interested in attending chapter meetings or otherwise getting involved, we &amp;lt;i&amp;gt;strongly&amp;lt;/i&amp;gt; encourage you to join the [https://groups.google.com/a/owasp.org/forum/#!forum/portland-chapter/join local chapter email list].  This list is low-volume, but acts as a great resource for local security information and announcements about chapter meetings.&lt;br /&gt;
&lt;br /&gt;
=== Ways You Can Get Involved ===&lt;br /&gt;
&lt;br /&gt;
==== Speakers / Venues ====&lt;br /&gt;
For our monthly meetings it would be wonderful if you would help us think of topics, volunteer to speak or help find a good person for a topic, or help us secure a venue capable of hosting ~75 members and guests.  &lt;br /&gt;
&lt;br /&gt;
==== Training Day ====&lt;br /&gt;
We need volunteers for Training Day every year to take tickets, direct people to classes, assist trainers, etc. Many people volunteer for a half a day and take a class the other half.  We'd love to have your help.&lt;br /&gt;
&lt;br /&gt;
==== Mentorship ====&lt;br /&gt;
Interested in being a mentor or being mentored ? Please reach out to David Quisenberry, our membership coordinator, to get involved.  Focus of mentoring can be Public Speaking, AppSec Skills, Career Development and we will work to align interests of mentors and those being mentored.  &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leadership ====&lt;br /&gt;
Chapter leaders take the initiative to make sure monthly meetings, Training Day, and mentorships run smoothly (or at least run).  If you are looking for a more significant way to get involved over the course of a year this is a great opportunity.&lt;br /&gt;
&lt;br /&gt;
=For Speakers=&lt;br /&gt;
We would be thrilled if you would like to come give a talk at one of our chapter meetings.  Anything security-related is a good candidate for a talk and will likely draw an interested audience.  Suggestions for possible topics for future meetings:&lt;br /&gt;
&lt;br /&gt;
* Integrating security into an SDLC&lt;br /&gt;
* HTML5 security&lt;br /&gt;
* Social engineering&lt;br /&gt;
* Application Security Tools Review &amp;amp; Comparisons&lt;br /&gt;
* Discussion starters for controversial security topics&lt;br /&gt;
* Your experiences trying to implement a security solution&lt;br /&gt;
* Security basics talks; introductions to secure coding practices&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Our OWASP meetings typically draw between 40 - 75 attendees. Chapter meetings are a great place to do a dry run of talks you intend to give at conferences or just to connect with locals.  Before you present, please be sure you carefully review the [[Speaker_Agreement | speaker agreement]].&lt;br /&gt;
&lt;br /&gt;
= OWASP Annual Training Day =&lt;br /&gt;
[[OWASP Portland 2018 Training Day|2018 Training Day]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland 2017 Training Day|2017 Training Day]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland 2016 Training Day|2016 Training Day]]&lt;br /&gt;
&lt;br /&gt;
=Presentations=&lt;br /&gt;
&amp;lt;big&amp;gt;'''2019'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''January'''&lt;br /&gt;
&lt;br /&gt;
Docker Exploits with Josh Farwell&lt;br /&gt;
&lt;br /&gt;
[https://github.com/sparklespdx/conference-talks/blob/master/OWASP_PDX_2019-01-09/slides.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''February'''&lt;br /&gt;
&lt;br /&gt;
Building a Security Program with Kendra Ash&lt;br /&gt;
&lt;br /&gt;
[https://github.com/kendraash/talks/blob/master/SecurityProgramTalk%20-%20Kendra%20Ash.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''March'''&lt;br /&gt;
&lt;br /&gt;
Breaching the Cyber-Security Job Industry with Ryan Krause&lt;br /&gt;
&lt;br /&gt;
[https://github.com/ryankrause/talks/blob/master/Breaching%20the%20Cyber%20Security%20Job%20Industry.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''April'''&lt;br /&gt;
&lt;br /&gt;
OWASP Top Ten For JavaScript Developers with Lewis Ardern&lt;br /&gt;
&lt;br /&gt;
=Contact=&lt;br /&gt;
&lt;br /&gt;
Your current Portland Chapter Board:&lt;br /&gt;
&lt;br /&gt;
*Ian Melven - 2019 Chapter Leader (ian.melven@owasp.org)&lt;br /&gt;
*Bhushan Gupta - 2019 Vice Leader (bhushan.gupta@owasp.org) &lt;br /&gt;
*Benny Zhao - 2019 Treasurer (benny.zhao@owasp.org)&lt;br /&gt;
*David Quisenberry - Community Outreach (david.quisenberry@owasp.org)&lt;br /&gt;
&lt;br /&gt;
A huge THANK YOU to the other members of the chapter leadership team and our volunteers, past and present ! &lt;br /&gt;
&lt;br /&gt;
*Philip Jenkins&lt;br /&gt;
*Brian Ventura&lt;br /&gt;
*Sonny Nallamilli - 2018 Treasurer&lt;br /&gt;
*James Bohem&lt;br /&gt;
*Adam Russell (adam.russell@owasp.org) &lt;br /&gt;
*Matthew Lapworth&lt;br /&gt;
*Katie Feucht&lt;br /&gt;
*Timothy D. Morgan - Founder (tim.morgan@owasp.org)&lt;br /&gt;
*AJ Dexter - Founder (aj.dexter@gmail.com - now retired)&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Chapter Supporters =&lt;br /&gt;
Besides being funded through individual contributions and chapter memberships, our chapter is also supported through corporate sponsors.  We would like to thank our sponsors for making many excellent activities possible:&lt;br /&gt;
&lt;br /&gt;
== 2019 ==&lt;br /&gt;
=== Champion Supporters ===&lt;br /&gt;
[[File:simple-logo.png|x100px|link=https://simple.com/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Newrelic-logo.png|x100px|frameless|link=https://newrelic.com/]]&lt;br /&gt;
&lt;br /&gt;
[[File:Vacasa Logo .png|frameless|375x375px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland Sponsorship Archive|Past Chapter Supporters]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;&amp;lt;big&amp;gt;Want to become a chapter supporter?  See the [[OWASP Portland Sponsorship Policy]] for more information.&amp;lt;/big&amp;gt;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Donate ==&lt;br /&gt;
OWASP is non-profit, volunteer-managed organization.  All chapters are organized by volunteers.  By donating to your local chapter or becoming an OWASP member, you help support a variety of activities and events including chapter meetings, competitions, and training.  As a [[About_OWASP | 501(c)(3)]] non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible.  Financial contributions should only be made online using the authorized online chapter donation button.&lt;br /&gt;
&lt;br /&gt;
[[Image:Btn_donate_SM.gif|link=http://www.regonline.com/donation_1044369]] to this chapter or become a local chapter supporter.&lt;br /&gt;
&lt;br /&gt;
Or consider the value of [[Membership | Individual, Corporate, or Academic Supporter membership]]. Ready to become a member? [[Image:Join_Now_BlueIcon.JPG|75px|link=https://myowasp.force.com/memberappregion]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Oregon]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Portland&amp;diff=251636</id>
		<title>Portland</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Portland&amp;diff=251636"/>
				<updated>2019-05-15T17:50:52Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the Portland, Oregon OWASP Chapter.&lt;br /&gt;
&lt;br /&gt;
[[File:Portland_and_Mt_Hood.jpg]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Events=&lt;br /&gt;
&lt;br /&gt;
Past and future event information can be found in [http://calagator.org/events/search?query=OWASP Calagator] or on our [https://www.meetup.com/OWASP-Portland-Chapter/ meetup group page].&lt;br /&gt;
&lt;br /&gt;
The Portland OWASP chapter aims to hold a chapter meeting once every month. There is also an OWASP training day held each year, featuring workshops ranging in multiple information security practices.&lt;br /&gt;
&lt;br /&gt;
Feel free to join us on [https://www.meetup.com/OWASP-Portland-Chapter/ Meetup], [https://www.linkedin.com/groups/4223013/ LinkedIn], and follow us on [https://twitter.com/PortlandOWASP Twitter] for upcoming events!&lt;br /&gt;
=For Participants=&lt;br /&gt;
OWASP Foundation ([https://docs.google.com/a/owasp.org/presentation/d/1ZgY25F0F7QgScMlB1X7LAa70LtyJql8XqcYdR4suPUo/edit#slide=id.p Overview Slides]) is a professional association of[[Membership | global members]] and is and open to anyone interested in learning more about software security. Local chapters are run independently by volunteers and guided by the [[Chapter_Leader_Handbook|Handbook]]. &lt;br /&gt;
&lt;br /&gt;
If you are interested in attending chapter meetings or otherwise getting involved, we &amp;lt;i&amp;gt;strongly&amp;lt;/i&amp;gt; encourage you to join the [https://groups.google.com/a/owasp.org/forum/#!forum/portland-chapter/join local chapter email list].  This list is low-volume, but acts as a great resource for local security information and announcements about chapter meetings.&lt;br /&gt;
&lt;br /&gt;
=== Ways You Can Get Involved ===&lt;br /&gt;
&lt;br /&gt;
==== Speakers / Venues ====&lt;br /&gt;
For our monthly meetings it would be wonderful if you would help us think of topics, volunteer to speak or help find a good person for a topic, or help us secure a venue capable of hosting ~75 members and guests.  &lt;br /&gt;
&lt;br /&gt;
==== Training Day ====&lt;br /&gt;
We need volunteers for Training Day every year to take tickets, direct people to classes, assist trainers, etc. Many people volunteer for a half a day and take a class the other half.  We'd love to have your help.&lt;br /&gt;
&lt;br /&gt;
==== Mentorship ====&lt;br /&gt;
Reach out to David Quisenberry, our membership coordinator, to get involved.  Focus of mentoring can be Public Speaking, AppSec Skills, Career Development and we will work to align interests of mentors and those being mentored.  &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leadership ====&lt;br /&gt;
Chapter leaders take the initiative to make sure monthly meetings, Training Day, and mentorships run smoothly (or at least run).  If you are looking for a more significant way to get involved over the course of a year this is a great opportunity.&lt;br /&gt;
&lt;br /&gt;
=For Speakers=&lt;br /&gt;
We would be thrilled if you would like to come give a talk at one of our chapter meetings.  Anything security-related is a good candidate for a talk and will likely draw an interested audience.  Suggestions for possible topics for future meetings:&lt;br /&gt;
&lt;br /&gt;
* Integrating security into an SDLC&lt;br /&gt;
* HTML5 security&lt;br /&gt;
* Social engineering&lt;br /&gt;
* Application Security Tools Review &amp;amp; Comparisons&lt;br /&gt;
* Discussion starters for controversial security topics&lt;br /&gt;
* Your experiences trying to implement a security solution&lt;br /&gt;
* Security basics talks; introductions to secure coding practices&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Our OWASP meetings typically draw between 40 - 75 attendees. Chapter meetings are a great place to do a dry run of talks you intend to give at conferences or just to connect with locals.  Before you present, please be sure you carefully review the [[Speaker_Agreement | speaker agreement]].&lt;br /&gt;
&lt;br /&gt;
= OWASP Annual Training Day =&lt;br /&gt;
[[OWASP Portland 2018 Training Day|2018 Training Day]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland 2017 Training Day|2017 Training Day]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland 2016 Training Day|2016 Training Day]]&lt;br /&gt;
&lt;br /&gt;
=Presentations=&lt;br /&gt;
&amp;lt;big&amp;gt;'''2019'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''January'''&lt;br /&gt;
&lt;br /&gt;
Docker Exploits with Josh Farwell&lt;br /&gt;
&lt;br /&gt;
[https://github.com/sparklespdx/conference-talks/blob/master/OWASP_PDX_2019-01-09/slides.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''February'''&lt;br /&gt;
&lt;br /&gt;
Building a Security Program with Kendra Ash&lt;br /&gt;
&lt;br /&gt;
[https://github.com/kendraash/talks/blob/master/SecurityProgramTalk%20-%20Kendra%20Ash.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''March'''&lt;br /&gt;
&lt;br /&gt;
Breaching the Cyber-Security Job Industry with Ryan Krause&lt;br /&gt;
&lt;br /&gt;
[https://github.com/ryankrause/talks/blob/master/Breaching%20the%20Cyber%20Security%20Job%20Industry.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''April'''&lt;br /&gt;
&lt;br /&gt;
OWASP Top Ten For JavaScript Developers with Lewis Ardern&lt;br /&gt;
&lt;br /&gt;
=Contact=&lt;br /&gt;
&lt;br /&gt;
Your current Portland Chapter Board:&lt;br /&gt;
&lt;br /&gt;
*Ian Melven - 2019 Chapter Leader (ian.melvin@owasp.org)&lt;br /&gt;
*Bhushan Gupta - 2019 Vice Leader (bhushan.gupta@owasp.org) &lt;br /&gt;
*Benny Zhao - 2019 Treasurer (benny.zhao@owasp.org)&lt;br /&gt;
*David Quisenberry - Community Outreach (david.quisenberry@owasp.org)&lt;br /&gt;
&lt;br /&gt;
Other volunteers and organizers:&lt;br /&gt;
&lt;br /&gt;
*Sonny Nallamilli - 2018 Treasurer&lt;br /&gt;
*James Bohem&lt;br /&gt;
*Adam Russell (adam.russell@owasp.org) &lt;br /&gt;
*Matthew Lapworth&lt;br /&gt;
*Katie Feucht&lt;br /&gt;
*Timothy D. Morgan - Founder (tim.morgan@owasp.org)&lt;br /&gt;
*AJ Dexter - Founder (aj.dexter@gmail.com - now retired)&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Chapter Supporters =&lt;br /&gt;
Besides being funded through individual contributions and chapter memberships, our chapter is also supported through corporate sponsors.  We would like to thank our sponsors for making many excellent activities possible:&lt;br /&gt;
&lt;br /&gt;
== 2019 ==&lt;br /&gt;
=== Champion Supporters ===&lt;br /&gt;
[[File:simple-logo.png|x100px|link=https://simple.com/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Newrelic-logo.png|x100px|frameless|link=https://newrelic.com/]]&lt;br /&gt;
&lt;br /&gt;
[[File:Vacasa Logo .png|frameless|375x375px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland Sponsorship Archive|Past Chapter Supporters]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;&amp;lt;big&amp;gt;Want to become a chapter supporter?  See the [[OWASP Portland Sponsorship Policy]] for more information.&amp;lt;/big&amp;gt;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Donate ==&lt;br /&gt;
OWASP is non-profit, volunteer-managed organization.  All chapters are organized by volunteers.  By donating to your local chapter or becoming an OWASP member, you help support a variety of activities and events including chapter meetings, competitions, and training.  As a [[About_OWASP | 501(c)(3)]] non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible.  Financial contributions should only be made online using the authorized online chapter donation button.&lt;br /&gt;
&lt;br /&gt;
[[Image:Btn_donate_SM.gif|link=http://www.regonline.com/donation_1044369]] to this chapter or become a local chapter supporter.&lt;br /&gt;
&lt;br /&gt;
Or consider the value of [[Membership | Individual, Corporate, or Academic Supporter membership]]. Ready to become a member? [[Image:Join_Now_BlueIcon.JPG|75px|link=https://myowasp.force.com/memberappregion]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Oregon]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Portland&amp;diff=251635</id>
		<title>Portland</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Portland&amp;diff=251635"/>
				<updated>2019-05-15T17:50:31Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the Portland, Oregon OWASP Chapter.&lt;br /&gt;
&lt;br /&gt;
[[File:Portland_and_Mt_Hood.jpg]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Events=&lt;br /&gt;
&lt;br /&gt;
Past and future event information can be found in [http://calagator.org/events/search?query=OWASP Calagator] or on our [https://www.meetup.com/OWASP-Portland-Chapter/ meetup group page].&lt;br /&gt;
&lt;br /&gt;
The Portland OWASP chapter aims to hold a chapter meeting once every month. There is also an OWASP training day held each year, featuring workshops ranging in multiple information security practices.&lt;br /&gt;
&lt;br /&gt;
Feel free to join us on [https://www.meetup.com/OWASP-Portland-Chapter/ Meetup], [https://www.linkedin.com/groups/4223013/ LinkedIn], and follow us on [https://twitter.com/PortlandOWASP Twitter] for upcoming events!&lt;br /&gt;
=For Participants=&lt;br /&gt;
OWASP Foundation ([https://docs.google.com/a/owasp.org/presentation/d/1ZgY25F0F7QgScMlB1X7LAa70LtyJql8XqcYdR4suPUo/edit#slide=id.p Overview Slides]) is a professional association of[[Membership | global members]] and is and open to anyone interested in learning more about software security. Local chapters are run independently by volunteers and guided by the [[Chapter_Leader_Handbook|Handbook]]. &lt;br /&gt;
&lt;br /&gt;
If you are interested in attending chapter meetings or otherwise getting involved, we &amp;lt;i&amp;gt;strongly&amp;lt;/i&amp;gt; encourage you to join the [https://groups.google.com/a/owasp.org/forum/#!forum/portland-chapter/join local chapter email list].  This list is low-volume, but acts as a great resource for local security information and announcements about chapter meetings.&lt;br /&gt;
&lt;br /&gt;
=== Ways You Can Get Involved ===&lt;br /&gt;
&lt;br /&gt;
==== Speakers / Venues ====&lt;br /&gt;
For our monthly meetings it would be wonderful if you would help us think of topics, volunteer to speak or help find a good person for a topic, or help us secure a venue capable of hosting ~75 members and guests.  &lt;br /&gt;
&lt;br /&gt;
==== Training Day ====&lt;br /&gt;
We need volunteers for Training Day every year to take tickets, direct people to classes, assist trainers, etc. Many people volunteer for a half a day and take a class the other half.  We'd love to have your help.&lt;br /&gt;
&lt;br /&gt;
==== Mentorship ====&lt;br /&gt;
Reach out to David Quisenberry, our membership coordinator, to get involved.  Focus of mentoring can be Public Speaking, AppSec Skills, Career Development and we will work to align interests of mentors and those being mentored.  &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leadership ====&lt;br /&gt;
Chapter leaders take the initiative to make sure monthly meetings, Training Day, and mentorships run smoothly (or at least run).  If you are looking for a more significant way to get involved over the course of a year this is a great opportunity.&lt;br /&gt;
&lt;br /&gt;
=For Speakers=&lt;br /&gt;
We would be thrilled if you would like to come give a talk at one of our chapter meetings.  Anything security-related is a good candidate for a talk and will likely draw an interested audience.  Suggestions for possible topics for future meetings:&lt;br /&gt;
&lt;br /&gt;
* Integrating security into an SDLC&lt;br /&gt;
* HTML5 security&lt;br /&gt;
* Social engineering&lt;br /&gt;
* Application Security Tools Review &amp;amp; Comparisons&lt;br /&gt;
* Discussion starters for controversial security topics&lt;br /&gt;
* Your experiences trying to implement a security solution&lt;br /&gt;
* Security basics talks; introductions to secure coding practices&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Our OWASP meetings typically draw between 40 - 75 attendees. Chapter meetings are a great place to do a dry run of talks you intend to give at conferences or just to connect with locals.  Before you present, please be sure you carefully review the [[Speaker_Agreement | speaker agreement]].&lt;br /&gt;
&lt;br /&gt;
= OWASP Annual Training Day =&lt;br /&gt;
[[OWASP Portland 2018 Training Day|2018 Training Day]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland 2017 Training Day|2017 Training Day]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland 2016 Training Day|2016 Training Day]]&lt;br /&gt;
&lt;br /&gt;
=Presentations=&lt;br /&gt;
&amp;lt;big&amp;gt;'''2019'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''January'''&lt;br /&gt;
&lt;br /&gt;
Docker Exploits with Josh Farwell&lt;br /&gt;
&lt;br /&gt;
[https://github.com/sparklespdx/conference-talks/blob/master/OWASP_PDX_2019-01-09/slides.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''February'''&lt;br /&gt;
&lt;br /&gt;
Building a Security Program with Kendra Ash&lt;br /&gt;
&lt;br /&gt;
[https://github.com/kendraash/talks/blob/master/SecurityProgramTalk%20-%20Kendra%20Ash.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''March'''&lt;br /&gt;
&lt;br /&gt;
Breaching the Cyber-Security Job Industry with Ryan Krause&lt;br /&gt;
&lt;br /&gt;
[https://github.com/ryankrause/talks/blob/master/Breaching%20the%20Cyber%20Security%20Job%20Industry.pdf Slides]&lt;br /&gt;
&lt;br /&gt;
'''April'''&lt;br /&gt;
&lt;br /&gt;
OWASP Top Ten For JavaScript Developers with Lewis Ardern&lt;br /&gt;
&lt;br /&gt;
=Contact=&lt;br /&gt;
&lt;br /&gt;
Your current Portland Chapter Board:&lt;br /&gt;
&lt;br /&gt;
*Ian Melven - 2019 Chapter Chair (ian.melven@owasp.org)&lt;br /&gt;
*Bhushan Gupta - 2019 Vice Chair (bhushan.gupta@owasp.org) &lt;br /&gt;
*Benny Zhao - 2019 Treasurer (benny.zhao@owasp.org)&lt;br /&gt;
*David Quisenberry - Community Outreach (david.quisenberry@owasp.org)&lt;br /&gt;
&lt;br /&gt;
Thank you to the rest of our leadership team, volunteers and organizers! &lt;br /&gt;
&lt;br /&gt;
*Sonny Nallamilli - 2018 Treasurer&lt;br /&gt;
*Brian Ventura&lt;br /&gt;
*Philip Jenkins&lt;br /&gt;
*James Bohem&lt;br /&gt;
*Adam Russell (adam.russell@owasp.org) &lt;br /&gt;
*Matthew Lapworth&lt;br /&gt;
*Katie Feucht&lt;br /&gt;
*Timothy D. Morgan - Founder (tim.morgan@owasp.org)&lt;br /&gt;
*AJ Dexter - Founder (aj.dexter@gmail.com - now retired)&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Chapter Supporters =&lt;br /&gt;
Besides being funded through individual contributions and chapter memberships, our chapter is also supported through corporate sponsors.  We would like to thank our sponsors for making many excellent activities possible:&lt;br /&gt;
&lt;br /&gt;
== 2019 ==&lt;br /&gt;
=== Champion Supporters ===&lt;br /&gt;
[[File:simple-logo.png|x100px|link=https://simple.com/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Newrelic-logo.png|x100px|frameless|link=https://newrelic.com/]]&lt;br /&gt;
&lt;br /&gt;
[[File:Vacasa Logo .png|frameless|375x375px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP Portland Sponsorship Archive|Past Chapter Supporters]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;i&amp;gt;&amp;lt;big&amp;gt;Want to become a chapter supporter?  See the [[OWASP Portland Sponsorship Policy]] for more information.&amp;lt;/big&amp;gt;&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Donate ==&lt;br /&gt;
OWASP is non-profit, volunteer-managed organization.  All chapters are organized by volunteers.  By donating to your local chapter or becoming an OWASP member, you help support a variety of activities and events including chapter meetings, competitions, and training.  As a [[About_OWASP | 501(c)(3)]] non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible.  Financial contributions should only be made online using the authorized online chapter donation button.&lt;br /&gt;
&lt;br /&gt;
[[Image:Btn_donate_SM.gif|link=http://www.regonline.com/donation_1044369]] to this chapter or become a local chapter supporter.&lt;br /&gt;
&lt;br /&gt;
Or consider the value of [[Membership | Individual, Corporate, or Academic Supporter membership]]. Ready to become a member? [[Image:Join_Now_BlueIcon.JPG|75px|link=https://myowasp.force.com/memberappregion]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Oregon]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2019_Training_Day&amp;diff=247220</id>
		<title>OWASP Portland 2019 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2019_Training_Day&amp;diff=247220"/>
				<updated>2019-02-07T22:56:34Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For the fourth year in a row, the Portland OWASP chapter is proud to host our information security training day! This is be an excellent opportunity for the local Portland security community to receive top quality information security and application security training for prices far lower than normally offered. It's also a great chance to network with other local infosec and appsec enthusiasts and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
The 4th annual OWASP Portland 2019 Training Day date will be '''announced soon!''' See [[#Details|Details]] for more info.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:red&amp;quot;&amp;gt;General registration date will be announced soon.&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Want to get news and information on our 2018 Training Day? Subscribe to the [https://lists.owasp.org/listinfo/owasp-portland] Portland OWASP mailing list or follow [https://twitter.com/portlandowasp @PortlandOWASP] on Twitter!&lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses will be held in two tracks: four in the morning session, and four in the afternoon session.  Each participant can register for one morning course, one afternoon course, or one of each. &lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Classes are TBD ===&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor? Watch this space for 2019 sponsorship information or contact us via the mailing list or Twitter!'''&lt;br /&gt;
&lt;br /&gt;
== A huge thank you to our 2018 sponsors! == &lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:OCI Logo.png|link=https://cloud.oracle.com/en_US/iaas]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:ForgeRock logo.png|link=https://www.forgerock.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Security Innovation logo.png|link=https://www.securityinnovation.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Morning Coffee Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:OCI Logo.png|link=https://cloud.oracle.com/en_US/iaas]] &lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:simple.png|link=https://simple.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
OWASP Portland 2019 Training Day will be Fall 2019. &lt;br /&gt;
&lt;br /&gt;
This year for the 2nd time, we'll be located at:&lt;br /&gt;
&lt;br /&gt;
 World Trade Center Portland&lt;br /&gt;
 121 SW Salmon St.&lt;br /&gt;
 Portland, OR 97204. &lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rock Bottom Restaurant &amp;amp; Brewery, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 206 SW Morrison St&lt;br /&gt;
 Portland, OR 97204&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
Schedule TBD!&lt;br /&gt;
&lt;br /&gt;
Interested in teaching a training at Training Day 2019? Contact Portland OWASP via the mailing list or Twitter!&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
Here are some lunch ideas:&lt;br /&gt;
* Farmhouse Cafe, 101 SW Main St.&lt;br /&gt;
* The Good Earth Cafe, 1136 SW 3rd Ave.&lt;br /&gt;
* Chipotle Mexican Grill, 240 SW Yamhill St.&lt;br /&gt;
* Luc Lac Vietnamese Kitchen, 835 SW 2nd Ave.&lt;br /&gt;
* Rock Bottom Restaurant &amp;amp; Brewery, 206 SW Morrison St.&lt;br /&gt;
* Buffalo Wild Wings, 327 SW Morrison St.&lt;br /&gt;
* Cafe Yumm, 301 SW Morrison St.&lt;br /&gt;
* Killer Burger, 510 SW 3rd Ave.&lt;br /&gt;
* House of Ramen, 223 SW Columbia St.&lt;br /&gt;
* There are some food carts north of the World Trade Center on SW 3rd Ave. and SW Stark St.&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
&lt;br /&gt;
Registration will again be via EventBrite&lt;br /&gt;
&lt;br /&gt;
Thank you to the OWASP Foundation and the many sponsors, trainers, volunteers and trainers that have helped make Training Day a success and allow us to continue!&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2019_Training_Day&amp;diff=247219</id>
		<title>OWASP Portland 2019 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2019_Training_Day&amp;diff=247219"/>
				<updated>2019-02-07T22:56:09Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: 2019 training day page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For the fourth year in a row, the Portland OWASP chapter is proud to host our information security training day! This is be an excellent opportunity for the local Portland security community to receive top quality information security and application security training for prices far lower than normally offered. It's also a great chance to network with other local infosec and appsec enthusiasts and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
The 4th annual OWASP Portland 2019 Training Day date will be '''announced soon!''' See [[#Details|Details]] for more info.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:red&amp;quot;&amp;gt;General registration date will be announced soon.&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Want to get news and information on our 2018 Training Day? Subscribe to the [https://lists.owasp.org/listinfo/owasp-portland] Portland OWASP mailing list or follow [https://twitter.com/portlandowasp @PortlandOWASP] on Twitter!&lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses will be held in two tracks: four in the morning session, and four in the afternoon session.  Each participant can register for one morning course, one afternoon course, or one of each. &lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Classes are TBD ===&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor? Watch this space for 2019 sponsorship information or contact us via the mailing list or Twitter!'''&lt;br /&gt;
&lt;br /&gt;
== A huge thank you to our 2018 sponsors! == &lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:OCI Logo.png|link=https://cloud.oracle.com/en_US/iaas]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:ForgeRock logo.png|link=https://www.forgerock.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Security Innovation logo.png|link=https://www.securityinnovation.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Morning Coffee Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:OCI Logo.png|link=https://cloud.oracle.com/en_US/iaas]] &lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:simple.png|link=https://simple.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PNSQC 2018 125x125.jpg|link=https://www.pnsqc.org/]]&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
OWASP Portland 2019 Training Day will be Fall 2019. &lt;br /&gt;
&lt;br /&gt;
This year for the 2nd time, we'll be located at:&lt;br /&gt;
&lt;br /&gt;
 World Trade Center Portland&lt;br /&gt;
 121 SW Salmon St.&lt;br /&gt;
 Portland, OR 97204. &lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rock Bottom Restaurant &amp;amp; Brewery, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 206 SW Morrison St&lt;br /&gt;
 Portland, OR 97204&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
Schedule TBD!&lt;br /&gt;
&lt;br /&gt;
Interested in teaching a training at Training Day 2019? Contact Portland OWASP via the mailing list or Twitter!&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
Here are some lunch ideas:&lt;br /&gt;
* Farmhouse Cafe, 101 SW Main St.&lt;br /&gt;
* The Good Earth Cafe, 1136 SW 3rd Ave.&lt;br /&gt;
* Chipotle Mexican Grill, 240 SW Yamhill St.&lt;br /&gt;
* Luc Lac Vietnamese Kitchen, 835 SW 2nd Ave.&lt;br /&gt;
* Rock Bottom Restaurant &amp;amp; Brewery, 206 SW Morrison St.&lt;br /&gt;
* Buffalo Wild Wings, 327 SW Morrison St.&lt;br /&gt;
* Cafe Yumm, 301 SW Morrison St.&lt;br /&gt;
* Killer Burger, 510 SW 3rd Ave.&lt;br /&gt;
* House of Ramen, 223 SW Columbia St.&lt;br /&gt;
* There are some food carts north of the World Trade Center on SW 3rd Ave. and SW Stark St.&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
&lt;br /&gt;
Registration will again be via EventBrite&lt;br /&gt;
&lt;br /&gt;
Thank you to the OWASP Foundation and the many sponsors, trainers, volunteers and trainers that have helped make Training Day a success and allow us to continue!&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2018_Training_Day&amp;diff=242430</id>
		<title>OWASP Portland 2018 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2018_Training_Day&amp;diff=242430"/>
				<updated>2018-08-09T23:17:27Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For the third year in a row, the Portland OWASP chapter is proud to host our information security training day! This is be an excellent opportunity for those interested to receive top quality information security and application security training for prices far lower than normally offered. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
Want to get news and information on our 2018 Training Day? Subscribe to the Portland OWASP mailing list or follow @PortlandOWASP on Twitter!&lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses will be held in two tracks: four in the morning session, and four in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each. &lt;br /&gt;
&lt;br /&gt;
More information coming soon!&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor? Watch this space for 2018 sponsorship information!'''&lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
Coming soon! &lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
Coming soon! &lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
Coming soon!&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
OWASP Portland 2018 Training Day will be October 3, 2018. This year we'll be located at the World Trade Center Portland, 121 SW Salmon St, Portland, OR 97204. &lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
Schedule TBD!&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
Lunch ideas for 2018 coming soon!&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
Registration information and dates coming soon!&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2018_Training_Day&amp;diff=237339</id>
		<title>OWASP Portland 2018 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2018_Training_Day&amp;diff=237339"/>
				<updated>2018-02-05T20:01:04Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For the third year in a row, the Portland OWASP chapter is proud to host our information security training day! This is be an excellent opportunity for those interested to receive top quality information security and application security training for prices far lower than normally offered. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
Want to get news and information on our 2018 Training Day? Subscribe to the Portland OWASP mailing list or follow @PortlandOWASP on Twitter!&lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses will be held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each. &lt;br /&gt;
&lt;br /&gt;
More information coming soon!&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor? Watch this space for 2018 sponsorship information!'''&lt;br /&gt;
&lt;br /&gt;
Thank you very much to our 2017 sponsors! &lt;br /&gt;
&lt;br /&gt;
The following sponsors made our 2017 event possible:&lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
===== [https://www.obsglobal.com/ Online Business Systems] =====&lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
Date and location coming very soon!&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
Schedule TBD!&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
Lunch ideas for 2018 coming soon!&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
Registration information and dates coming soon!&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2018_Training_Day&amp;diff=237338</id>
		<title>OWASP Portland 2018 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2018_Training_Day&amp;diff=237338"/>
				<updated>2018-02-05T20:00:16Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: Created page with &amp;quot;For the third year in a row, the Portland OWASP chapter is proud to host our information security training day! This is be an excellent opportunity for those interested to rec...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For the third year in a row, the Portland OWASP chapter is proud to host our information security training day! This is be an excellent opportunity for those interested to receive top quality information security and application security training for prices far lower than normally offered. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
Want to get news and information on our 2018 Training Day? Subscribe to the Portland OWASP mailing list or follow @PortlandOWASP on Twitter!&lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses will be held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each. &lt;br /&gt;
&lt;br /&gt;
More information&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor?&amp;quot;&amp;quot; Watch this space for 2018 sponsorship information.&lt;br /&gt;
&lt;br /&gt;
Thank you very much to our 2017 sponsors! &lt;br /&gt;
&lt;br /&gt;
The following sponsors made our 2017 event possible:&lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
===== [https://www.obsglobal.com/ Online Business Systems] =====&lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
Date and location coming very soon!&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
Schedule TBD!&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
Lunch ideas for 2018 coming soon!&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
Registration information and dates coming soon!&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233744</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233744"/>
				<updated>2017-09-25T16:57:54Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  '''The cost per course is $25.''' The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
&lt;br /&gt;
==== Sponsored by New Relic ====&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
&lt;br /&gt;
==== Sponsored by Online Business Systems ====&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor?  Please contact: ian ''DOT'' melven ''AT'' owasp.org'''&lt;br /&gt;
&lt;br /&gt;
The following sponsors have made this event possible:&lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
===== [https://www.obsglobal.com/ Online Business Systems] =====&lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
[[File:OWASP Training map.png|none|thumb]]&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room SMSU 329: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room SMSU 329: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |5:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
Registration is via EventBrite : https://www.eventbrite.com/e/portland-owasp-training-day-2017-tickets-37297273148?aff=es2&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_Training_map.png&amp;diff=233743</id>
		<title>File:OWASP Training map.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_Training_map.png&amp;diff=233743"/>
				<updated>2017-09-25T16:57:11Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Map&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233582</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233582"/>
				<updated>2017-09-21T15:33:29Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  '''The cost per course is $25.''' The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
&lt;br /&gt;
==== Sponsored by New Relic ====&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
&lt;br /&gt;
==== Sponsored by Online Business Systems ====&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor?  Please contact: ian ''DOT'' melven ''AT'' owasp.org'''&lt;br /&gt;
&lt;br /&gt;
The following sponsors have made this event possible:&lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
===== [https://www.obsglobal.com/ Online Business Systems] =====&lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room SMSU 329: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room SMSU 329: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |5:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
Registration is via EventBrite : https://www.eventbrite.com/e/portland-owasp-training-day-2017-tickets-37297273148?aff=es2&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233543</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233543"/>
				<updated>2017-09-20T15:20:51Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  '''The cost per course is $25.''' The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
&lt;br /&gt;
==== Sponsored by New Relic ====&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor?  Please contact: ian ''DOT'' melven ''AT'' owasp.org'''&lt;br /&gt;
&lt;br /&gt;
The following sponsors have made this event possible:&lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
===== [https://www.obsglobal.com/ Online Business Systems] =====&lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room SMSU 329: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room SMSU 329: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |5:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
Registration is via EventBrite : https://www.eventbrite.com/e/portland-owasp-training-day-2017-tickets-37297273148?aff=es2&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233008</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233008"/>
				<updated>2017-09-08T01:03:49Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: /* Courses */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  '''The cost per course is $25.''' The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
&lt;br /&gt;
==== Sponsored by New Relic ====&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor?  Please contact: ian ''DOT'' melven ''AT'' owasp.org'''&lt;br /&gt;
&lt;br /&gt;
The following sponsors have made this event possible:&lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
===== [https://www.obsglobal.com/ Online Business Systems] =====&lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room SMSU 329: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room SMSU 329: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |5:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration will open soon - please follow @PortlandOWASP on Twitter for updates!'''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233005</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233005"/>
				<updated>2017-09-08T00:59:28Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: /* Sponsors */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  '''The cost per course is $25.''' The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor?  Please contact: ian ''DOT'' melven ''AT'' owasp.org'''&lt;br /&gt;
&lt;br /&gt;
The following sponsors have made this event possible:&lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
===== [https://www.obsglobal.com/ Online Business Systems] =====&lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room SMSU 329: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room SMSU 329: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |5:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration will open soon - please follow @PortlandOWASP on Twitter for updates!'''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233003</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233003"/>
				<updated>2017-09-08T00:57:42Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  '''The cost per course is $25.''' The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''Interested in becoming a sponsor?  Please contact: ian ''DOT'' melven ''AT'' owasp.org'''&lt;br /&gt;
&lt;br /&gt;
The following sponsors have made this event possible:&lt;br /&gt;
&lt;br /&gt;
=== Mixer Sponsors===&lt;br /&gt;
[[File:github.png|link=https://github.com/]]&lt;br /&gt;
&lt;br /&gt;
=== Training Session Sponsors ===&lt;br /&gt;
[[File:newrelic.png|link=https://newrelic.com/]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
Online Business Systems https://www.obsglobal.com/&lt;br /&gt;
&lt;br /&gt;
=== General Sponsors ===&lt;br /&gt;
&lt;br /&gt;
[[File:summit.png|link=http://summitinfosec.com/]]&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room SMSU 329: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room SMSU 329: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |5:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration will open soon - please follow @PortlandOWASP on Twitter for updates!'''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233002</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=233002"/>
				<updated>2017-09-08T00:48:54Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: /* Courses */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  '''The cost per course is $25.''' The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''COMING SOON !''' We are finalizing our sponsors for this year's training day. It's not too late to sponsor! If interested, please contact ian DOT melven@owasp DOT org&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room SMSU 329: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room SMSU 329: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |5:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration will open soon - please follow @PortlandOWASP on Twitter for updates!'''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232943</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232943"/>
				<updated>2017-09-06T17:41:50Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: /* Schedule */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''COMING SOON !''' We are finalizing our sponsors for this year's training day. It's not too late to sponsor! If interested, please contact ian DOT melven@owasp DOT org&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room SMSU 329: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room SMSU 329: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |5:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration will open soon - please follow @PortlandOWASP on Twitter for updates!'''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232942</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232942"/>
				<updated>2017-09-06T17:39:22Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
'''COMING SOON !''' We are finalizing our sponsors for this year's training day. It's not too late to sponsor! If interested, please contact ian DOT melven@owasp DOT org&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room SMSU 329: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room SMSU 329: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |6:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration will open soon - please follow @PortlandOWASP on Twitter for updates!'''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232941</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232941"/>
				<updated>2017-09-06T17:19:58Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: /* Schedule */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
We are finalizing our sponsors for this year's training day. It's not too late to sponsor! If interested, please contact ian DOT melven@owasp DOT org&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room SMSU 329: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 327: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room SMSU 328: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room SMSU 329: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |6:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration is via EventBrite : https://www.eventbrite.com/myevent?eid=37297273148'''&lt;br /&gt;
&lt;br /&gt;
'''Registration will open soon - please follow @PortlandOWASP on Twitter for updates!'''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232940</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232940"/>
				<updated>2017-09-06T17:17:48Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
''Instructor: Timothy Morgan''&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
We are finalizing our sponsors for this year's training day. It's not too late to sponsor! If interested, please contact ian DOT melven@owasp DOT org&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room TBD: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room TBD:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room TBD: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room TBD: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room TBD: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room TBD: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |6:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration is via EventBrite : https://www.eventbrite.com/myevent?eid=37297273148'''&lt;br /&gt;
&lt;br /&gt;
'''Registration will open soon - please follow @PortlandOWASP on Twitter for updates!'''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232807</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232807"/>
				<updated>2017-09-01T16:15:31Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: /* Schedule */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
''Instructor: Timothy Morgan''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
We are finalizing our sponsors for this year's training day. It's not too late to sponsor! If interested, please contact ian DOT melven@owasp DOT org&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room TBD: Client-side Security for Modern Web Applications &lt;br /&gt;
(SOP, XSS, CSRF, CSP, etc)&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room TBD:  Cyber Security&lt;br /&gt;
Framework&lt;br /&gt;
|Room TBD: Securing Your AWS Environment&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room TBD: Burp and ZAP: Introduction into web intercept/scanning tools&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room TBD: Applied Physical Attacks on Embedded Systems, Introductory Version&lt;br /&gt;
|Room TBD: Cyber First-Aid: Introduction to Incident Response&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |6:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration information is coming soon! Follow @PortlandOWASP on Twitter for updates! '''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232806</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232806"/>
				<updated>2017-09-01T16:10:15Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
''Instructor: Timothy Morgan''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
''Instructor: James Trumper''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
''Instructor: Derek Hill''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
''Instructor: Alexei Kojenov''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
''Instructor: Joe Fitzpatrick''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
''Instructor: Kris Rosenberg''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
We are finalizing our sponsors for this year's training day. It's not too late to sponsor! If interested, please contact ian DOT melven@owasp DOT org&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Activity&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; |Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room 298: Cyber Hygiene - Critical Security Controls&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room 333: Introduction to Injection Vulnerabilities&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room 298: Applied Physical Attacks on Embedded Systems&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |Room 333: Communications Security in Modern Software&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot; |6:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot; | Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration information is coming soon! Follow @PortlandOWASP on Twitter for updates! '''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232805</id>
		<title>OWASP Portland 2017 Training Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Portland_2017_Training_Day&amp;diff=232805"/>
				<updated>2017-09-01T16:08:58Z</updated>
		
		<summary type="html">&lt;p&gt;Imelven: Created page with &amp;quot;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Once again this year the Portland OWASP chapter is hosting an information security training day! This will be an excellent opportunity for those interested to receive quality information security and application security training for next to nothing. It's also a great chance to network with the local infosec community and meet those who share your interests. &lt;br /&gt;
&lt;br /&gt;
=Courses=&lt;br /&gt;
Courses are held in two tracks: three in the morning session, and three in the afternoon session.  Each participant can register for one morning course, or one afternoon course, or one of each.  The six courses offered are as follows:&lt;br /&gt;
&lt;br /&gt;
== Morning Session 8:30 AM - Noon ==&lt;br /&gt;
&lt;br /&gt;
=== Client-side Security for Modern Web Applications (SOP, XSS, CSRF, CSP, etc) ===&lt;br /&gt;
''Instructor: Timothy Morgan''&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: This course introduces the student to key concepts of browser security, such as the same-origin policy, and continues with a series of web-specific vulnerability classes, including: cross-site scripting, cross-site request forgery, clickjacking, and JSON hijacking. The course finishes up by covering new security mechanisms and standards, including cross-origin resource sharing (CORS) and content security policy (CSP).&lt;br /&gt;
&lt;br /&gt;
=== Cyber Security Framework ===&lt;br /&gt;
&amp;quot;Instructor: James Trumper&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking for a place to start addressing your information security posture, how to understand current maturity and plan future enhancements and budget? Have you been tasked with complying or using an information security framework? The CyberSecurity Framework (CSF) is a comprehensive information security framework developed by NIST (the National Institute of Standards and Technology). Although the framework is required for many federal agencies and used by State and local agencies, it is also recommended for use by non-governmental organizations including small to medium businesses. In this course, we will review the framework's structure and components, going into details around specific requirements as well as references to NIST 800-53. Once we have a good foundation around the CSF categories and sub-categories, we will transition into how we can manage our efforts to this framework. The course provides a creative-commons management tool to track current controls, maturity, existing budget, plan for future control enhancement projects, and future budget requests. The tool is both an internal tracking tool as well as a presentation layer to various teams and management based on their need-to-know.&lt;br /&gt;
&lt;br /&gt;
=== Securing Your AWS Environment ===&lt;br /&gt;
&amp;quot;Instructor: Derek Hill&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: Are you looking to move your infrastructure into the cloud, but are worried about how to secure it? Are you ready to let go of all of your physical infrastructure? You are not alone in this journey. The cloud does not have to be this scary unknown black hole. Sure, things are certainly different and not everything that you used to do in your own infrastructure is easily repeatable in the cloud; however, there are many benefits. Thing are different, but many things are the same. We will discuss how to secure your cloud environment using both AWS tools and third party tools, including some custom applications that allow you to see what you have and how you need to secure it. We are successfully managing over 120 AWS accounts with approximately 3000 instances and many other AWS services. This class does not have any labs (due to the short duration). We will have some demos on how we accomplish certain tasks. We hope that you can take away some ideas on how to solve some of your current security problems and gain the confidence that security in the cloud can be achieved.&lt;br /&gt;
&lt;br /&gt;
== Afternoon Session: 1:30 PM - 5:00 PM ==&lt;br /&gt;
&lt;br /&gt;
=== Burp and ZAP: Introduction into web intercept/scanning tools ===&lt;br /&gt;
&amp;quot;Instructor: Alexei Kojenov&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: The participants will learn how browsers communicate with web application back ends and how special tools such as Burp Suite and OWASP ZAP can be used to intercept, analyze and modify these communications to assess the application's security posture and, ultimately, to find and exploit vulnerabilities. We will discuss and try both passive and active attacks while diving deeper into each tool's functionality. We will talk about how to efficiently use the available features, as well as the ways to automate manual tasks. The participants will be able to immediately practice the learned skills during the class, and then apply them in their work environments. Prerequisites: A laptop (any OS) with Firefox or Chrome and Oracle VirtualBox (participants will be given a virtual machine with intentionally vulnerable web application for practice).&lt;br /&gt;
&lt;br /&gt;
=== Applied Physical Attacks on Embedded Systems, Introductory Version === &lt;br /&gt;
&amp;quot;Instructor: Joe Fitzpatrick&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: This workshop introduces several different relatively accessible interfaces on embedded systems. Attendees will get hands-on experience with UART, SPI, and JTAG interfaces on a MIPS-based wifi router. After a brief architectural overview of each interface, hands-on labs will guide through the process understanding, observing, interacting with, and exploiting the interface to potentially access a root shell on the target.&lt;br /&gt;
&lt;br /&gt;
=== Cyber First-Aid: Introduction to Incident Response === &lt;br /&gt;
&lt;br /&gt;
&amp;quot;Instructor: Kris Rosenberg&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
''Assistant: TBD''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Abstract: In today’s world It is not a question of “if” you will get hacked, but “when”. More importantly. what are you going to do about it? When an incident occurs you need to be prepared to respond quickly to minimize losses and collect any potential evidence that could be used for a more detailed analysis of the incident. Much like a typical first aid course that prepares first responders to give immediate care needed to sustain life, this session is designed to give those who are typically the first on-scene to a cybersecurity event the skills they need to effectively identify and contain the incident, and preserve potentially valuable evidence for further forensic analysis.&lt;br /&gt;
&lt;br /&gt;
=Sponsors=&lt;br /&gt;
&lt;br /&gt;
We are finalizing our sponsors for this year's training day. It's not too late to sponsor! If interested, please contact ian DOT melven@owasp DOT org&lt;br /&gt;
&lt;br /&gt;
=Details=&lt;br /&gt;
The training day will be held on Wednesday, October 4 at:&lt;br /&gt;
&lt;br /&gt;
 PSU - Smith Memorial Student Union Building&lt;br /&gt;
 1825 SW Broadway&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
Later in the evening, a social mixer will also be held at Rogue Hall, just a short walk away:&lt;br /&gt;
&lt;br /&gt;
 1717 Southwest Park Ave.&lt;br /&gt;
 Portland, OR 97201&lt;br /&gt;
&lt;br /&gt;
===Schedule===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! |Time&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot;|Activity&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot;|8:00 AM - 9:00 AM&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot;|Morning Registration (Near Room 298)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot;|9:00 AM - 12:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot;|Room 298: Cyber Hygiene - Critical Security Controls&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot;|Room 333: Introduction to Injection Vulnerabilities&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot;|12:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot;| Lunch on your own - ''Meet a new friend and grab a bite!''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot;|1:00 PM - 1:30 PM&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot;| Afternoon Registration (for those attending only in the afternoon)&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot;|1:30 PM - 5:00 PM&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot;|Room 298: Applied Physical Attacks on Embedded Systems&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot;|Room 333: Communications Security in Modern Software&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;padding: 0.5em;&amp;quot;|6:00 PM - 7:30 PM&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; style=&amp;quot;padding: 0.5em;&amp;quot;| Evening Mixer @ Rogue Hall&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Lunch Ideas ===&lt;br /&gt;
&lt;br /&gt;
There are a '''large''' number of restaurants nearby, but in case you're having trouble deciding (or your phone battery died), here are some possibilities:&lt;br /&gt;
&lt;br /&gt;
* Baan-Thai Restaurant, 1924 SW Broadway&lt;br /&gt;
* Hotlips Pizza, 1909 SW 6th Ave&lt;br /&gt;
* Laughing Planet Cafe, 1720 SW 4th Ave&lt;br /&gt;
* Love Belizean, 1503 SW Broadway&lt;br /&gt;
* McMenamins Market Street Pub, 1526 SW 10th Ave&lt;br /&gt;
* There is also a block of food carts on SW 4th Ave between Hall St &amp;amp; College St.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=How to Register=&lt;br /&gt;
'''Registration information is coming soon! Follow @PortlandOWASP on Twitter for updates! '''&lt;/div&gt;</summary>
		<author><name>Imelven</name></author>	</entry>

	</feed>